Atlas / MCP servers / u-c4n / Autocad

AutocadCAUTION

mcp/u-c4n/autocad-4

Production-grade AutoCAD MCP server for AI agents — 122 tools, dual COM (live AutoCAD) + headless ezdxf engines, ISO GD&T and dimension-tolerance validation for CAD automation.

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
93 62r · 27w · 4d
Transport
stdio · streamable-http
License
MIT
Stars
127
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Production-grade AutoCAD automation for AI agents. Live through COM on Windows, or headless through ezdxf anywhere — one typed contract, two engines.

[](https://github.com/U-C4N/Autocad-MCP/actions/workflows/ci.yml) [](https://pypi.org/project/autocad-mcp-pro/) [](https://pypi.org/project/autocad-mcp-pro/) [](https://github.com/U-C4N/Autocad-MCP/blob/main/pyproject.toml) [](https://github.com/U-C4N/Autocad-MCP/blob/main/LICENSE)

Install · What's new · Tools · Engines · Evidence · Limits · Config · Changelog

Not a mockup. Every line on this sheet was drawn by the tools this server exposes — ISO layers, involute gear geometry, DIN 6885 keyway, section A-A, ISO 129 dimensions, an ISO 286 H7 bore fit, ISO 7200 title block — then rendered headlessly by viewscreenshot. drawingcritique returns 0 issues on it. Rebuild it with python scripts/renderreadmeshowcase.py.

v1.6 release snapshot: 247 tools · 8 resources · 5 prompt templates · 4992 collected te
Read from source at commit e7c5de2b3c33OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add autocad-mcp-pro -- None autocad-mcp-pro==1.6.0
03

Exposed tools (93)

