MCP servers for design tools and image, video and audio generation and processing. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.
Security scan results for the Fastmcp MCP server.
Security scan results for the Brave Search MCP server.
Security scan results for the Chart MCP server.
Security scan results for the Kubb MCP server.
Security scan results for the Korean Law MCP server.
Security scan results for the Brandsystem MCP server.
Security scan results for the Taiga Ui MCP server.
Security scan results for the Figma MCP server.
Security scan results for the Aleph Siliconflow MCP server.
Security scan results for the Figma Mcp Console MCP server.
Security scan results for the Runapi.ai MCP server.
Security scan results for the Nanobanana MCP server.
Security scan results for the Simple Dynamsoft MCP server.
Security scan results for the I MCP server.
Security scan results for the Figma Mcp Bridge MCP server.
Security scan results for the Nano Banana MCP server.
Security scan results for the Goldbean MCP server.
Security scan results for the Ai Figma MCP server.
Security scan results for the Swatchbook MCP server.
Security scan results for the Gemini MCP server.
Security scan results for the Mcporter MCP server.
Security scan results for the Figma Mcp Express MCP server.
Security scan results for the Coalesce MCP server.
Security scan results for the Xbrush Api MCP server.
Ask an AI assistant to pull design tokens out of a Figma file, render product shots through Replicate or a local ComfyUI pipeline, or batch-transcode video with an FFmpeg wrapper, and a Model Context Protocol server is doing the work underneath. Design and media MCP servers typically bridge Claude or Cursor to design platforms such as Figma and Canva, diffusion-based image generators, hosted inference APIs, converters built on FFmpeg and ImageMagick, and text-to-speech engines. The same connections that make those workflows possible define what a compromised server could reach, so the security questions here are specific to creative tooling:
Each entry in the MCP Trust Registry carries a Trust Score produced by a deterministic open-source scanner: it reads the published npm or PyPI package, maps the real capability blast radius, and grades the result 0-100 with an A-F letter — no LLM in the loop, no paid placement, and identical code always scores identically. For media servers, the finding that matters most is filesystem or shell access paired with outbound network calls, the combination that turns an innocent image converter into an exfiltration path; the scoring model is documented in full. Pipelines that hand finished assets to other systems can be checked the same way in Business & CRM and API Development.
Only if its capabilities allow it — which is exactly what the scan surfaces. A server that talks to a single generation endpoint has little to leak with, while one holding file access, shell execution and open network egress could exfiltrate design files or credentials if compromised. Compare capability profiles and Trust Scores before connecting one to real client work.