Atlas / MCP servers / mixelpixx / KiCAD

KiCADBLOCK

mcp/mixelpixx/kicad-1

KiCAD MCP is a Model Context Protocol (MCP) implementation that enables Large Language Models (LLMs) like Claude to directly interact with KiCAD for printed circuit board design.

Verdict
BLOCK
Grade
F
Trust score
52 /100
Exposed tools
200 158r · 75w · 18d
Transport
stdio
License
MIT
Stars
2,416
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

https://github.com/mixelpixx/KiCAD-MCP-Server/discussions/73

## 🚀 Meet Konnect — the next generation [Konnect](https://github.com/mixelpixx/Konnect) is this project rebuilt from scratch in Rust as a native KiCAD 10 plugin: a single binary with no runtime dependencies, built on KiCAD's official IPC API instead of SWIG, with 171 tools, bundled Claude skills and agents, design-review audits, and a manufacturing pipeline. It's where new development happens — licensed AGPL-3.0 (free for individuals and open source; commercial licenses available for businesses). This Python/TypeScript server remains fully open (MIT) and maintained.

KiCAD MCP Server

A Model Context Protocol (MCP) server that enables AI assistants like Claude to interact with KiCAD for PCB design automation. Built on the MCP 2025-06-18 specification, this server provides comprehensive tool schemas and real-time project state access for intelligent PCB design workflows.

Overview

The Model Context Protocol is an open standard from Anthropic that allows AI assistants to securely connect to external tools and data sources. This implementation provides a standardized bridge between AI assistants and KiCAD, enabling natural language control of PCB design operations.

Key Capabilities:

  • 233 tools registered, 173 of them indexed for keyword discovery
  • 173 tools across 16 categories with JSON Schema validation
  • Keyword tool discovery via search_tools / get_category_tools
  • 23 dynamic resources exposing project state
  • Complete schematic workflow with 65 tools (authoring, batch edits, hierarchy, layout) and dynamic symbol loading (~10,000 symbols)
  • Freerouting autorouter integration (Java, Docker, or Podman)
  • Custom footprint and symbol creation tools
  • JLCPCB parts integration with 2.5M+ component catalog and local library search
  • Datasheet enrichment via LCSC
  • Full MCP 2025-06-18 protocol compliance
Read from source at commit f439a850d105OBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add kicad-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DIGIKEY_CLIENT_ID=${DIGIKEY_CLIENT_ID} --env JLCPCB_API_KEY=${JLCPCB_API_KEY} --env JLCPCB_API_SECRET=${JLCPCB_API_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "kicad-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "DIGIKEY_CLIENT_ID": "${DIGIKEY_CLIENT_ID}",
        "JLCPCB_API_KEY": "${JLCPCB_API_KEY}",
        "JLCPCB_API_SECRET": "${JLCPCB_API_SECRET}"
      }
    }
  }
}
03

Exposed tools (200)

158 read · 75 write · 18 destructive. Blast radius: 18 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_board_outlinewriteAdd a board outline to the PCB
add_board_textwriteAdd a text label to a PCB layer (e.g. silkscreen, fab, courtyard).
add_component_3d_modelwriteAttach a 3D model to one or more PLACED footprints on the open board, live via
add_component_annotationwriteAdd a text annotation or comment to a PCB component.
add_copper_pourwriteAdd a copper pour (ground/power plane) to the PCB
add_footprint_3d_modelwriteAttach (or replace) a 3D model — .step/.stp/.wrl — to a .kicad_mod footprint file.
add_gnd_stitching_viasdestructiveDrop GND stitching vias across the board with collision checking against every non-GND segment, via, and pad on every copper layer (PTH vias penetrate the full stackup, so missing any one layer is the classic silent-short failure mode). Three combinable strategies:
add_hierarchical_sheetwriteInsert a hierarchical-sheet reference block into a parent schematic, pointing at an existing sub-sheet file. Adds the sheet box, name/file fields, a sheet_instances path entry on the next page number, and fixes sub-sheet component instance paths so ERC resolves references.
add_layerwriteAdd a new copper or technical layer to the PCB stackup.
add_library_symbol_propertywriteAdd or update a custom property (Manufacturer, MPN, LCSC, etc.) on a symbol definition in the lib_symbols section. This makes the property available to all instances of that symbol in the schematic.
add_mounting_holewritePlace a mounting hole (NPTH or PTH) at the specified position on the PCB.
add_netwriteAdd a new net to the PCB
add_no_connectwriteAdd a no-connect flag (X marker) to a pin that is intentionally left unconnected.
add_schematic_componentwriteAdd a component to a KiCAD schematic
add_schematic_hierarchical_labelwriteAdd a hierarchical label (sheet interface port) to a sub-sheet schematic.
add_schematic_net_labelwriteAdd a net label to the schematic.
add_schematic_textwriteAdd a free-form text annotation to the schematic.
add_schematic_wirewriteAdd a wire connection to a KiCAD schematic
add_sheet_pinwriteAdd a pin to a sheet symbol block on the parent schematic. Sheet pins are the
add_symbol_propertywriteAdd or update a custom property (Manufacturer, MPN, LCSC, etc.) on a symbol in a .kicad_sym
add_viawriteAdd a via to the PCB
add_zonewriteCreate a copper fill zone (pour) on a PCB layer for a specified net.
align_componentsreadAlign multiple PCB components horizontally, vertically or on a grid with optional spacing.
annotate_schematicreadAssign reference designators to unannotated components (R? → R1, R2, ...). Must be called before tools that require known references.
assign_net_to_classwriteAssign a net to an existing net class to apply its specific design rules.
autoplace_schematic_fieldsreadAutomatically reposition every component
autoroutewriteRun Freerouting autorouter on the current PCB. Exports to Specctra DSN, runs Freerouting CLI, and imports the routed SES result. Requires Java 11+ and freerouting.jar (see check_freerouting). Set
backannotate_footprintsreadCopy footprint assignments from a .kicad_pcb back into the schematic
batch_add_and_connectwritePlace multiple components AND wire their nets in a single call — the fewest-round-trip way to build a subcircuit. Each component is like batch_add_components plus an optional
batch_add_componentswriteAdd multiple components to a schematic in one call (far fewer round-trips than add_schematic_component). Each component: {symbol:
batch_add_no_connectswriteAdd no-connect (X) flags to multiple pins in one call, to mark intentionally unconnected pins and silence ERC.
batch_connectreadPlace net labels on multiple pins in one call to wire nets quickly.
batch_edit_schematic_componentswriteEdit multiple existing components in one call.
batch_list_symbol_pinsread
batch_move_componentswriteMove multiple PCB components transactionally. If one reference/spec is invalid, no components are moved. Saves by default unless save=false.
batch_set_schematic_property_positionswriteMove many Reference/Value field labels in a single file read/write — far faster than repeated set_schematic_property_position calls. Pass an
boardreadBoard configuration: layers, mounting holes, zones, visualization
check_clearancereadCheck the actual clearance between two PCB items (track, via, pad, zone or component) and report whether it meets the design rules.
check_courtyard_overlapsreadDetect courtyard overlaps between footprints and (optionally) flag courtyards that extend past the board outline. Accepts a
