Starwind UISAFE
Framework-aware Starwind UI v3 tools for Astro and React setup, components, docs, and migration.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Official MCP Registry · io.github.starwind-ui/mcp
A TypeScript Model Context Protocol server for Starwind UI v3 and Starwind Pro. It gives AI clients current, framework-aware guidance for Astro and React projects.
Quick start
For the maintained client setup guide, see the Starwind UI MCP documentation.
Codex (~/.codex/config.toml):
[mcp_servers.starwind_ui] command = "npx" args = ["-y", "@starwind-ui/mcp"] enabled = true
Claude Code (.mcp.json) or Cursor (.cursor/mcp.json):
{
"mcpServers": {
"starwind-ui": {
"command": "npx",
"args": ["-y", "@starwind-ui/mcp"]
}
}
}Restart the client or reload its MCP servers after changing the configuration.
v3 model
Starwind UI v3 has three related surfaces. The MCP keeps them distinct:
ff34cd1d245aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp -- npx -y @starwind-ui/[email protected]
Exposed tools (17)
13 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
button | read | An interactive button. |
combobox | read | A searchable selection component. |
fetch_llm_data | read | Fetches LLM data from starwind.dev (rate limited to 3 requests per minute, with caching) |
get_documentation | read | Returns documentation links for Starwind UI |
get_package_manager | read | Detects and returns the current package manager information |
image | read | An Astro image component. |
init_project | read | Initializes a new project with Starwind UI |
install_component | write | Generates installation commands for Starwind UI components |
migration | read | Migrate to v3. |
search_starwind_pro_blocks | read | Searches Starwind Pro blocks by query, category, or plan type. Returns matching blocks with install commands. Use this to find pre-built UI blocks like heroes, footers, pricing tables, etc. IMPORTANT: Pro blocks require the project to be initialized with |
starwind_add | write | Generates validated Starwind UI v3 install commands for styled components, vendored primitives, or Starwind Pro blocks, with optional Astro or React targeting. |
starwind_docs | read | Fetches current Starwind UI v3 documentation across styled components, primitives, Runtime, migration, and Astro or React framework guides. |
starwind_init | read | Generates a Starwind UI v3 initialization command for an existing Astro or React project. The CLI auto-detects the framework unless an override is provided. Paid Pro authorization is opt-in and currently targets Astro. |
starwind_migrate | read | Generates the safe Starwind UI v3 migration command for a legacy Astro project. Interactive migration is the default; non-interactive overwrite behavior must be explicitly requested. |
starwind_search | read | Searches Starwind UI v3 styled components, Primitive adapters, and Starwind Pro blocks with framework-aware results. |
update_component | write | Generates update commands for Starwind UI components |
vite-react | write | Install with Vite and React. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
.prettierrc.mjs
const pkg = require("../../package.json");} from "../../test/starwind_manifest_fixture.js";
} from "../../test/starwind_manifest_fixture.js";
const result = await starwindDocsTool.handler({ topic: "../../secret", surface: "component" });"https://starwind.dev/docs/components/../../secret.md",
@modelcontextprotocol/sdk, dotenv, zod, @changesets/cli, @eslint/js, @types/node, @vitest/coverage-v8, eslint
Gates applied: no_behavioural_pass.
ff34cd1d245afull audit observations/trust-audit/mcp-server/starwind-ui__starwind-ui-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ff34cd1d245a | SAFE | B | 89 | first audit |
Questions
What is the Starwind UI MCP server?
Framework-aware Starwind UI v3 tools for Astro and React setup, components, docs, and migration.
What tools does Starwind UI expose?
17 in total: 13 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Starwind UI safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Starwind UI need?
No credential environment variables were found in its source, so it appears to need none.
How does Starwind UI run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @starwind-ui/mcp at 0.5.1.
How current is this page?
The grade is for one exact copy of the source (ff34cd1d245a), read on 2026-10-08. The repository is watched and re-audited when it changes.