Atlas / MCP servers / mixelpixx / Konnect

KonnectCAUTION

mcp/mixelpixx/konnect

AI-assisted PCB design for KiCAD 10. Native KiCAD plugin — a single Rust binary exposing 217 schematic, layout, routing, placement, design-review, and manufacturing tools to Claude, or the LLM of your choosing

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
36 18r · 15w · 3d
Transport
streamable-http
License
AGPL-3.0
Stars
724
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI-assisted PCB design for KiCAD 10. Konnect is a native KiCAD plugin — a single Rust binary — that lets Claude and other AI assistants design schematics and PCBs through the Model Context Protocol (MCP).

226 tools across 21 on-demand toolsets. Schematic capture, PCB layout and routing, ERC/DRC, design-review audits, JLCPCB part search, reference circuits, and a full manufacturing export pipeline — with bundled skills and agents that teach Claude KiCAD conventions out of the box.

Status: beta. The core toolchain is tested and working, but this is a young release and it wants real-world mileage and review. Issues and PRs are welcome — see CONTRIBUTING.md and the naming conventions.
## Add realtime research to KiCAD MCP and Konnect. Introducing Nimrod **Nimrod** is our web-research MCP server: quality-scored Google search, clean webpage extraction, and deep multi-source research. Design the board with Konnect while Nimrod pulls live parts availability, datasheets, and errata — no more guessing from year-old training data - Works with claude.ai, Claude Desktop, Claude Code, VS Code, and any MCP client - 1 credit = 1 search · extraction always free · free 50-credit trial, no card - Official MCP Registry: `ai.orchis/nimrod`

Why Konnect exists

Konnect is the successor to KiCAD-MCP-Server, a Python/TypeScript project that proved AI-driven PCB design works — and, in the process, showed exactly where that architecture runs out of road. Konnect was built to fix those specific problems:

The call path was too long. In the original server, a single tool

Read from source at commit 83016057adf2OBSERVED · 2026-09-19
02

Exposed tools (36)

18 read · 15 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_mounting_holewrite
align_componentsread
configreadUser preferences, project rules, design rules, fab constraints — call load_user_config at session start
create_footprintwrite
design_reviewreadAI-powered design audits: decoupling, connections, power rails, DFM, BOM health
edit_componentwrite
edit_footprint_padwrite
editor_navigationreadObserve and semantically navigate exact KiCad editor, document, sheet, selection, and cross-probe context
integrationreadJLCPCB parts database, local Freerouting MCP routing, datasheet URLs
librarywriteSearch, register, and author symbol and footprint libraries — create symbols and footprints, edit pads, graphics, metadata and 3D models
load_toolsetread
manufacturingreadDesign-to-fab pipeline: export Gerber+BOM+positions package, validate for fab house, estimate cost
pcb_boardwriteBoard outline, layers, zones, mounting holes, board text, SVG logo import
pcb_componentswritePlace, refresh, move, rotate, flip, align, duplicate and repair PCB footprints; inspect pads; inspect and edit a placed footprint
pcb_exportreadGerber, PDF, SVG, 3D model, BOM, Specctra DSN, pick-and-place, DRC, DXF/GenCAD/IPC-2581/ODB++
pcb_routingreadTraces, vias, copper pours, net classes, differential pairs, and strict Specctra SES import
place_componentread
place_component_arrayread
placementreadPlacement quality and automation: score with named deductions, plan decoupling rows and BGA fanouts, first placement, force-directed refinement
projectwriteCreate, open, save, rename, snapshot KiCAD projects, and launch the live schematic viewer
register_footprint_libraryread
run_drcwrite
sch_analysisreadNet connectivity, pin queries, trace paths, overlap/orphan detection
sch_batchdestructiveBulk add, edit, delete, and move schematic elements in one call
sch_busreadBuses, bus entries, and fanning a group of pins out onto a bus
sch_componentsdestructiveAdd, edit, move, rotate, and delete schematic symbols, and set the page size
sch_exportwriteExport schematic to SVG/PDF/PNG/netlist, run ERC, and synchronize a live PCB
sch_hierarchydestructiveHierarchical sheets: add/edit/move/delete/duplicate a sheet, hierarchy and page-numbering queries, import/add/edit/delete sheet pins, pin/label sync validation
sch_wiringreadWires, net labels, power symbols, junctions, no-connects, pin-to-pin connections
set_footprint_graphicswrite
set_footprint_metadatawrite
set_footprint_modelswrite
templatesreadReference circuit library: USB-C, LDO, buck converter, STM32, I2C, LED — verified component values
update_footprints_from_librarywrite
update_pcb_from_schematicwrite
verificationreadDRC, design rules, layer constraints, clearance checks, KiCAD UI control (ERC is in sch_export)
03