check_freeroutingwriteCheck if Java and Freerouting JAR are available on the system. Run this before autoroute to verify prerequisites.
check_kicad_uireadCheck if KiCAD UI is currently running
check_placement_clearancereadClassify placement conflicts as body overlap, courtyard overlap, keepout violation, silk/text overlap or pad clearance.
clear_board_outlinedestructiveDelete all Edge.Cuts graphics from the current PCB board.
close_projectdestructiveClose the currently loaded KiCAD project: optionally save, then drop the in-memory board and clear session state. Use this to hand control back so the user (or the agent) can edit project files directly without the MCP later clobbering those changes on save.
componentdestructiveAdvanced component operations: edit, delete, search, group, annotate
connect_passthroughreadConnects all pins of a source connector (e.g. J1) to matching pins of a target connector (e.g. J2) via shared net labels — pin N gets net
connect_to_netreadConnect a component pin to a named net by adding a wire stub and net label at the exact pin endpoint.
copy_routing_patternreadCopy routing pattern (traces and vias) from a group of source components to a matching group of target components. The offset is calculated automatically from the position difference between the first source and first target component. Useful for replicating routing between identical circuit blocks.
create_board_from_schematicwriteCreate a new .kicad_pcb file from a schematic, then update the PCB from that schematic so footprints and nets are present.
create_footprintwriteCreate a new KiCAD footprint (.kicad_mod) inside a .pretty library directory.
create_hierarchical_subsheetwriteCreate a new sub-sheet .kicad_sch file and link it into a parent schematic in a single call (create_schematic + add_hierarchical_sheet). The fastest way to grow a hierarchical design.
create_netclasswriteCreate a new net class with custom design rules, optionally assigning nets to it immediately.
create_projectwriteCreate a new KiCAD project
create_schematicwriteCreate a new KiCAD schematic
create_symbolwriteCreate a new schematic symbol in a .kicad_sym library file (created if missing).
delete_componentdestructiveRemove a component from the PCB by its reference designator.
delete_graphicdestructiveDelete a PCB graphic/drawing item by UUID.
delete_schematic_componentdestructiveRemove a placed symbol from a KiCAD schematic (.kicad_sch). This removes the symbol instance (the placed component) from the schematic. It does NOT remove the symbol definition from lib_symbols. With deleteAttachedLabels, net labels sitting exactly on the deleted component
delete_schematic_net_labeldestructiveRemove a net label from the schematic.
delete_schematic_wiredestructiveRemove a wire from the schematic by start and end coordinates.
delete_symboldestructiveRemove a symbol from a .kicad_sym library file.
delete_tracedestructiveDelete traces from the PCB. Can delete by UUID, position, or bulk-delete all traces on a net.
digikeyreadDigi-Key Product Information V4: search parts for stock, price and lifecycle, and sweep a symbol library for obsolete or unavailable parts (needs DIGIKEY_CLIENT_ID / DIGIKEY_CLIENT_SECRET in the server environment)
digikey_check_library_availabilityreadLook up every symbol in a .kicad_sym on Digi-Key and report which parts are
digikey_search_partsreadSearch Digi-Key by part number, manufacturer part number, or a parametric phrase
digikey_test_connectionreadVerify that the server
discard_or_reloadreadDiscard the current in-memory PCB state and reload the board from disk.
download_jlcpcb_databaseread
download_registry_partreadDownload a registry part
drcreadDesign rule checking and electrical validation: DRC, net classes, clearances
duplicate_componentreadDuplicate an existing PCB component at an offset position, optionally with a new reference designator.
edit_componentwriteEdit properties of an existing PCB component (reference, value, footprint).
edit_footprint_padwriteEdit an existing pad inside a .kicad_mod footprint file.
edit_schematic_componentwrite
enrich_datasheetsreadFill in missing Datasheet URLs in a KiCAD schematic using LCSC part numbers. For every placed symbol that has: • (property
estimate_airwire_lengthsreadAlias for get_ratsnest: estimate airwire segments and lengths by net.
exportreadFile export for fabrication and documentation: Gerber, PDF, BOM, 3D models
export_3dreadExport the PCB as a 3D model (STEP, STL, VRML or OBJ) including optional copper, solder mask, silkscreen and component 3D models.
export_3d_clireadExport a 3D model of the PCB via kicad-cli. The
export_bomreadExport a Bill of Materials (BOM) from the PCB in CSV, XML, HTML or JSON format.
