Atlas / MCP servers / patrickchugh / Terravision

TerravisionBLOCK

mcp/patrickchugh/terravision

Professional cloud architecture diagrams with official AWS, Azure and GCP icons, from Terraform code or a plain JSON graph. MCP server + agent skill.

Verdict
BLOCK
Grade
F
Trust score
52 /100
Exposed tools
2 2r · 0w · 0d
Transport
sse · stdio
License
AGPL-3.0
Stars
1,639
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Turn Terraform or JSON into professional cloud architecture diagrams with official AWS, Azure and GCP styles

[](https://github.com/patrickchugh/terravision/actions/workflows/lint-and-test.yml) [](https://pypi.org/project/terravision/) [](https://pypi.org/project/terravision/) [](https://pypi.org/project/terravision/) [](https://github.com/patrickchugh/terravision/stargazers) [](https://github.com/patrickchugh/terravision/blob/main/LICENSE) [](https://github.com/psf/black)

📖 [Full documentation site →](https://patrickchugh.github.io/terravision/)

Ask your AI assistant for a cloud architecture diagram, in plain words, and get the diagram a cloud architect would draw: the official AWS, Azure and GCP icons, with every resource in its VPC, subnet, zone or resource group. From a description, from your Terraform code, or the other way round, with the Terraform written from the diagram. TerraVision runs on your own computer and needs no cloud access.

Get started with your AI assistant

1. Install the prerequisites (once)

TerraVision needs Graphviz (to draw) and Git. uv runs TerraVision for Claude Code, Codex, Gemini CLI and other MCP clients; Claude Desktop brings its own

Read from source at commit 675c4d7defe1OBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add terravision -- uvx terravision==0.48.0 mcp
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
diagram_filereadReturn a rendered diagram file
open_diagram_filereadOpen a rendered diagram file for the user on their own computer.
04

Trust audit

BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (8 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
modules/resource_handlers_azure.py:660
zone = str(eval(zone))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
modules/llm.py:247
"~/.aws/credentials, IAM role, or SSO.",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
modules/tgwrapper.py:570
"(e.g., mount ~/.ssh). For HTTPS sources, ensure credentials "
Why it matters. touches a credential store
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
modules/config_loader.py:89
config_module = importlib.import_module(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
modules/config_loader.py:144
config_module = importlib.import_module(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
modules/drawing.py:174
package = importlib.import_module(package_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
modules/drawing.py:179
module = importlib.import_module(full_module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
modules/drawio_emitter.py:137
pkg = importlib.import_module(pkg_name)
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/aws_terraform/api_gateway_rest_lambda/lambda.zip
lambda.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/aws_terraform/elasticache_redis/lambda.zip
lambda.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/aws_terraform/elasticache_replication/lambda.zip
lambda.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/aws_terraform/eventbridge_lambda/lambda.zip
lambda.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/aws_terraform/eventbridge_lambda/tests/fixtures/aws_terraform/sns_sqs_lambda/lambda.zip
lambda.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcpb/.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/lint-and-test.yml:80
touch id_rsa.pub
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/lint-and-test.yml:81
chmod 777 id_rsa.pub
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_mcp_service.py:64
("../../etc/passwd", "passwd"),
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/demo-azure.html:519
<image xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAQAAAAEACAYAAABccqhmAAAACXBIWXMAANH5AADR+QGceVN3AAAAGXRFWHRTb2Z0d2FyZQB3d3cuaW5rc2NhcGUub3Jnm+48GgAAIABJREFUeJztnXl0HNWBr7+q6k1q7bIs2ZI
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/demo-azure.html:527
<image xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAQAAAAEACAYAAABccqhmAAAACXBIWXMAANH5AADR+QGceVN3AAAAGXRFWHRTb2Z0d2FyZQB3d3cuaW5rc2NhcGUub3Jnm+48GgAAF1BJREFUeJzt3XlwVdd9B/Dvufe+TU96ktD
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/demo-azure.html:540
<image xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAQAAAAEACAYAAABccqhmAAAACXBIWXMAANH5AADR+QGceVN3AAAAGXRFWHRTb2Z0d2FyZQB3d3cuaW5rc2NhcGUub3Jnm+48GgAAF1BJREFUeJzt3XlwVdd9B/Dvufe+TU96ktD
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/demo-azure.html:553
<image xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAQAAAAEACAYAAABccqhmAAAACXBIWXMAANH5AADR+QGceVN3AAAAGXRFWHRTb2Z0d2FyZQB3d3cuaW5rc2NhcGUub3Jnm+48GgAAF1BJREFUeJzt3XlwVdd9B/Dvufe+TU96ktD
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/demo-azure.html:566
<image xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAQAAAAEACAYAAABccqhmAAAACXBIWXMAANH5AADR+QGceVN3AAAAGXRFWHRTb2Z0d2FyZQB3d3cuaW5rc2NhcGUub3Jnm+48GgAADvpJREFUeJzt3X+MHOddx/HPs7u399Nn311
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
modules/html_renderer.py:421
raw = base64.b64decode(candidate_padded, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_mcp_diagram_view.py:126
assert base64.b64decode(png["blob"]).startswith(b"\x89PNG")

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 675c4d7defe1full audit observations/trust-audit/mcp-server/patrickchugh__terravision.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-29675c4d7defe1BLOCKF52first audit
06

Questions

What is the Terravision MCP server?

Professional cloud architecture diagrams with official AWS, Azure and GCP icons, from Terraform code or a plain JSON graph. MCP server + agent skill.

What tools does Terravision expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Terravision safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (52/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Terravision need?

No credential environment variables were found in its source, so it appears to need none.

How does Terravision run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on PyPI as terravision.

How current is this page?

The grade is for one exact copy of the source (675c4d7defe1), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement