50
/ 100
3 days ago
glama

Penpot MCP Server

Enables AI assistants to create, modify, and manage Penpot designs programmatically, providing full manipulation capabilities for the open-source design tool.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for the top badge — read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical, 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 1 credential: PENPOT_ACCESS_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 critical3 high2 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalform-data@4.0.1GHSA-fjxv-7rqg-78g4

form-data uses unsafe random function in form-data for choosing boundary

criticalform-data@4.0.1GHSA-fjxv-7rqg-78g4

form-data uses unsafe random function in form-data for choosing boundary

high@modelcontextprotocol/sdk@1.0.4GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highform-data@4.0.1GHSA-hmw2-7cc7-3qxx

form-data: CRLF injection in form-data via unescaped multipart field names and filenames

highform-data@4.0.1GHSA-hmw2-7cc7-3qxx

form-data: CRLF injection in form-data via unescaped multipart field names and filenames

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOWED_HOSTSexport ="localhost,example.com"
configALLOWED_ORIGINSexport ="https://example.com,https://app.example.com"
configENABLE_DNS_REBINDING_PROTECTIONexport ="true"
configHTTPS_PROXY
configHTTP_HOSTexport ="0.0.0.0" # Default
configHTTP_PORTTRANSPORT=http =8080 node dist/index.js
configHTTP_PROXY
🔐 secretPENPOT_ACCESS_TOKENexport ="your-access-token-here"
configPENPOT_API_URLexport ="https://design.penpot.app"
configTRANSPORThttp penpot-mcp-server
confighttp_proxy
confighttps_proxy
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/zcube-penpot-mcp-server-1m98vs)](https://m8ven.ai/mcp/zcube-penpot-mcp-server-1m98vs)
commit: 389545cfacffaca7465eedac90892f0db92e1f16
code hash: f82bee4b5cf0869d4cbb2db1d746ddd9999792b981911a50c6cb1c4629b024bd
verified: 8/7/2026, 4:14:10 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client