export_drillreadGenerate drill files for a PCB via kicad-cli, exposing the full Excellon/Gerber drill option set (format, drill origin, zero suppression, oval format, units, mirror-Y, minimal header, separate PTH/NPTH files, drill map + map format). Reads the last SAVED state of the .kicad_pcb.
export_dsnreadExport the current PCB to Specctra DSN format. Useful for manual Freerouting workflow or external autorouters.
export_gencadreadExport the PCB in GenCAD format via kicad-cli. Assembly/test interchange format. Exposes padstack flip, unique pin/footprint shape generation, drill-file origin, and store-origin-coordinate options. Reads the last SAVED state of the .kicad_pcb.
export_gerberreadExport PCB Gerber manufacturing files to a directory. Optionally include drill files, map files and choose layer subset.
export_gerber_singlereadPlot the given layers to a SINGLE Gerber file via kicad-cli (
export_gerbersreadPlot Gerber files for a PCB via kicad-cli, exposing the full Plot-dialog option set (X2, netlist attributes, DNP handling, soldermask subtraction, precision, drill-file origin, stored board plot settings, etc). Reads the board from disk, so it reflects the last SAVED state of the .kicad_pcb.
export_ipc2581read
export_ipcd356readGenerate an IPC-D-356 bare-board electrical-test netlist via kicad-cli. Consumed by flying-probe and bed-of-nails testers. Reads the last SAVED state of the .kicad_pcb.
export_netlistread
export_odbreadExport the PCB in ODB++ format via kicad-cli. Single job archive (copper, drill, placement, components, nets, outline) widely used by CAM/MES/assembly. Reads the last SAVED state of the .kicad_pcb.
export_pcb_dxfread
export_pcb_pdfread
export_pcb_svgread
export_pdfreadExport the PCB layout as a PDF document, optionally selecting layers, page size and colour mode.
export_posread
export_position_filereadExport a component placement/position file (pick-and-place) for PCB assembly in CSV or ASCII format.
export_sch_bomreadGenerate a Bill of Materials from a schematic via kicad-cli (
export_sch_dxfreadExport a schematic to DXF via kicad-cli (
export_sch_hpglreadExport a schematic to HPGL via kicad-cli (
export_sch_pdfreadExport a schematic to PDF via kicad-cli (
export_sch_psreadExport a schematic to PostScript via kicad-cli (
export_sch_python_bomreadExport the legacy Python-BOM intermediate XML from a schematic via kicad-cli (
export_sch_svgreadExport a schematic to SVG via kicad-cli (
export_schematic_pdfreadExport a KiCAD schematic to PDF
export_schematic_svgreadExport schematic to SVG format using kicad-cli.
export_svgreadExport the PCB layout as an SVG vector image, optionally selecting layers and colour mode.
export_symbolreadExtract a single symbol from a .kicad_sym library into a standalone .kicad_sym file.
export_vrmlreadExport the PCB as a VRML 3D model for use in web viewers or simulation tools.
find_componentreadSearch for a PCB component by reference designator or value and return its position and properties.
find_duplicate_symbolsreadGroup symbols in a .kicad_sym that are the same part stored twice under different
find_orphaned_wiresreadFind wire segments with at least one dangling endpoint — not connected to a component pin,
find_overlapping_elementsreadDetect spatially overlapping symbols, wires, and labels in the schematic. Finds duplicate power symbols at the same position, collinear overlapping wires, and labels stacked on top of each other.
find_wires_crossing_symbolsreadFind all wires that cross over component symbol bodies. Wires passing over symbols are unacceptable in schematics — they indicate routing mistakes where a wire was drawn across a component instead of around it.
generate_netlistread
get_backend_statereadReturn the active backend, realtime status, loaded project/board paths, and dirty state.
get_board_2d_viewread
get_board_extentsreadReturn the bounding box (min/max X and Y) of all objects on the current PCB board.
get_board_inforeadRetrieve general information about the current PCB board (dimensions, layer count, DRC status).
get_board_originreadRead back the auxiliary (drill/place) origin and grid origin of a .kicad_pcb in mm.
get_category_toolsreadReturn all tools available in a specific category. Use list_tool_categories first to find valid category names.
get_component_geometryreadReturn separated footprint geometry bboxes: body, pads, courtyard, keepout, fab, silk and text.
get_component_listreadReturn a list of all components on the PCB, optionally filtered by layer or bounding box region.
get_component_padsreadReturn all pads of a PCB component with their positions, net assignments and sizes.
