61
/ 100
5 days ago
pulsemcp

BrandCode Studio

Extracts brand identity from websites and Figma files into structured design tokens, brand policies, and AI-consumable guidelines.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: FIRECRAWL_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Tool annotations don’t match behaviour
3 read-only tools perform write/delete/exec — brand_check_compliance (line 39: hexRe.exec(css)); brand_feedback_review (line 20: mkdir(FEEDBACK_DIR, { recursive: true })); brand_preflight (line 140: re.exec(css))
⚠️
Tool descriptions don’t match what handlers do
4 tools describe read intent but their handlers mutate — brand_check (line 922: re.exec(input)); brand_clarify (line 235: hexPattern.exec(answer)); brand_feedback_review (line 20: mkdir(FEEDBACK_DIR, { recursive: true }))
🔐
You'll be asked for 5 credentials: ANTHROPIC_API_KEY, BRANDCODE_MCP_SMOKE_FULL_KEY, BRANDCODE_MCP_SMOKE_READ_KEY, FIRECRAWL_API_KEY, OPENAI_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretANTHROPIC_API_KEY
configBRANDCODE_MCP_ENV
configBRANDCODE_MCP_SMOKE_ASSET_ID
🔐 secretBRANDCODE_MCP_SMOKE_FULL_KEY
🔐 secretBRANDCODE_MCP_SMOKE_READ_KEY
configBRANDCODE_MCP_SMOKE_SKIP_FEEDBACK
configBRANDCODE_MCP_SMOKE_TIMEOUT_MS
configBRANDCODE_MCP_SMOKE_URL
configBRANDCODE_MCP_TEST_KEYS
configBRANDSYSTEM_DOGFOOD_FILE
configBRANDSYSTEM_EVAL_BASE_URL
configBRANDSYSTEM_EVAL_HOLDOUT
configBRANDSYSTEM_EVAL_MODEL
configBRANDSYSTEM_PROFILE
configBRANDSYSTEM_TELEMETRY
configEVAL_ARM
🔐 secretFIRECRAWL_API_KEY
configGITHUB_REF_NAME
configMCP_CLIENT
🔐 secretOPENAI_API_KEY
configPORT
configUCS_API_BASE_URL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 9 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/brandcode-studio-brandsystem-mcp-1lqvwj)](https://m8ven.ai/mcp/brandcode-studio-brandsystem-mcp-1lqvwj)
commit: dd3f82bb945122a5526141bd428a893cf3b03204
code hash: 89c00a81a78a4e7c7e9d2275df3028971aaee3e31f01b3ca8380fae6279e894c
verified: 7/26/2026, 8:56:54 AM
view raw JSON →