kicad-mcp
npm
v0.1.6
Published by iengphogit — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
Automate KiCad with an MCP server, Codex skill, and GUI plugin for inspection, safe edits, ERC/DRC, capability inventory, readiness reports, and fabrication exports.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 7 = 93. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`bin/kicad-mcp.js:8`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: nSync } = require("node:child_process"); const packageRoot = path.resolve(__dirname, ".."); const pluginDir = path.join
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server bin/kicad-mcp.js
In the server's implementation (`kicad-ai-plugin/plugin.py:888`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: : process = subprocess.Popen( [_python_executable(), str(SERVER_PATH)], cwd=
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server kicad-ai-plugin/plugin.py
In the server's implementation (`kicad-ai-plugin/tools/common.py:96`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: Result: completed = subprocess.run( list(command), text=True, stdout=subprocess.PIPE,
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server kicad-ai-plugin/tools/common.py
In the server's implementation (`kicad-ai-plugin/tools/drc.py:168`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: -> str: completed = subprocess.run( [kicad_cli, "pcb", "drc", "--help"], text=True, stdout=s
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server kicad-ai-plugin/tools/drc.py
In the server's implementation (`kicad-ai-plugin/tools/gerber.py:16`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: -> str: completed = subprocess.run( [kicad_cli, *args, "--help"], text=True, stdout=subproce
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server kicad-ai-plugin/tools/gerber.py
Each tool and what it can reach — statically extracted from the published source.
kicad_add_custom_pad_primitiveno sensitive capabilitykicad_add_footprint_graphicno sensitive capabilitykicad_add_footprint_modelno sensitive capabilitykicad_add_footprint_padno sensitive capabilitykicad_add_footprint_slotno sensitive capabilitykicad_add_footprint_textno sensitive capabilitykicad_add_polygon_custom_padno sensitive capabilitykicad_align_footprintsno sensitive capabilitykicad_arrange_board_footprintsno sensitive capabilitykicad_create_footprintno sensitive capabilitykicad_create_footprint_libraryno sensitive capabilitykicad_create_mounting_hole_footprintno sensitive capabilitykicad_create_slotted_hole_footprintno sensitive capabilitykicad_delete_board_footprintno sensitive capabilitykicad_delete_custom_pad_primitiveno sensitive capabilitykicad_delete_footprint_padno sensitive capabilitykicad_distribute_footprintsno sensitive capabilitykicad_export_bomno sensitive capabilitykicad_export_drill_filesno sensitive capabilitykicad_export_fabrication_packageno sensitive capabilitykicad_export_footprint_svgno sensitive capabilitykicad_export_gerbersno sensitive capabilitykicad_export_ipc2581no sensitive capabilitykicad_export_ipcd356no sensitive capabilitykicad_export_odbno sensitive capabilitykicad_export_position_fileno sensitive capabilitykicad_get_board_footprint_propertiesno sensitive capabilitykicad_grid_place_footprintsno sensitive capabilitykicad_inspect_footprintno sensitive capabilitykicad_list_board_backupsno sensitive capabilitykicad_list_board_footprintsno sensitive capabilitykicad_list_custom_pad_primitivesno sensitive capabilitykicad_list_footprint_librariesno sensitive capabilitykicad_move_board_footprintno sensitive capabilitykicad_parse_drc_reportno sensitive capabilitykicad_parse_erc_reportno sensitive capabilitykicad_place_footprintno sensitive capabilitykicad_register_project_footprint_libraryno sensitive capabilitykicad_restore_board_backupno sensitive capabilitykicad_rotate_board_footprintno sensitive capabilitykicad_run_drcno sensitive capabilitykicad_run_ercno sensitive capabilitykicad_search_footprintsno sensitive capabilitykicad_set_board_footprint_layerno sensitive capabilitykicad_set_footprint_metadatano sensitive capabilitykicad_set_footprint_propertyno sensitive capabilitykicad_sort_board_footprintsno sensitive capabilitykicad_summarize_drc_reportno sensitive capabilitykicad_summarize_erc_reportno sensitive capabilitykicad_tool_inventoryno sensitive capabilitykicad_update_custom_pad_primitiveno sensitive capabilitykicad_update_footprint_padno sensitive capabilitykicad_validate_boardno sensitive capabilitykicad_validate_footprintno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.1.6 latest |
A 93/100 | 5 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan kicad-mcp --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 6 side by side →
MCP server exposing KiCad PCB Editor functionality via IPC API
KiCad MCP Server
Model Context Protocol (MCP) server for automated KiCad PCB design
MCP server for AI-assisted PCB design with KiCad
MCP servers for KiCad schematic, PCB, and export automation
Authenticated MCP transport with HTTP Signatures for AAuth agents
Local-first MCP server for parallel AI coding agents to claim file ownership before edits, preventing stomping on each other in the same worktree.
Agent-agnostic intercommunication system — sessions, messaging, channels, shared state, and real-time events
MCP server for AI agent task communication and delegation with diagnostic lifecycle visibility
Programmatic add/link/unlink for MCP servers across 23 AI coding agents (Claude Code, Claude Desktop, Cursor, VS Code, Codex, Gemini CLI, Zed, Cline, OpenCode, Goose, Kiro, Windsurf, and more). Functional API with dry-run support.
MCP server layer exposing agent-mesh orchestrator as an MCP agent