get_component_propertiesreadReturn all properties of a PCB component (position, rotation, layer, value, footprint).
get_datasheet_urlreadGet the LCSC datasheet URL for a component by LCSC number. Returns the direct PDF URL and product page URL. No network request – URL is constructed from the LCSC number alone. Example: get_datasheet_url(
get_design_rulesreadReturn the current PCB design rules (clearance, track width, via sizes, courtyard settings).
get_drc_violationsreadReturn the list of current DRC violations on the PCB, optionally filtered by severity (error, warning).
get_elements_in_regionreadList all symbols, wires, and labels within a rectangular region of the schematic. Useful for understanding what is in a specific area before modifying it.
get_footprint_inforeadGet detailed information about a specific footprint
get_jlcpcb_database_statsreadGet statistics about the local JLCPCB parts database
get_jlcpcb_partread
get_layer_listreadReturn the list of all layers defined in the current PCB board.
get_net_at_pointreadReturns the net name at a given (x, y) coordinate in a schematic, or null if no net label
get_net_connectionsreadGet all connections for a named net
get_net_padsreadReturn every PCB pad attached to a net name or net code.
get_nets_listreadGet a list of all nets in the PCB with optional statistics.
get_pad_positionreadReturn the exact XY position of a specific pad on a PCB component. Use this before routing to get accurate start/end coordinates.
get_padsreadReturn pads for one PCB component, selected refs, or all components, including XY, layer, size and net.
get_project_inforeadGet information about the current project
get_ratsnestreadEstimate ratsnest/airwire segments and lengths from current pad positions grouped by net.
get_registry_partreadGet full details for one registry part by id: description, downloadable files (footprint/symbol/3D), datasheet, license, and provenance. Use the id returned by search_parts_registry.
get_schematic_componentreadGet full component info from a schematic: position, every field
get_schematic_pin_locationsreadReturns the exact x/y coordinates of every pin on a schematic component. Use this before add_schematic_net_label to place labels correctly on pin endpoints.
get_schematic_viewreadReturn a rasterized image of the schematic (PNG by default, or SVG). Uses kicad-cli to export SVG, then converts to PNG via cairosvg. Use this for visual feedback after placing or wiring components.
get_schematic_view_regionreadExport a cropped region of the schematic as an image (PNG or SVG). Specify bounding box coordinates in schematic mm. Useful for zooming into a specific area to inspect wiring or layout.
get_sheet_propertiesreadList hierarchical sheets in a schematic with their name, file, uuid, position, and full property map (built-ins plus custom properties set via set_sheet_property). With sheetName or sheetPath, returns just that sheet.
get_symbol_inforeadGet detailed information about a specific symbol (global or project-scope when projectPath is supplied or a project has been opened).
get_wire_connectionsreadReturns the net name and all wires and component pins connected at a given point.
group_componentsreadGroup multiple PCB components together by name for easier selection and manipulation.
hierarchical_placereadCluster a board
import_3d_modelwriteCopy a 3D model file (.step/.stp/.wrl/.x3d/.iges) into the project
import_eagle_projectwriteImport an Eagle project (.brd + .sch) and convert it to a KiCad project.
import_pcbwriteImport a vendor PCB file (PADS, Altium, Eagle, CADSTAR, Fabmaster, P-CAD, SolidWorks PCB,
import_seswriteImport a Specctra SES (session) file into the current PCB. Use after running Freerouting externally.
import_svg_logowriteImports an SVG file as filled graphic polygons onto a KiCAD PCB layer (default F.SilkS / front silkscreen). Curves are linearised automatically. Ideal for placing a company or project logo on the board.
import_symbolwriteCopy a symbol from one .kicad_sym library into another, with optional rename and overwrite.
is_dirtyreadReturn whether the MCP knows the loaded board has unsaved memory changes or external disk changes.
launch_kicad_uireadLaunch KiCAD UI, optionally with a project file
libraryreadFootprint library access: search, browse, get footprint information
lint_offgridreadReport every off-grid connection-relevant coordinate in a schematic — wire/bus
lint_schematic_cosmeticreadNetlist-safe cosmetic cleanup of a .kicad_sch, applied as raw-text edits that never
list_floating_labelsreadReturns all net labels in the schematic that are not connected to any component pin.
list_footprint_librariesreadList available .pretty footprint libraries and their contents (first 20 footprints per library).
list_graphicsreadList PCB graphic/drawing items such as gr_line, gr_arc, gr_rect, gr_text and dimensions.
list_librariesreadList all available KiCAD footprint libraries
list_library_footprintsreadList all footprints in a specific KiCAD library
list_library_symbolsreadList all symbols in a specific KiCAD symbol library (global or project-scope when projectPath is supplied or a project has been opened).
list_library_tablereadRead a sym-lib-table or fp-lib-table: nickname, type, URI and description of every
list_schematic_componentsreadList all components in a schematic with their references, values, positions, and pins. Essential for inspecting what
list_schematic_labelsreadList all net labels, global labels, and power flags in the schematic.
list_schematic_librariesreadList available KiCAD symbol libraries
list_schematic_netsreadList all nets in the schematic with their connections.
list_schematic_textsreadList all free-form text annotations (notes, headings, documentation strings) in the schematic.
list_schematic_wireswriteList all wires in the schematic with start/end coordinates.
list_symbol_librariesreadList all available KiCAD symbol libraries from global sym-lib-table, plus the project
list_symbol_pinsreadReturn pin names, numbers, and types for a symbol directly from the library — no schematic required. Use this before add_schematic_component to discover pins for connect_to_net calls. Each pin has
list_symbols_in_libraryreadList all symbol names in a .kicad_sym library file.
list_tool_categoriesreadList all available KiCAD tool categories with their descriptions and tool counts. Use this to discover which tools exist; every tool can then be called directly by name.
load_schematicreadLoad an existing KiCAD schematic
modify_tracewriteModify an existing trace (change width, layer, or net).
move_componentwriteMove a PCB component to a new position. Optionally update rotation or flip to a different copper layer.
move_footprint_textwriteMove or update a footprint Reference/Value/user text field without moving the footprint.
move_schematic_componentwriteMove a placed symbol to a new position in the schematic. By default (preserveWires=true) wire endpoints touching the component
move_schematic_net_labelwriteMove a net label (local, global, or hierarchical) to a new position in the schematic. Use currentPosition to disambiguate when multiple labels share the same name.
namereaddescription
open_boardreadOpen a specific .kicad_pcb board file and refresh the MCP in-memory board state.
open_projectreadOpen an existing KiCAD project
parts-registryreadOpen gate-verified parts registry (PartReel by default, no auth): search existing KiCAD parts and download footprint/symbol/3D files before generating custom ones
place_componentreadPlace a component on the PCB
place_component_arrayreadPlace a rectangular grid array of identical components on the PCB with configurable row/column spacing.
query_tracesreadQuery traces on the board with optional filters by net, layer, or bounding box.
query_zonesreadQuery copper zones (filled pours) on the board with optional filters by net, layer, or bounding box. Returns zone net, layers, priority, fill state, and bounding box. Useful for auditing power planes and GND pours that query_traces does not include.
refill_zonesreadRefill all copper zones on the board. WARNING: SWIG path has known segfault risk (see KNOWN_ISSUES.md). Prefer using IPC backend (KiCAD open) or triggering zone fill via KiCAD UI instead.
register_footprint_libraryreadRegister a .pretty footprint library in KiCAD
register_symbol_libraryreadRegister a .kicad_sym library in KiCAD
reload_boardreadReload the current or specified .kicad_pcb from disk, discarding stale in-memory board state.
remove_hierarchical_sheetdestructiveRemove a hierarchical-sheet reference from a parent schematic (the reverse of add_hierarchical_sheet). Identify the sheet by sheetName (matches the sheet
remove_library_table_entrydestructiveRemove one or more entries from a sym-lib-table or fp-lib-table by nickname — the
remove_schematic_component_propertydestructiveRemove a single custom property from a placed schematic symbol. Built-in fields (Reference, Value, Footprint, Datasheet) cannot be removed — KiCad requires them on every symbol. To clear a built-in field, use edit_schematic_component and set its value to an empty string.
rename_symbolwriteRename a symbol in a .kicad_sym library, including its sub-symbol shards (name_0_1, ...) and
04

