FeuseSAFE
Frontend Useful MCP Tools - Essential utilities for web developers to automate API integration and code generation
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Frontend Useful MCP (Model Context Protocol) Tools - Essential utilities for web developers to automate API integration, Figma design-to-code conversion, and development workflow optimization.
English | 中文
📖 Documentation
feuse-mcp Official Documentation
✨ Features
- 🎨 Figma Integration: Built-in integration with Figma-Context-MCP for seamless Figma design-to-code conversion and automatic asset extraction
- 📝 API Automation: Generate TypeScript interface types, API URL constants, mock data, and request functions from API documentation
- 🖼️ Asset Management: Download SVG and PNG images from Figma files with organized file structure
- 🎯 Similarity Comparison: Compare generated code pages with original Figma prototypes for accuracy validation
- 🛠️ Project Standards: Generate global specification guidance files for Copilot & Cursor based on current project architecture
- 🔧 Color Variables: Extract and convert Figma color variables to CSS/design tokens in specified standards (UnoCSS, TailwindCSS, or custom structures)
🔧 Available Toolset (Continuously Updated)
9aa9ae796b6cOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add feuse-mcp --env FIGMA_API_KEY=${FIGMA_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"feuse-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"FIGMA_API_KEY": "${FIGMA_API_KEY}"
}
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Download-Figma-Images | read | Download SVG and PNG images used in a Figma file based on the IDs of image or icon nodes |
api-automation | read | 理解后端接口文档自动生成接口类型、地址常量、mock数据、请求函数等 |
download-svg-assets | read | 根据图像或图标节点的ID,仅下载Figma文件中使用的SVG资源 |
extract-color-vars | read | 从Figma DSL文件中提取颜色变量,并输出在用户指定的文件中(比如unocss、tailwindcss或者自定义标准文件中等) |
extract-svg-assets | read | 分析figma SDL中的结构,并调用download-svg-assets工具下载Figma文件中使用的SVG资源 |
initialize-project-standard | read | 针对用户指定项目进行分析,生成Copilot 和 cursor对应的全局项目规则 |
similarity-figma | read | 获取Figma原型图,请你结合项目源码并通过原型图与生成的代码页面的截图进行相似性比对 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
"../../node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected]_96eb05a9d65343021e53791dd83f3773/node_modules/tsup/assets/esm_shims.js"() {
"../../node_modules/.pnpm/[email protected]/node_modules/rfdc/index.js"(exports, module) {
"../../node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected]_96eb05a9d65343021e53791dd83f3773/node_modules/tsup/assets/esm_shims.js"() {
"../../node_modules/.pnpm/[email protected]/node_modules/speakingurl/lib/speakingurl.js"(exports, module) {
"../../node_modules/.pnpm/[email protected]/node_modules/speakingurl/index.js"(exports, module) {
vitepress
@figma/rest-api-spec, @types/express, dotenv, express, fastmcp, globals, js-yaml, lodash
Gates applied: no_behavioural_pass.
9aa9ae796b6cfull audit observations/trust-audit/mcp-server/panzer-jack__feuse.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 9aa9ae796b6c | SAFE | B | 89 | first audit |
Questions
What is the Feuse MCP server?
Frontend Useful MCP Tools - Essential utilities for web developers to automate API integration and code generation
What tools does Feuse expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Feuse safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Feuse need?
It reads FIGMA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (9aa9ae796b6c), read on 2026-10-08. The repository is watched and re-audited when it changes.