AutocadCAUTION
Production-grade AutoCAD MCP server for AI agents — 122 tools, dual COM (live AutoCAD) + headless ezdxf engines, ISO GD&T and dimension-tolerance validation for CAD automation.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Production-grade AutoCAD automation for AI agents. Live through COM on Windows, or headless through ezdxf anywhere — one typed contract, two engines.
[](https://github.com/U-C4N/Autocad-MCP/actions/workflows/ci.yml) [](https://pypi.org/project/autocad-mcp-pro/) [](https://pypi.org/project/autocad-mcp-pro/) [](https://github.com/U-C4N/Autocad-MCP/blob/main/pyproject.toml) [](https://github.com/U-C4N/Autocad-MCP/blob/main/LICENSE)
Install · What's new · Tools · Engines · Evidence · Limits · Config · Changelog
Not a mockup. Every line on this sheet was drawn by the tools this server exposes — ISO layers, involute gear geometry, DIN 6885 keyway, section A-A, ISO 129 dimensions, an ISO 286 H7 bore fit, ISO 7200 title block — then rendered headlessly by viewscreenshot. drawingcritique returns 0 issues on it. Rebuild it with python scripts/renderreadmeshowcase.py.
v1.6 release snapshot: 247 tools · 8 resources · 5 prompt templates · 4992 collected te
e7c5de2b3c33OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add autocad-mcp-pro -- None autocad-mcp-pro==1.6.0
Exposed tools (93)
62 read · 27 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analysis_bounding_box | read | Get the bounding box (extents) of all entities in the drawing. |
analysis_entity_stats | read | Analyze the drawing and return entity counts grouped by type and by layer. |
analysis_find_in_region | read | Find all entities within a rectangular region (crossing selection). |
analysis_layer_stats | read | Return detailed statistics for each layer: entity count, types present. |
analysis_list_properties | read | AutoCAD |
analysis_measure_distance | read | Measure the Euclidean distance between two points. |
analysis_select_by_layer | read | Get all entities on a specific layer. Returns entity list with handles. |
analysis_select_by_type | read | Get all entities of a specific type. Returns entity list with handles. |
block_create_from_entities | write | Create a new block definition from existing entities in the drawing. |
block_find_references | write | Find all insert references to a specific block definition. |
block_insert | write | Insert a block and optionally set attribute values. |
block_list | read | List all block definitions in the drawing (name, origin, attribute count, entity count). |
boundary_from_entities | read | Chain the given entities into one closed polyline. |
boundary_trace | read | AutoCAD |
dimension_aligned | write | Create an aligned dimension that measures the true distance between two points. |
dimension_angular | write | Create an angular dimension measuring the angle between two lines from a vertex. |
dimstyle_list | read | Every DIMSTYLE table entry with the seventeen preset variables |
dimstyle_modify | write | Change variables on an existing dimension style. |
document_close | read | Close a document and report `saved`, `discarded_changes` and the new `active`. |
document_list | read | Every open document with `name`, `path`, `active`, `saved` and |
drawing_audit | read | Audit the drawing: repair every fixable structural problem, and report it. |
drawing_close | write | Close the active document. If save is True (default), the drawing is |
drawing_export_dxf | read | Export the current drawing as a DXF file. |
drawing_info | read | Get comprehensive metadata for the current drawing. |
drawing_purge | destructive | Purge all unused objects (layers, blocks, linetypes, styles) from the drawing. |
drawing_redo | read | Reapply the operation you just undid. |
drawing_save | write | Save the current drawing. Optionally specify a new path. |
drawing_template_list | write | The templates `drawing_new(template=<name>)` can start from. |
drawing_undo | read | Undo the last drawing operation. |
entity_batch_create | write | Create multiple entities in a single call for better performance. |
entity_copy | write | Copy an entity and move the copy by (dx, dy, dz). Returns info of the new copy. |
entity_create_point | write | Create a point marker entity at (x, y). |
entity_create_polyline | write | Create a lightweight 2D polyline through the given points. |
entity_create_rectangle | write | Create a closed rectangular polyline between two corner points. |
entity_create_spline | write | Create a NURBS spline curve passing through the specified fit points. |
entity_create_wipeout | write | Create a WIPEOUT that hides drawing content behind its outline. |
entity_delete | destructive | Permanently delete an entity by its handle. |
entity_delete_many | destructive | Delete multiple entities in one call. Returns count of deleted entities. |
entity_get | read | Get all properties of a specific entity by its handle. |
entity_get_xdata | read | Extended entity data as {app: [values]}. An app with no XDATA is simply absent. |
entity_mirror | read | Mirror an entity across a line defined by two points. Returns the mirrored copy. |
entity_trim | read | Trim `target` against `cutter`, keeping the segment containing (keep_x, keep_y). |
hatch_add_boundary | write | Add one boundary path built from typed edges - an island inside the hatch. |
layer_freeze | read | Freeze a layer (makes it invisible and unselectable, faster regeneration). |
layer_hide | read | Turn off a layer (entities invisible but still processed in regeneration). |
layer_list | read | List all layers with their properties (color, linetype, frozen, locked, visibility). |
layer_lock | read | Lock a layer (entities visible but cannot be selected or modified). |
layer_modify | write | Modify an existing layer |
layer_set_current | write | Set the active/current layer for new entities. |
layer_show | read | Turn on a layer that was previously turned off. |
layer_state_delete | destructive | Remove the named state |
