.cursor — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited .cursor (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A secure Model Context Protocol (MCP) tool with workspace sandbox for AI Agents to find prompts, save HTML, and render HTML to images.
This is a major version update with breaking changes. All API parameters have been redesigned for enhanced security and usability.
output/ subdirectories# Install and run with workspace
npx mcp-artisan /path/to/your/workspace
# Example
npx mcp-artisan ./my-projectRequired: You must specify a workspace directory when starting the server.
To use MCP-Artisan with AI development environments like Cursor, you need to configure the MCP server command.
# Global installation
npm install -g mcp-artisan
# Or local project installation
npm install mcp-artisan.cursor-agent/mcp.json or a similar configuration file), set up the server command as follows:npx["mcp-artisan", "/path/to/your/project/workspace"]Replace /path/to/your/project/workspace with the absolute path to the folder you want the AI to work in. This folder will be used to find prompts and save output files.
Example Configuration (`.cursor-agent/mcp.json`):
{
"mcpServers": {
"my-artisan-tool": {
"command": "npx",
"args": [
"-y",
"mcp-artisan",
"/Users/username/my-ai-project"
]
}
}
}Lists available prompt files automatically.
workspace/prompts/ first, falls back to workspace rootReads prompt file content by filename.
promptFileName (string): Just the filename, no path neededSaves HTML with automatic organization.
htmlContent (string): Complete HTML contentsubfolderName (string, max 20 chars): Descriptive folder namefileName (string): Filename without .html extensionworkspace/output/{subfolderName}/{fileName}.htmlRenders HTML to image using relative paths.
htmlPath (string): Relative path from workspace (e.g., "output/my-card/index.html")imageType (optional): 'png' or 'jpeg'| v1.x Parameter | v2.x Parameter | Notes |
|---|---|---|
promptsPath | (removed) | Auto-discovery in workspace |
promptPath | promptFileName | Just filename, no path |
outputPath | subfolderName | Auto-organized in output/ |
htmlPath (absolute) | htmlPath (relative) | Relative to workspace |
# Start server with workspace
npx mcp-artisan ./my-project
# Directory structure will be:
# my-project/
# ├── prompts/ # Your prompt files
# │ ├── card.txt
# │ └── banner.md
# └── output/ # Generated files
# └── my-cards/ # Organized by subfolder
# ├── card.html
# └── card.png# Clone and install
git clone <repo>
cd mcp-artisan
npm install
# Build
npm run build
# Development with workspace
npm run dev -- ./test-workspaceMIT
Issues and pull requests are welcome. Please ensure all tests pass before submitting.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.