Atlas / MCP servers / neka-nat / FreeCAD

FreeCADBLOCK

mcp/neka-nat/freecad-1

FreeCAD MCP(Model Context Protocol) server

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
17 8r · 8w · 1d
Transport
—
License
MIT
Stars
2,455
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/neka-nat-freecad-mcp)

Control FreeCAD from Claude Desktop and other MCP clients. Create and edit models, run Python scripts, inspect documents, and run FEM analyses.

Demo

Design a flange:

See more demos and examples for a toy car, modelling from a 2D drawing, and agent integrations.

Quick start

You need FreeCAD and uv / uvx. FreeCAD MCP has two components: an addon running inside FreeCAD and an MCP server launched by your client.

1. Install and start the FreeCAD addon

git clone https://github.com/neka-nat/freecad-mcp.git
cd freecad-mcp

Copy addon/FreeCADMCP into your FreeCAD addon directory, then restart FreeCAD. Select the MCP Addon workbench and click Start RPC Server in the FreeCAD MCP toolbar.

See the installation guide for platform-specific commands and screenshots.

2. Connect Claude Desktop

Add the following entry to claude_desktop_config.json:

{
"mcpServers": {
"freecad": {
"command": "uvx",
"args": ["freecad-mcp"]
}
}
}

Restart Claude Desktop to load the configuration, keep FreeCAD open with its RPC server running, and ask Claude to create a model. Connections use localhost by default.

Documentation

Read from source at commit b672609c51f3OBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add freecad-mcp -- uvx freecad-mcp
claude-desktop
{
  "mcpServers": {
    "freecad-mcp": {
      "command": "uvx",
      "args": [
        "freecad-mcp"
      ]
    }
  }
}
03

Exposed tools (17)

8 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_documentwriteCreate a new document in FreeCAD.
create_objectwriteCreate a new object in FreeCAD.
delete_objectdestructiveDelete an object in FreeCAD.
edit_objectwriteEdit an object in FreeCAD.
execute_codewriteExecute arbitrary Python code in FreeCAD.
execute_code_asyncwriteExecute Python code in FreeCAD without waiting for completion.
execute_code_headlesswriteRun a FreeCAD Python script in a separate headless `freecadcmd` process.
get_async_statusreadReport the state of background jobs started by execute_code_async.
get_objectreadGet an object from a document.
get_objectsreadGet all objects in a document.
get_parts_listreadGet the list of parts in the parts library addon.
get_rpc_statusreadGet RPC and FreeCAD GUI-dispatch health.
get_viewreadGet a screenshot of the active view.
insert_part_from_librarywriteInsert a part from the parts library addon.
list_documentsreadGet the list of open documents in FreeCAD.
reload_documentreadClose and re-open a document to pick up external file changes.
run_fem_analysiswriteRun the CalculiX solver on an existing Fem::FemAnalysis container and return summary results.
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (13)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
addon/FreeCADMCP/rpc_server/rpc_server.py:300
exec(code, _EXEC_NAMESPACE)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
addon/FreeCADMCP/rpc_server/rpc_server.py:381
exec(code, _EXEC_NAMESPACE)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/freecad_mcp/headless.py:87
argv = command + ["-c", f"exec(open({script!r}, encoding='utf-8').read())"]
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMHard-coded secrets · inv.env_committed · CWE-798, CWE-321
examples/adk/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_object
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/adk/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_parts_library.py:81
module.insert_part_from_library("../../../secret.FCStd")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/installation.md:127
py -3.12 -c "import socket, xmlrpc.client; socket.setdefaulttimeout(5); s = xmlrpc.client.ServerProxy('http://127.0.0.1:9875'); print(s.ping()); print(s.get_rpc_status())"
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/execution.md:18
name collisions; code execution still has FreeCAD's full privileges.
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/examples.md:25
[Conversation history](https://claude.ai/share/7b48fd60-68ba-46fb-bb21-2fbb17399b48)
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
assets/freecad_mcp4.gif
assets/freecad_mcp4.gif
Why it matters. 1912674 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/from_2ddrawing.gif
assets/from_2ddrawing.gif
Why it matters. 2615757 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/make_toycar4.gif
assets/make_toycar4.gif
Why it matters. 2754318 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha b672609c51f3full audit observations/trust-audit/mcp-server/neka-nat__freecad-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-24b672609c51f3BLOCKD66source changed, verdict held
06

Questions

What is the FreeCAD MCP server?

FreeCAD MCP(Model Context Protocol) server

What tools does FreeCAD expose?

17 in total: 8 read-only, 8 that write, and 1 that can delete or overwrite (delete_object). Every one is listed on this page with its risk.

Is FreeCAD safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does FreeCAD need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (b672609c51f3), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement