FreeCADBLOCK
FreeCAD MCP(Model Context Protocol) server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/neka-nat-freecad-mcp)
Control FreeCAD from Claude Desktop and other MCP clients. Create and edit models, run Python scripts, inspect documents, and run FEM analyses.
Demo
Design a flange:
See more demos and examples for a toy car, modelling from a 2D drawing, and agent integrations.
Quick start
You need FreeCAD and uv / uvx. FreeCAD MCP has two components: an addon running inside FreeCAD and an MCP server launched by your client.
1. Install and start the FreeCAD addon
git clone https://github.com/neka-nat/freecad-mcp.git cd freecad-mcp
Copy addon/FreeCADMCP into your FreeCAD addon directory, then restart FreeCAD. Select the MCP Addon workbench and click Start RPC Server in the FreeCAD MCP toolbar.
See the installation guide for platform-specific commands and screenshots.
2. Connect Claude Desktop
Add the following entry to claude_desktop_config.json:
{
"mcpServers": {
"freecad": {
"command": "uvx",
"args": ["freecad-mcp"]
}
}
}Restart Claude Desktop to load the configuration, keep FreeCAD open with its RPC server running, and ask Claude to create a model. Connections use localhost by default.
Documentation
b672609c51f3OBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add freecad-mcp -- uvx freecad-mcp
{
"mcpServers": {
"freecad-mcp": {
"command": "uvx",
"args": [
"freecad-mcp"
]
}
}
}Exposed tools (17)
8 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_document | write | Create a new document in FreeCAD. |
create_object | write | Create a new object in FreeCAD. |
delete_object | destructive | Delete an object in FreeCAD. |
edit_object | write | Edit an object in FreeCAD. |
execute_code | write | Execute arbitrary Python code in FreeCAD. |
execute_code_async | write | Execute Python code in FreeCAD without waiting for completion. |
execute_code_headless | write | Run a FreeCAD Python script in a separate headless `freecadcmd` process. |
get_async_status | read | Report the state of background jobs started by execute_code_async. |
get_object | read | Get an object from a document. |
get_objects | read | Get all objects in a document. |
get_parts_list | read | Get the list of parts in the parts library addon. |
get_rpc_status | read | Get RPC and FreeCAD GUI-dispatch health. |
get_view | read | Get a screenshot of the active view. |
insert_part_from_library | write | Insert a part from the parts library addon. |
list_documents | read | Get the list of open documents in FreeCAD. |
reload_document | read | Close and re-open a document to pick up external file changes. |
run_fem_analysis | write | Run the CalculiX solver on an existing Fem::FemAnalysis container and return summary results. |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (3 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (13)
exec(code, _EXEC_NAMESPACE)
exec(code, _EXEC_NAMESPACE)
argv = command + ["-c", f"exec(open({script!r}, encoding='utf-8').read())"].env
delete_object
.env
module.insert_part_from_library("../../../secret.FCStd")py -3.12 -c "import socket, xmlrpc.client; socket.setdefaulttimeout(5); s = xmlrpc.client.ServerProxy('http://127.0.0.1:9875'); print(s.ping()); print(s.get_rpc_status())"name collisions; code execution still has FreeCAD's full privileges.
[Conversation history](https://claude.ai/share/7b48fd60-68ba-46fb-bb21-2fbb17399b48)
assets/freecad_mcp4.gif
assets/from_2ddrawing.gif
assets/make_toycar4.gif
Gates applied: no_behavioural_pass.
b672609c51f3full audit observations/trust-audit/mcp-server/neka-nat__freecad-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | b672609c51f3 | BLOCK | D | 66 | source changed, verdict held |
Questions
What is the FreeCAD MCP server?
FreeCAD MCP(Model Context Protocol) server
What tools does FreeCAD expose?
17 in total: 8 read-only, 8 that write, and 1 that can delete or overwrite (delete_object). Every one is listed on this page with its risk.
Is FreeCAD safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does FreeCAD need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (b672609c51f3), read on 2026-09-24. The repository is watched and re-audited when it changes.