PenpotBLOCK
Penpot MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AI-Powered Design Workflow Automation Connect Claude AI and other LLMs to Penpot designs via Model Context Protocol
🚀 What is Penpot MCP?
Penpot MCP is a revolutionary Model Context Protocol (MCP) server that bridges the gap between AI language models and Penpot, the open-source design and prototyping platform. This integration enables AI assistants like Claude (in both Claude Desktop and Cursor IDE) to understand, analyze, and interact with your design files programmatically.
🎯 Key Benefits
- 🤖 AI-Native Design Analysis: Let Claude AI analyze your UI/UX designs, provide feedback, and suggest improvements
- ⚡ Automated Design Workflows: Streamline repetitive design tasks with AI-powered automation
- 🔍 Intelligent Design Search: Find design components and patterns across your projects using natural language
- 📊 Design System Management: Automatically document and maintain design systems with AI assistance
- 🎨 Cross-Platform Integration: Works with any MCP-compatible AI assistant (Claude Desktop, Cursor IDE, etc.)
🎥 Demo Video
Check out our demo video to see Penpot MCP in action:
[
10 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
export_object | read | Export a Penpot design object as an image. |
get_cached_files | read | List all files currently stored in the cache. |
get_file | read | Retrieve a Penpot file by its ID and cache it. Don |
get_object_tree | read | Get the object tree structure for a Penpot object ( |
get_project_files | read | Get all files contained within a specific Penpot project. |
get_rendered_component | read | Return a rendered component image by its ID. |
list_projects | read | Retrieve a list of all available Penpot projects. |
penpot_schema | read | Provide the Penpot API schema as JSON. |
penpot_tree_schema | read | Provide the Penpot object tree schema as JSON. |
search_object | read | Search for objects within a Penpot file by name. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (13)
echo "On Ubuntu/Debian: sudo apt install python3-venv"
print(json.dumps(payload, indent=2).replace(password, "********"))
.flake8
.pre-commit-config.yaml
image_id = hashlib.md5(f"{file_id}:{page_id}:{object_id}".encode()).hexdigest()image_id = hashlib.md5(f"{file_id}:{object_id}".encode()).hexdigest()image_id = hashlib.md5(f"{file_id}:{object_id}".encode()).hexdigest()image_id = hashlib.md5(f"{file_id}:{object_id}".encode()).hexdigest()image_id = hashlib.md5(f"{file_id}:{object_id}".encode()).hexdigest()1. Check that your Penpot access token is correctly set in the environment variables
curl -LsSf https://astral.sh/uv/install.sh | sh
system use found in code, not declared in the description
Gates applied: no_behavioural_pass, no_license.
54dd41a59417full audit observations/trust-audit/mcp-server/montevive__penpot.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 54dd41a59417 | BLOCK | D | 69 | first audit |
Questions
What is the Penpot MCP server?
Penpot MCP server
What tools does Penpot expose?
10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Penpot safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Penpot need?
It reads PENPOT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (54dd41a59417), read on 2026-10-06. The repository is watched and re-audited when it changes.