
Research
/Security News
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
@aicanvas/mcp
Advanced tools
Model Context Protocol server for AI Canvas — search, inspect, and install components from the aicanvas.me registry directly from your AI editor.
@aicanvas/mcpModel Context Protocol server for AI Canvas. Lets your AI editor (Claude Code, Cursor, Claude Desktop, Codex) discover and install AI Canvas components without leaving the chat.
You: "find me an animated card stack"
AI: [calls search_components → ranks matches → picks polaroid-stack]
[calls get_install_command → returns: npx shadcn add @aicanvas/polaroid-stack]
[runs the command — file lands in your project]
You: "make the rotation more dramatic"
AI: [edits the file directly]
Five tools, derived from the live aicanvas.me registry — adding a component to the website auto-updates the MCP within minutes:
| Tool | Purpose |
|---|---|
list_categories | Show every category with component counts. Orient before drilling in. |
list_components | Browse components, optionally filtered by category. Paginated. |
search_components | Fuzzy keyword search across slugs, names, descriptions, categories, tags. Ranked results. |
get_component | Full metadata + complete .tsx source code for one component. |
get_install_command | Get the npx shadcn add @aicanvas/<slug> command for a component. |
All tools are read-only. Nothing is mutated on AI Canvas's side.
Edit claude_desktop_config.json:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json~/.config/Claude/claude_desktop_config.json{
"mcpServers": {
"aicanvas": {
"command": "npx",
"args": ["-y", "@aicanvas/mcp"]
}
}
}
Restart Claude Desktop. The aicanvas tools should appear in the tools list.
Project-level (.cursor/mcp.json in your repo) or global (~/.cursor/mcp.json):
{
"mcpServers": {
"aicanvas": {
"command": "npx",
"args": ["-y", "@aicanvas/mcp"]
}
}
}
Project-level .mcp.json (committed alongside your code):
{
"mcpServers": {
"aicanvas": {
"command": "npx",
"args": ["-y", "@aicanvas/mcp"]
}
}
}
Or via the CLI:
claude mcp add aicanvas -- npx -y @aicanvas/mcp
~/.codex/config.toml:
[mcp_servers.aicanvas]
command = "npx"
args = ["-y", "@aicanvas/mcp"]
Inside any of the AI editors above, ask:
"What categories of components does AI Canvas have?"
You should see all 11 categories with counts. If you don't, check the host's MCP logs — typically a "Failed to spawn process" or network error means npx couldn't fetch the package, or the host wasn't restarted after editing the config.
To inspect the server outside an editor:
npx -y @modelcontextprotocol/inspector npx -y @aicanvas/mcp
This opens a browser UI where you can call each tool by hand.
| Env var | Default | What it does |
|---|---|---|
AICANVAS_REGISTRY_BASE | https://aicanvas.me/r | Registry root URL. Override only for local development against a self-hosted mirror. |
The MCP fetches https://aicanvas.me/r/aicanvas-mcp.json on first use and caches it for 5 minutes. New components on AI Canvas appear in the MCP automatically — no package update required.
The full source code for each component is fetched on demand from /r/<slug>.json (the same shadcn registry items the CLI installs).
git clone https://github.com/uiNerd16/aicanvas.git
cd aicanvas/mcp
npm install
npm run build
# Smoke-test against the deployed registry:
npm run inspect
# Or point at a locally running aicanvas dev server:
AICANVAS_REGISTRY_BASE=http://localhost:3000/r node dist/index.js
Edit src/index.ts, run npm run build, restart your AI editor.
MIT — same as the AI Canvas project.
FAQs
Model Context Protocol server for AI Canvas: search, inspect, and install components from the aicanvas.me registry directly from your AI editor.
The npm package @aicanvas/mcp receives a total of 203 weekly downloads. As such, @aicanvas/mcp popularity was classified as not popular.
We found that @aicanvas/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.