62 read · 27 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analysis_bounding_boxreadGet the bounding box (extents) of all entities in the drawing.
analysis_entity_statsreadAnalyze the drawing and return entity counts grouped by type and by layer.
analysis_find_in_regionreadFind all entities within a rectangular region (crossing selection).
analysis_layer_statsreadReturn detailed statistics for each layer: entity count, types present.
analysis_list_propertiesreadAutoCAD
analysis_measure_distancereadMeasure the Euclidean distance between two points.
analysis_select_by_layerreadGet all entities on a specific layer. Returns entity list with handles.
analysis_select_by_typereadGet all entities of a specific type. Returns entity list with handles.
block_create_from_entitieswriteCreate a new block definition from existing entities in the drawing.
block_find_referenceswriteFind all insert references to a specific block definition.
block_insertwriteInsert a block and optionally set attribute values.
block_listreadList all block definitions in the drawing (name, origin, attribute count, entity count).
boundary_from_entitiesreadChain the given entities into one closed polyline.
boundary_tracereadAutoCAD
dimension_alignedwriteCreate an aligned dimension that measures the true distance between two points.
dimension_angularwriteCreate an angular dimension measuring the angle between two lines from a vertex.
dimstyle_listreadEvery DIMSTYLE table entry with the seventeen preset variables
dimstyle_modifywriteChange variables on an existing dimension style.
document_closereadClose a document and report `saved`, `discarded_changes` and the new `active`.
document_listreadEvery open document with `name`, `path`, `active`, `saved` and
drawing_auditreadAudit the drawing: repair every fixable structural problem, and report it.
drawing_closewriteClose the active document. If save is True (default), the drawing is
drawing_export_dxfreadExport the current drawing as a DXF file.
drawing_inforeadGet comprehensive metadata for the current drawing.
drawing_purgedestructivePurge all unused objects (layers, blocks, linetypes, styles) from the drawing.
drawing_redoreadReapply the operation you just undid.
drawing_savewriteSave the current drawing. Optionally specify a new path.
drawing_template_listwriteThe templates `drawing_new(template=<name>)` can start from.
drawing_undoreadUndo the last drawing operation.
entity_batch_createwriteCreate multiple entities in a single call for better performance.
entity_copywriteCopy an entity and move the copy by (dx, dy, dz). Returns info of the new copy.
entity_create_pointwriteCreate a point marker entity at (x, y).
entity_create_polylinewriteCreate a lightweight 2D polyline through the given points.
entity_create_rectanglewriteCreate a closed rectangular polyline between two corner points.
entity_create_splinewriteCreate a NURBS spline curve passing through the specified fit points.
entity_create_wipeoutwriteCreate a WIPEOUT that hides drawing content behind its outline.
entity_deletedestructivePermanently delete an entity by its handle.
entity_delete_manydestructiveDelete multiple entities in one call. Returns count of deleted entities.
entity_getreadGet all properties of a specific entity by its handle.
entity_get_xdatareadExtended entity data as {app: [values]}. An app with no XDATA is simply absent.
entity_mirrorreadMirror an entity across a line defined by two points. Returns the mirrored copy.
entity_trimreadTrim `target` against `cutter`, keeping the segment containing (keep_x, keep_y).
hatch_add_boundarywriteAdd one boundary path built from typed edges - an island inside the hatch.
layer_freezereadFreeze a layer (makes it invisible and unselectable, faster regeneration).
layer_hidereadTurn off a layer (entities invisible but still processed in regeneration).
layer_listreadList all layers with their properties (color, linetype, frozen, locked, visibility).
layer_lockreadLock a layer (entities visible but cannot be selected or modified).
layer_modifywriteModify an existing layer
layer_set_currentwriteSet the active/current layer for new entities.
layer_showreadTurn on a layer that was previously turned off.
layer_state_deletedestructiveRemove the named state
layer_state_listreadEvery state under `ACADMCP_LAYERSTATES` with its description and layer
layer_state_restorewriteApply a saved state to the layers that still exist.
layer_state_savewriteSnapshot every layer
layer_thawreadThaw a frozen layer, making it visible and selectable again.
layer_unlockreadUnlock a layer to allow entity selection and modification.
layout_listreadList all layout tabs (Model + paper-space layouts) and the current one.
layout_renamewriteRename a paper-space layout. Entity handles are unaffected.
linetype_listreadReturn the names of all linetypes currently loaded in the active drawing.
mleaderstyle_listreadEvery MLEADERSTYLE with its four values on both engines
pid_from_specreadEquipment, valves, instruments and connectors placed, then every line
pid_symbol_listreadThe symbols `pid_symbol_insert` can place, with their ports and variant options.
pid_tag_parsereadISA-5.1-2009 Table 4.1 as a grammar: first letter, modifier, readout and
plot_style_listreadThe ctb files AutoCAD ships (`monochrome.ctb`, `acad.ctb`, `Grayscale.ctb`,
point_tangentreadCompute the tangent point on a circle from an external point.
selection_filterreadAutoCAD
selection_getreadRead the entities the user pre-selected in the AutoCAD viewport (COM backend only).
solid_booleanreadBoolean-combine two native 3D solids (COM backend, opt-in).
system_aboutreadGet detailed information about AutoCAD MCP Pro capabilities and available tools.
system_capabilitiesreadReturn machine-readable support modes for the active backend.
system_launchreadConnect to the application named by `CAD_PROGID` (attach if running,
system_preferences_getreadThe whitelisted `Preferences.*` values, enum values as names
system_preferences_setwriteWrite one preference and report `old`, `new` and `changed`.
system_prompt_messageread`Utility.Prompt`: tell the operator something where they are looking.
system_set_variablewriteSet an AutoCAD system variable (e.g. DIMSCALE, LTSCALE, MEASUREMENT).
system_statusreadGet full status of the AutoCAD MCP Pro server and backend connection.
template_apply_layerswriteApply a standard layer set from a predefined template.
template_listreadList all available layer templates and their contents.
textstyle_listreadEvery STYLE table entry and the one new TEXT/MTEXT will use.
transaction_beginreadBegin a transaction (undo mark).
transaction_commitwriteCommit the current transaction.
transaction_rollbackreadRollback the current transaction to the point of transaction_begin.
ucs_listreadThe `world` row first, then every UCS table entry with origin and unit
ucs_restorereadLive: `ActiveUCS` for a named entry; `world` runs `UCS World`, which is
user_pick_pointread`Utility.GetPoint`: returns the WCS `x`, `y` (`z`) the operator clicks.
validation_checkwriteRun quality checks on the current drawing.
view_named_listreadEvery VIEW table entry with centre, height and width. No refusals.
view_named_restorereadLive: zooms the active viewport to the saved window the way `-VIEW _R`
view_screenshotreadCapture a screenshot of the current drawing view.
view_zoom_and_screenshotreadZoom to extents (or window if coordinates given), then capture a screenshot.
view_zoom_extentsreadZoom to show all entities in the drawing (fit drawing in viewport).
view_zoom_windowreadZoom to display the specified rectangular window region.
viewport_listreadList paper-space viewports: handle, geometry, scale and lock state.
04

