Atlas / MCP servers / ymadd / Shadcn-ui

Shadcn-uiSAFE

mcp/ymadd/shadcn-ui

MCP server for shadcn/ui component references

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 4r · 0w · 0d
Transport
stdio
License
MIT
Stars
60
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP server for shadcn/ui component references

This is a TypeScript-based MCP server that provides reference information for shadcn/ui components. It implements a Model Context Protocol (MCP) server that helps AI assistants access shadcn/ui component documentation and examples.

Features

Tools

  • list_shadcn_components - Get a list of all available shadcn/ui components
  • get_component_details - Get detailed information about a specific component
  • get_component_examples - Get usage examples for a specific component
  • search_components - Search for components by keyword

Functionality

This server scrapes and caches information from:

  • The official shadcn/ui documentation site (https://ui.shadcn.com)
  • The shadcn/ui GitHub repository

It provides structured data including:

  • Component descriptions
  • Installation instructions
  • Usage examples
  • Props and variants
  • Code samples

Development

Install dependencies:

npm install

Build the server:

npm run build

For development with auto-rebuild:

npm run watch

Installation

Claude Desktop Configuration

To use with Claude Desktop, add the server config:

On MacOS: ~/Library/Application Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json

Option 1: Using local build

{
"mcpServers": {
"shadcn-ui-server": {
"command": "/path/to/shadcn-ui-server/build/index.js"
}
}
}

Option 2: Using npx command

{
"mcpServers": {
"shadcn-ui-server": {
"command": "npx",
"args": ["-y", "shadcn-ui-mcp-server"]
}
}
}

Windsurf Configuration

Add this to your ./codeium/windsurf/model_config.json:

{
"mcpServers": {
"shadcn-ui-server": {
"command": "npx",
"args": ["-y", "shadcn-ui-mcp-server"]
}
}
}

Cursor Configuration

Add this to your .cursor/mcp.json:

{
"mcpServers": {
Read from source at commit da33d920e7efOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add shadcn-ui-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "shadcn-ui-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
get_component_detailsreadGet detailed information about a specific shadcn/ui component
get_component_examplesreadGet usage examples for a specific shadcn/ui component
list_shadcn_componentsreadGet a list of all available shadcn/ui components
search_componentsreadSearch for shadcn/ui components by keyword
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, cheerio, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha da33d920e7effull audit observations/trust-audit/mcp-server/ymadd__shadcn-ui.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07da33d920e7efSAFEB89first audit
06

Questions

What is the Shadcn-ui MCP server?

MCP server for shadcn/ui component references

What tools does Shadcn-ui expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Shadcn-ui safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Shadcn-ui need?

No credential environment variables were found in its source, so it appears to need none.

How does Shadcn-ui run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as shadcn-ui-mcp-server at 0.1.2.

How current is this page?

The grade is for one exact copy of the source (da33d920e7ef), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement