PlumbCAUTION
Local Figma MCP server with no REST rate limits, no metered tool-call quotas, and a verification loop. Drop-in alternative to Figma's Dev Mode MCP and Framelink for Claude Code, Cursor, Windsurf — works on every plan including Free.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
⭐ If Plumb saves you tokens — or designs you a page — star it on GitHub so others can find it.
Plumb is an AI-native design engineering platform, shipped as a single MCP server. Point it at a Figma file or a live website and it normalises either one into the same semantic design graph — deduped tokens, flexbox-resolved layout, conservative role labels (nav / hero / card ...) — that your coding agent can build from and a verification loop can grade. Point it at a one-line prompt instead and it becomes an AI design director: it researches best-in-class references, extracts a brand, and generates a full, on-brand Figma file on your canvas, then critiques its own render until it clears the bar.
Design → code (Figma or the live web, verified, not vibes) • prompt → design (research → brand → generate → critique) • one semantic design graph underneath both. MCP-native — works with Claude Code, Cursor, Windsurf, or any agent that speaks Model Context Protocol.
📖 Full docs: ****
805f5f08f253OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add plumb-mcp --env FIGMA_TOKEN=${FIGMA_TOKEN} --env UNSPLASH_ACCESS_KEY=${UNSPLASH_ACCESS_KEY} --env PEXELS_API_KEY=${PEXELS_API_KEY} --env PIXABAY_API_KEY=${PIXABAY_API_KEY} -- npx -y [email protected]Exposed tools (28)
26 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
plumb_assets | read | |
plumb_audit | read | |
plumb_brand | read | |
plumb_components | read | |
plumb_describe | read | |
plumb_design | read | |
plumb_diff | read | |
plumb_emit_react | read | |
plumb_fig_node | read | |
plumb_fig_outline | read | |
plumb_fit | read | |
plumb_import_web | write | |
plumb_node | read | |
plumb_outline | read | |
plumb_query | read | |
plumb_review | read | |
plumb_scan_references | read | |
plumb_screenshot | read | |
plumb_search | read | |
plumb_selection | read | |
plumb_source | read | |
plumb_status | read | |
plumb_studio | read | |
plumb_studio_kit | read | |
plumb_studio_page | read | |
plumb_studio_start | write | |
plumb_tokens | read | |
plumb_verify | read |
Trust audit
CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
shared.ts
text.ts
console.log(` estTokens=${compression.estTokens}, token dedup ratio=${compression.dedupRatio.toFixed(3)}`);console.log(`✓ PASS: fixture PDS is under the ${TARGET}-token target and structurally complete.`);CMD node -e "fetch('http://127.0.0.1:'+(process.env.PLUMB_BRIDGE_PORT||31337)+'/healthz').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))""QA-strict on appearance — colour (ΔE2000), icon/asset fidelity, box-shadow, " +
.checkov.yaml
.helmignore
const hash = createHash("sha1").update(key).digest("hex").slice(0, 20);const hash = createHash("sha1").update(r.bytes!).digest("hex").slice(0, 10);import type { CirEdge, CirNode, SemanticGraph } from "../../src/semantic/graph";import type { PdsDocument } from "../../src/pds";import { fetchNodeViaRest } from "../../src/figma/rest";import { resolveFigmaTarget } from "../../src/figma/url";import { normalizeToBudget } from "../../src/normalize/budget";docker compose up bridge # bridge + Plumb Studio on http://127.0.0.1:31337
open http://127.0.0.1:31337/
then open http://127.0.0.1:{{ .Values.bridge.port }}/open http://127.0.0.1:31337/
})();<\/script>`;function fm(e){return e.includes("</body>")?e.replace("</body>",`${Ws}</body>`):e+Ws}function dm(e,t,n=8e3){return new Promise((r,l)=>{let i=!1;const o=()=>{i||(i=!0,clearTimeout(s),wreturn JSON.parse(decodeURIComponent(escape(atob(h.slice(4)))));
it("carries a numeric ΔE distance so the caller can rank findings", () => {@modelcontextprotocol/sdk, openfig-core, ws, zod, @figma/plugin-typings, @types/node, @types/ws, @vitest/coverage-v8
react, react-dom, @types/react, @types/react-dom, @vitejs/plugin-react, typescript, vite
react, react-dom, @types/react, @types/react-dom, @vitejs/plugin-react, typescript, vite
Gates applied: no_behavioural_pass.
805f5f08f253full audit observations/trust-audit/mcp-server/tathagat22__plumb.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 805f5f08f253 | CAUTION | C | 77 | first audit |
Questions
What is the Plumb MCP server?
Local Figma MCP server with no REST rate limits, no metered tool-call quotas, and a verification loop. Drop-in alternative to Figma's Dev Mode MCP and Framelink for Claude Code, Cursor, Windsurf — works on every plan including Free.
What tools does Plumb expose?
28 in total: 26 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Plumb safe to connect to an agent?
With care. The audit graded it C (77/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Plumb need?
It reads ANTHROPIC_API_KEY, FIGMA_ACCESS_TOKEN, FIGMA_TOKEN, PEXELS_API_KEY, PIXABAY_API_KEY, PLUMB_FILE_KEY and UNSPLASH_ACCESS_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Plumb run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as plumb-studio at 0.12.0.
How current is this page?
The grade is for one exact copy of the source (805f5f08f253), read on 2026-10-07. The repository is watched and re-audited when it changes.