Trust audit

BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (10 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/server.ts:381
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/server.ts:436
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
.github/README.md:1
<a name="top"></a>
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
setup-macos.sh:186
importlib.import_module(module_name)
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_digikey.py:36
SECRET = "test-client-secret-99999"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_digikey.py:333
token = "tok-secret-value-1234"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
add_gnd_stitching_vias, clear_board_outline, close_project, component, delete_component, delete_graphic, delete_schematic_component, delete_schematic_net_label, delete_schematic_wire, delete_symbol, d
Why it matters. 18 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.flake8
.flake8
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
python/commands/find_duplicate_symbols.py:185
return hashlib.sha1("\n".join(sorted(parts)).encode("utf-8")).hexdigest()[:16]
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests-ts/parts-registry.test.ts:360
filenameForAsset("https://assets.partreel.com/../../../etc/passwd.kicad_mod", "ID", FP),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_get_board_2d_view_save_to_file.py:77
assert base64.b64decode(result["imageData"]) == _FAKE_PNG
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_get_board_2d_view_save_to_file.py:109
assert base64.b64decode(result["imageData"]) == _FAKE_SVG
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_get_board_2d_view_save_to_file.py:200
assert base64.b64decode(result["imageData"]) == _FAKE_SVG
LOWObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
tests/test_get_board_2d_view_save_to_file.py:200
b64decode( ... subprocess.
Why it matters. decodes a payload and executes it
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, express, zod, @cfworker/json-schema, @eslint/js, @types/express, @types/glob
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
python/requirements.txt
Pillow, cairosvg, typing-extensions, colorlog, kicad-skip
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
pytest, pytest-cov, pytest-asyncio, pytest-mock, black, mypy, pylint, flake8
Why it matters. 14 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
kicad-python, sexpdata, kicad-skip, Pillow, pymupdf, cairosvg, colorlog, pydantic
Why it matters. 10 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/JLCPCB_INTEGRATION.md:400
# Credentials are read from the project-root .env (auto-loaded) or the environment:
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/JLCPCB_USAGE_GUIDE.md:37
> may be stale. Use `get_jlcpcb_part` with Open Platform credentials (Approach 3) for
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:1366
Add to your shell profile (`~/.bashrc`, `~/.zshrc`, or `~/.profile`):
Why it matters. instructs the agent to persist itself in the user's environment
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/PLATFORM_GUIDE.md:258
# Permanent (add to ~/.bashrc or ~/.profile)
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha f439a850d105full audit observations/trust-audit/mcp-server/mixelpixx__kicad-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-23f439a850d105BLOCKF52source changed, verdict held
06

Questions

What is the KiCAD MCP server?

KiCAD MCP is a Model Context Protocol (MCP) implementation that enables Large Language Models (LLMs) like Claude to directly interact with KiCAD for printed circuit board design.

What tools does KiCAD expose?

200 in total: 158 read-only, 75 that write, and 18 that can delete or overwrite (add_gnd_stitching_vias, clear_board_outline, close_project, component, delete_component). Every one is listed on this page with its risk.

Is KiCAD safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (52/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 18 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does KiCAD need?

It reads ANTHROPIC_API_KEY, DIGIKEY_CLIENT_ID, JLCPCB_API_KEY and JLCPCB_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does KiCAD run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as kicad-mcp at 2.7.0.

How current is this page?

The grade is for one exact copy of the source (f439a850d105), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement