Shadcn-uiSAFE
MCP server for shadcn/ui component references
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP server for shadcn/ui component references
This is a TypeScript-based MCP server that provides reference information for shadcn/ui components. It implements a Model Context Protocol (MCP) server that helps AI assistants access shadcn/ui component documentation and examples.
Features
Tools
list_shadcn_components- Get a list of all available shadcn/ui componentsget_component_details- Get detailed information about a specific componentget_component_examples- Get usage examples for a specific componentsearch_components- Search for components by keyword
Functionality
This server scrapes and caches information from:
- The official shadcn/ui documentation site (https://ui.shadcn.com)
- The shadcn/ui GitHub repository
It provides structured data including:
- Component descriptions
- Installation instructions
- Usage examples
- Props and variants
- Code samples
Development
Install dependencies:
npm install
Build the server:
npm run build
For development with auto-rebuild:
npm run watch
Installation
Claude Desktop Configuration
To use with Claude Desktop, add the server config:
On MacOS: ~/Library/Application Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json
Option 1: Using local build
{
"mcpServers": {
"shadcn-ui-server": {
"command": "/path/to/shadcn-ui-server/build/index.js"
}
}
}Option 2: Using npx command
{
"mcpServers": {
"shadcn-ui-server": {
"command": "npx",
"args": ["-y", "shadcn-ui-mcp-server"]
}
}
}Windsurf Configuration
Add this to your ./codeium/windsurf/model_config.json:
{
"mcpServers": {
"shadcn-ui-server": {
"command": "npx",
"args": ["-y", "shadcn-ui-mcp-server"]
}
}
}Cursor Configuration
Add this to your .cursor/mcp.json:
{
"mcpServers": {
da33d920e7efOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add shadcn-ui-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"shadcn-ui-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_component_details | read | Get detailed information about a specific shadcn/ui component |
get_component_examples | read | Get usage examples for a specific shadcn/ui component |
list_shadcn_components | read | Get a list of all available shadcn/ui components |
search_components | read | Search for shadcn/ui components by keyword |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
axios, cheerio, @types/node, typescript
Gates applied: no_behavioural_pass.
da33d920e7effull audit observations/trust-audit/mcp-server/ymadd__shadcn-ui.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | da33d920e7ef | SAFE | B | 89 | first audit |
Questions
What is the Shadcn-ui MCP server?
MCP server for shadcn/ui component references
What tools does Shadcn-ui expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Shadcn-ui safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Shadcn-ui need?
No credential environment variables were found in its source, so it appears to need none.
How does Shadcn-ui run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as shadcn-ui-mcp-server at 0.1.2.
How current is this page?
The grade is for one exact copy of the source (da33d920e7ef), read on 2026-10-07. The repository is watched and re-audited when it changes.