54
grade D
3 days ago
npm

DayuanJiang/next-ai-draw-io

MCP server for Next AI Draw.io - AI-powered diagram generation with real-time browser preview

DayuanJiang/next-ai-draw-io· npm: @next-ai-drawio/mcp-server· listed on npm

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 9 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: GOOGLE_VERTEX_API_KEY, OLLAMA_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configACCESS_CODE_LIST
configAI_MODEL
configAI_MODELS_CONFIGAdministrators can configure multiple server-side models that are available to all users without requiring personal API keys. Configure via environment variable (JSON string) or ai-models.json file.
configAI_MODELS_CONFIG_PATH
configAI_PROVIDER
configALLOW_PRIVATE_URLS
configANTHROPIC_THINKING_BUDGET_TOKENS
configANTHROPIC_THINKING_TYPE
configAPP_VERSION
configAWS_REGION
configAZURE_BASE_URL
configAZURE_REASONING_EFFORT
configAZURE_REASONING_SUMMARY
configAZURE_RESOURCE_NAME
configBEDROCK_REASONING_BUDGET_TOKENS
configBEDROCK_REASONING_EFFORT
configDAILY_REQUEST_LIMIT
configDAILY_TOKEN_LIMIT
configDRAWIO_BASE_URL
configDYNAMODB_QUOTA_TABLE
configDYNAMODB_REGION
configELECTRON_DEV_URL
configENABLE_HISTORY_XML_REPLACE
configENABLE_VLM_VALIDATION
configGOOGLE_CANDIDATE_COUNT
configGOOGLE_REASONING_EFFORT
configGOOGLE_THINKING_BUDGET
configGOOGLE_THINKING_LEVEL
configGOOGLE_TOP_K
configGOOGLE_TOP_P
🔐 secretGOOGLE_VERTEX_API_KEY
configGOOGLE_VERTEX_BASE_URL
configGOOGLE_VERTEX_THINKING_BUDGET
configGOOGLE_VERTEX_THINKING_LEVEL
configHTTPS_PROXY
configHTTP_PROXY
configMAX_OUTPUT_TOKENS
configNEXT_PUBLIC_BASE_PATH
configNEXT_PUBLIC_DRAWIO_BASE_URL
configNEXT_PUBLIC_GA_ID
configNEXT_PUBLIC_MAX_EXTRACTED_CHARS
configNEXT_PUBLIC_SELFHOSTED
configNEXT_PUBLIC_SHOW_ABOUT_AND_NOTICE
🔐 secretOLLAMA_API_KEY
configOLLAMA_BASE_URL
configOLLAMA_ENABLE_THINKING
configOPENAI_BASE_URL
configOPENAI_REASONING_EFFORT
configOPENAI_REASONING_SUMMARY
configPORT
configQUOTA_TIMEZONE
configTPM_LIMIT
configVALIDATION_MODEL
configVALIDATION_TIMEOUT
confighttp_proxy
confighttps_proxy
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/next-ai-drawio-mcp-server-1iku5o)](https://m8ven.ai/mcp/next-ai-drawio-mcp-server-1iku5o)
commit: d4454beb9ace3ea63139653dc6d2ff2e40d68682
code hash: e4e3380a5504d2be520bd40e365e5bcb0cc73a9317cad9e1349d7573906cd26c
verified: 4/18/2026, 4:03:19 PM
view raw JSON →