layer_state_list | read | Every state under `ACADMCP_LAYERSTATES` with its description and layer |
layer_state_restore | write | Apply a saved state to the layers that still exist. |
layer_state_save | write | Snapshot every layer |
layer_thaw | read | Thaw a frozen layer, making it visible and selectable again. |
layer_unlock | read | Unlock a layer to allow entity selection and modification. |
layout_list | read | List all layout tabs (Model + paper-space layouts) and the current one. |
layout_rename | write | Rename a paper-space layout. Entity handles are unaffected. |
linetype_list | read | Return the names of all linetypes currently loaded in the active drawing. |
mleaderstyle_list | read | Every MLEADERSTYLE with its four values on both engines |
pid_from_spec | read | Equipment, valves, instruments and connectors placed, then every line |
pid_symbol_list | read | The symbols `pid_symbol_insert` can place, with their ports and variant options. |
pid_tag_parse | read | ISA-5.1-2009 Table 4.1 as a grammar: first letter, modifier, readout and |
plot_style_list | read | The ctb files AutoCAD ships (`monochrome.ctb`, `acad.ctb`, `Grayscale.ctb`, |
point_tangent | read | Compute the tangent point on a circle from an external point. |
selection_filter | read | AutoCAD |
selection_get | read | Read the entities the user pre-selected in the AutoCAD viewport (COM backend only). |
solid_boolean | read | Boolean-combine two native 3D solids (COM backend, opt-in). |
system_about | read | Get detailed information about AutoCAD MCP Pro capabilities and available tools. |
system_capabilities | read | Return machine-readable support modes for the active backend. |
system_launch | read | Connect to the application named by `CAD_PROGID` (attach if running, |
system_preferences_get | read | The whitelisted `Preferences.*` values, enum values as names |
system_preferences_set | write | Write one preference and report `old`, `new` and `changed`. |
system_prompt_message | read | `Utility.Prompt`: tell the operator something where they are looking. |
system_set_variable | write | Set an AutoCAD system variable (e.g. DIMSCALE, LTSCALE, MEASUREMENT). |
system_status | read | Get full status of the AutoCAD MCP Pro server and backend connection. |
template_apply_layers | write | Apply a standard layer set from a predefined template. |
template_list | read | List all available layer templates and their contents. |
textstyle_list | read | Every STYLE table entry and the one new TEXT/MTEXT will use. |
transaction_begin | read | Begin a transaction (undo mark). |
transaction_commit | write | Commit the current transaction. |
transaction_rollback | read | Rollback the current transaction to the point of transaction_begin. |
ucs_list | read | The `world` row first, then every UCS table entry with origin and unit |
ucs_restore | read | Live: `ActiveUCS` for a named entry; `world` runs `UCS World`, which is |
user_pick_point | read | `Utility.GetPoint`: returns the WCS `x`, `y` (`z`) the operator clicks. |
validation_check | write | Run quality checks on the current drawing. |
view_named_list | read | Every VIEW table entry with centre, height and width. No refusals. |
view_named_restore | read | Live: zooms the active viewport to the saved window the way `-VIEW _R` |
view_screenshot | read | Capture a screenshot of the current drawing view. |
view_zoom_and_screenshot | read | Zoom to extents (or window if coordinates given), then capture a screenshot. |
view_zoom_extents | read | Zoom to show all entities in the drawing (fit drawing in viewport). |
view_zoom_window | read | Zoom to display the specified rectangular window region. |
viewport_list | read | List paper-space viewports: handle, geometry, scale and lock state. |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (20)
ansi_b_mech.dwt
ansi_d_arch.dwt
iso_a1_arch.dwt
iso_a3_mech.dwt
iso_a3_pid.dwt
drawing_purge, entity_delete, entity_delete_many, layer_state_delete
.pre-commit-config.yaml
adapter_cls = getattr(importlib.import_module(module_name), attr)
sanitize_lisp("(eval (read user-input))")"(eval (read user-input))",
digest = hashlib.sha1(
await server.batch_plot("../../outside", ctx=_Ctx(backend))[{"tool": "drawing_open", "args": {"path": "../../etc/passwd"}}],await backend.system_launch(open_path="../../etc/passwd")
validate_path("../../../etc/passwd")await server.drawing_template_save("../../outside.dxf", ctx=_Ctx(backend))("M12", "Насос CIP P = 7,5 кВт\\P3 ф. 400 В + N + PE\\PЧРП", 7.5, True),assert wiring_target("P = 2,2 кВт\nк CP1") == "CP-1"- Commit after every task with a conventional-commit message; end every commit message with the two attribution lines this session's harness requires (`Co-Authored-By: Claude Opus 5 (1M context) <nore
- Commit per task with the task's message and the two attribution lines (`Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>`, `Claude-Session: https://claude.ai/code/session_01FKFStjE
Gates applied: no_behavioural_pass.
e7c5de2b3c33full audit observations/trust-audit/mcp-server/u-c4n__autocad-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e7c5de2b3c33 | CAUTION | C | 79 | first audit |
Questions
What is the Autocad MCP server?
Production-grade AutoCAD MCP server for AI agents — 122 tools, dual COM (live AutoCAD) + headless ezdxf engines, ISO GD&T and dimension-tolerance validation for CAD automation.
What tools does Autocad expose?
93 in total: 62 read-only, 27 that write, and 4 that can delete or overwrite (drawing_purge, entity_delete, entity_delete_many, layer_state_delete). Every one is listed on this page with its risk.
Is Autocad safe to connect to an agent?
With care. The audit graded it C (79/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Autocad need?
It reads MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Autocad run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as autocad-mcp-pro.
How current is this page?
The grade is for one exact copy of the source (e7c5de2b3c33), read on 2026-10-08. The repository is watched and re-audited when it changes.