Atlas / MCP servers / montevive / Penpot

PenpotBLOCK

mcp/montevive/penpot

Penpot MCP server

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
10 10r · 0w · 0d
Transport
—
License
—
Stars
241
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI-Powered Design Workflow Automation Connect Claude AI and other LLMs to Penpot designs via Model Context Protocol

🚀 What is Penpot MCP?

Penpot MCP is a revolutionary Model Context Protocol (MCP) server that bridges the gap between AI language models and Penpot, the open-source design and prototyping platform. This integration enables AI assistants like Claude (in both Claude Desktop and Cursor IDE) to understand, analyze, and interact with your design files programmatically.

🎯 Key Benefits

  • 🤖 AI-Native Design Analysis: Let Claude AI analyze your UI/UX designs, provide feedback, and suggest improvements
  • ⚡ Automated Design Workflows: Streamline repetitive design tasks with AI-powered automation
  • 🔍 Intelligent Design Search: Find design components and patterns across your projects using natural language
  • 📊 Design System Management: Automatically document and maintain design systems with AI assistance
  • 🎨 Cross-Platform Integration: Works with any MCP-compatible AI assistant (Claude Desktop, Cursor IDE, etc.)

🎥 Demo Video

Check out our demo video to see Penpot MCP in action:

[![Penpot MCP Demo](https://img.y

Read from source at commit 54dd41a59417OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add penpot-mcp --env PENPOT_PASSWORD=${PENPOT_PASSWORD} -- uvx penpot-mcp
claude-desktop
{
  "mcpServers": {
    "penpot-mcp": {
      "command": "uvx",
      "args": [
        "penpot-mcp"
      ],
      "env": {
        "PENPOT_PASSWORD": "${PENPOT_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (10)

10 read · 0 write · 0 destructive.

ToolRiskDescription
export_objectreadExport a Penpot design object as an image.
get_cached_filesreadList all files currently stored in the cache.
get_filereadRetrieve a Penpot file by its ID and cache it. Don
get_object_treereadGet the object tree structure for a Penpot object (
get_project_filesreadGet all files contained within a specific Penpot project.
get_rendered_componentreadReturn a rendered component image by its ID.
list_projectsreadRetrieve a list of all available Penpot projects.
penpot_schemareadProvide the Penpot API schema as JSON.
penpot_tree_schemareadProvide the Penpot object tree schema as JSON.
search_objectreadSearch for objects within a Penpot file by name.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (13)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
fix-lint-deps.sh:18
echo "On Ubuntu/Debian: sudo apt install python3-venv"
Why it matters. asks for elevated privileges
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
penpot_mcp/api/penpot_api.py:222
print(json.dumps(payload, indent=2).replace(password, "********"))
LOWInventory / provenance · inv.hidden_file · CWE-1104
.flake8
.flake8
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
penpot_mcp/server/mcp_server.py:252
image_id = hashlib.md5(f"{file_id}:{page_id}:{object_id}".encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
penpot_mcp/server/mcp_server.py:308
image_id = hashlib.md5(f"{file_id}:{object_id}".encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_mcp_server.py:251
image_id = hashlib.md5(f"{file_id}:{object_id}".encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_mcp_server.py:356
image_id = hashlib.md5(f"{file_id}:{object_id}".encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_mcp_server.py:469
image_id = hashlib.md5(f"{file_id}:{object_id}".encode()).hexdigest()
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE_INTEGRATION.md:73
1. Check that your Penpot access token is correctly set in the environment variables
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CONTRIBUTING.md:40
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha 54dd41a59417full audit observations/trust-audit/mcp-server/montevive__penpot.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0654dd41a59417BLOCKD69first audit
06

Questions

What is the Penpot MCP server?

Penpot MCP server

What tools does Penpot expose?

10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Penpot safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Penpot need?

It reads PENPOT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (54dd41a59417), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement