Origin Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Origin Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
origin-mcp cover
origin-mcp is a local Model Context Protocol (MCP) server that lets AI assistants control Origin/OriginPro on Windows. It connects through OriginLab's Python automation interface and exposes tools for importing data, editing worksheets, creating and refining graphs, running Origin analyses, exporting figures, and managing the Origin application lifecycle.
This project is still in a testing stage. Trying it on real Origin workflows, reporting issues, suggesting improvements, and opening pull requests are all welcome.
descriptive statistics, interpolation, normalization, t-tests, FFT/IFFT, and correlation.
it to same-type figures (see docs/tools.md).
By default, origin-mcp keeps the styling defined by the Origin graph template you are using. If you want a cleaner publication-style scientific figure, ask your AI assistant to use the Nature-style format when creating or refining the graph. The preset applies colorblind-aware palettes, stronger scientific plot strokes, Arial typography, and simpler legends.
For more control, you can ask the assistant to list available palettes. See docs/tools.md for the detailed palette and style controls.
not currently guaranteed
originpro packageorigin-mcp runs as two cooperating processes, and the supported Python versions differ by role:
python -m origin_mcp process, which only talks tothe bridge over localhost): Python 3.10+. CI tests this core on Windows with Python 3.10, 3.11, 3.12, 3.13, and 3.14.
addon.py): runs inside Origin's own embedded Python, soits version is whatever your Origin install ships — there is nothing to pick.
Direct external originpro automation is not a supported MCP backend for this project. Start the bridge inside Origin's embedded Python and let the MCP server connect to it over localhost.
Install the MCP server core from PyPI:
pip install origin-mcpThat is all the MCP server needs: it runs as python -m origin_mcp and reaches Origin only through the bridge over localhost. The bridge runs inside Origin's own embedded Python and installs its own dependencies (see Start the Origin Bridge).
An optional origin-mcp[origin] extra pulls originpro and pywin32 into the same environment; the standard bridge setup does not require it. To work from a checkout instead, run pip install -e . in the repository root.
Copy this to your AI agent and let it self-configure:
Fetch and follow this bootstrap guide end to end:
https://raw.githubusercontent.com/Ge-Shun/origin-mcp/main/docs/agentic/origin-mcp-bootstrap.mdExample MCP client configuration:
{
"mcpServers": {
"origin": {
"command": "python",
"args": ["-m", "origin_mcp"]
}
}
}If python is not the Python 3.10+ interpreter you installed origin-mcp into, use that interpreter's absolute python.exe path instead. More examples are in docs/mcp-config.md.
The bridge runs inside Origin's own Python so originpro stays on Origin's UI thread. There is nothing to configure — start it once per Origin session:
Origin Apps (recommended for daily use). Build and install the two bridge Apps once with the steps in docs/origin-ui-buttons.md. After that, click Origin MCP Bridge Start in the Apps gallery to start the bridge and Origin MCP Bridge Stop to stop it.
Python Console (one-off or troubleshooting). Open Origin's Python Console and paste this line (replace the path with your checkout):
import runpy; runpy.run_path(r"C:\path\to\origin-mcp\addon.py", run_name="__main__")A Bridge is running inside Origin. box confirms startup; keep that console running while you use the tools. To stop, ask your MCP assistant to shut the bridge down (it calls origin_bridge_shutdown), or double-click scripts\stop-bridge.cmd (or run python scripts\stop_bridge.py). Origin stays open either way.
If a package is missing or the bridge will not start, see docs/origin-bridge.md.
The bridge listens only on 127.0.0.1 and authenticates local requests by default with a per-session token, so normal use needs no security setup.
Treat that token as a credential. Any local process that presents it can drive Origin with the full tool surface, including arbitrary LabTalk execution through origin_run_labtalk. The token is generated per session and written to an owner-scoped file in your per-user temporary directory (%TEMP%/origin-mcp/bridge.json on Windows), which a standard single-user machine already protects through the directory's OS permissions. If you redirect TEMP or ORIGIN_MCP_BRIDGE_HANDSHAKE to a directory other local users can read, the token — and therefore control of Origin — is exposed to them. Setting ORIGIN_MCP_BRIDGE_NO_AUTH removes the token boundary entirely and should be used only when you fully trust every local process.
If you need to restrict which files tools may read or write, set ORIGIN_MCP_ALLOWED_ROOTS to the allowed directories. Avoid disabling bridge authentication unless you fully trust every local process on the machine.
MIT. See LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.