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (20)

MEDIUMInventory / provenance · inv.binary · CWE-1104
templates/ansi_b_mech.dwt
ansi_b_mech.dwt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
templates/ansi_d_arch.dwt
ansi_d_arch.dwt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
templates/iso_a1_arch.dwt
iso_a1_arch.dwt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
templates/iso_a3_mech.dwt
iso_a3_mech.dwt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
templates/iso_a3_pid.dwt
iso_a3_pid.dwt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
drawing_purge, entity_delete, entity_delete_many, layer_state_delete
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
benchmarks/run_competitors.py:31
adapter_cls = getattr(importlib.import_module(module_name), attr)
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_security.py:221
sanitize_lisp("(eval (read user-input))")
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_security.py:345
"(eval (read user-input))",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
backends/com_backend.py:276
digest = hashlib.sha1(
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_batch_plot.py:254
await server.batch_plot("../../outside", ctx=_Ctx(backend))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_cad_batch.py:623
[{"tool": "drawing_open", "args": {"path": "../../etc/passwd"}}],
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_environment_live.py:537
await backend.system_launch(open_path="../../etc/passwd")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security.py:40
validate_path("../../../etc/passwd")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_templates.py:418
await server.drawing_template_save("../../outside.dxf", ctx=_Ctx(backend))
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/fixtures/plant_pair.py:130
("M12", "Насос CIP P = 7,5 кВт\\P3 ф. 400 В + N + PE\\PЧРП", 7.5, True),
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/test_understand_labels.py:230
assert wiring_target("P = 2,2 кВт\nк CP1") == "CP-1"
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/superpowers/plans/2026-09-15-v1.6-pid-implementation.md:24
- Commit after every task with a conventional-commit message; end every commit message with the two attribution lines this session's harness requires (`Co-Authored-By: Claude Opus 5 (1M context) <nore
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/superpowers/plans/2026-09-16-v1.6-settings-implementation.md:19
- Commit per task with the task's message and the two attribution lines (`Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>`, `Claude-Session: https://claude.ai/code/session_01FKFStjE
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e7c5de2b3c33full audit observations/trust-audit/mcp-server/u-c4n__autocad-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e7c5de2b3c33CAUTIONC79first audit
06

Questions

What is the Autocad MCP server?

Production-grade AutoCAD MCP server for AI agents — 122 tools, dual COM (live AutoCAD) + headless ezdxf engines, ISO GD&T and dimension-tolerance validation for CAD automation.

What tools does Autocad expose?

93 in total: 62 read-only, 27 that write, and 4 that can delete or overwrite (drawing_purge, entity_delete, entity_delete_many, layer_state_delete). Every one is listed on this page with its risk.

Is Autocad safe to connect to an agent?

With care. The audit graded it C (79/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Autocad need?

It reads MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Autocad run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as autocad-mcp-pro.

How current is this page?

The grade is for one exact copy of the source (e7c5de2b3c33), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement