Tldraw Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Tldraw Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Node-only MCP server exposing read_tldr, write_tldr, and validate_tldr tools. No browser, no DOM, no React — runs in plain Node v24.
@tldraw/editor 5.1.1
@tldraw/store 5.1.1
@tldraw/tlschema 5.1.1| Symbol | Package | Notes |
|---|---|---|
Store (class) | @tldraw/store | Use directly — createTLStore from @tldraw/editor hangs the process |
createTLSchema | @tldraw/tlschema | NOT in @tldraw/editor for 5.x |
createShapeId | @tldraw/tlschema | |
createBindingId | @tldraw/tlschema | |
parseTldrawJsonFile | @tldraw/tlschema | For reading .tldr files |
toRichText | @tldraw/tlschema | Convert plain text → ProseMirror richText doc |
NEVER import thetldrawumbrella package at runtime. NEVER callnew Editor()orcreateTLStorefrom@tldraw/editorin read/write/validate paths.@tldraw/tlschemais CJS — load viacreateRequirein.mjsfiles (named ESM imports fail).
.tldr file, return records + schema version.tldr file envelope.tldr JSON blob against the live schemaRequires Node v24.
npm ci
npm run buildBuilt output: dist/index.js (ESM, produced by tsc).
Add to your repo's .mcp.json (already committed at repo root):
{
"mcpServers": {
"tldraw": {
"type": "stdio",
"command": "node",
"args": ["tools/tldraw-mcp/dist/index.js"]
}
}
}The universal npx -y github:jinsoo/tldraw-mcp form (see below) can also be used here once the standalone repo is published.To upgrade to a newer tldraw release:
./track-upstream.shThis bumps @tldraw/* in package.json, re-extracts src/defaults.json via npm run probe-defaults, vendors a fresh llms-docs.txt, rebuilds, and runs the full test suite. Do NOT run during active development.
llms-docs.txt is the tldraw LLM reference doc vendored at the pinned version. It is fetched by track-upstream.sh from https://tldraw.dev/llms-docs.txt.
The correct write shape (do NOT use serializeTldrawJson — needs Editor):
{
tldrawFileFormatVersion: 1,
schema: store.schema.serialize(),
records: store.allRecords() // flat ARRAY, not a map
}schemaVersion is 2 for tldraw 5.1.1.
Runs straight from GitHub — no npm account, no local checkout:
npx -y github:jinsoo/tldraw-mcpClaude Code (.mcp.json):
{ "mcpServers": { "tldraw": { "type": "stdio", "command": "npx", "args": ["-y", "github:jinsoo/tldraw-mcp"] } } }Any MCP host that registers stdio servers (config.yaml mcp_servers example):
tldraw: { type: stdio, command: npx, args: ["-y", "github:jinsoo/tldraw-mcp"], enabled: true }Tools: read_tldr, write_tldr, validate_tldr.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.