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (15 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (18)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/konnect-core/src/freerouting_mcp.rs:36
"--api_server-endpoints=http://127.0.0.1:37864",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/konnect-core/src/freerouting_mcp.rs:39
"--mcp_server-endpoints=http://127.0.0.1:37964",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/konnect-core/src/freerouting_mcp.rs:842
assert!(arguments.contains(&"--api_server-endpoints=http://127.0.0.1:37864"));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/konnect-core/src/freerouting_mcp.rs:844
assert!(arguments.contains(&"--mcp_server-endpoints=http://127.0.0.1:37964"));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/konnect-core/src/native_specctra_bridge.rs:290
address: "http://127.0.0.1:32123".to_string(),
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
sch_batch, sch_components, sch_hierarchy
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.binary · CWE-1104
crates/konnect-core/tests/fixtures/board_only_footprint.ipc.bin
board_only_footprint.ipc.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
crates/konnect-core/tests/fixtures/board_only_shared_reference.ipc.bin
board_only_shared_reference.ipc.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
crates/konnect-core/tests/fixtures/issue_474_copper_zone_0.ipc.bin
issue_474_copper_zone_0.ipc.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
crates/konnect-core/tests/fixtures/issue_474_r1.ipc.bin
issue_474_r1.ipc.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
crates/konnect-core/tests/fixtures/issue_474_zone_0.ipc.bin
issue_474_zone_0.ipc.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:77
tar czf ../../../${{ env.BINARY_NAME }}-${{ github.ref_name }}-${{ matrix.target }}.tar.gz ${{ env.BINARY_NAME }}
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/konnect-core/src/mcp/handler.rs:1019
const CARRY: &str = include_str!("../../tests/fixtures/no_connect_carry_kicad10.kicad_sch");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/konnect-core/src/mcp/handler.rs:1351
include_str!("../../tests/fixtures/annotate_duplicates.kicad_sch"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/konnect-core/src/mcp/handler.rs:1468
include_str!("../../tests/fixtures/rotate_junctions_kicad10.kicad_sch"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/konnect-core/src/mcp/handler.rs:1878
let source = include_str!("../../tests/fixtures/socket_kicad10.kicad_mod");
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
crates/konnect/assets/agents/kicad-design-review-agent.md:16
You are a senior hardware design reviewer. Your job is to find every supported issue before fabrication and to distinguish direct evidence from heuristics. Exact requirements and datasheets decide whe

Gates applied: no_behavioural_pass.

Audited 2026-09-19 · audit v0.4.1 · source sha 83016057adf2full audit observations/trust-audit/mcp-server/mixelpixx__konnect.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-1983016057adf2CAUTIONB81first audit
05

Questions

What is the Konnect MCP server?

AI-assisted PCB design for KiCAD 10. Native KiCAD plugin — a single Rust binary exposing 217 schematic, layout, routing, placement, design-review, and manufacturing tools to Claude, or the LLM of your choosing

What tools does Konnect expose?

36 in total: 18 read-only, 15 that write, and 3 that can delete or overwrite (sch_batch, sch_components, sch_hierarchy). Every one is listed on this page with its risk.

Is Konnect safe to connect to an agent?

With care. The audit graded it B (81/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Konnect need?

No credential environment variables were found in its source, so it appears to need none.

How does Konnect run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (83016057adf2), read on 2026-09-19. The repository is watched and re-audited when it changes.

Advertisement