
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
cad-mcp-server
Advanced tools
Give your AI assistant the ability to inspect, measure, and compare 3D CAD models. Works locally with any STEP file — no CAD license, no cloud, no setup.
Give your AI assistant the ability to inspect, measure, and compare 3D CAD models. Drop in a STEP file, ask engineering questions, get measured answers. Runs entirely on your machine — no cloud, no CAD license, no setup.
npx -y cad-mcp-server
Add to your MCP client:
{
"mcpServers": {
"cad": {
"command": "npx",
"args": ["-y", "cad-mcp-server"]
}
}
}
Point your AI at any STEP file and ask questions like:
"Review this part before manufacturing. Check wall thickness, draft angles, and hole sizes. Flag anything that violates standard DFM rules."
| Tool | Example question |
|---|---|
inspect_step | "What are the overall dimensions and volume?" |
find_faces | "Find all cylindrical faces. Which ones are holes vs bosses?" |
find_edges | "What's the smallest fillet radius on this part?" |
measure_geometry | "Check wall thickness around every hole. Flag anything below 2mm." |
diff_step | "What changed between revision A and revision B?" |
The AI assistant interprets the measurements. You get engineering answers, not raw numbers.
See docs/EXAMPLE_PROMPTS.md for more.
MIT. The bundled OCCT kernel uses LGPL-2.1. See THIRD_PARTY_NOTICES.md.
FAQs
Give your AI assistant the ability to inspect, measure, and compare 3D CAD models. Works locally with any STEP file — no CAD license, no cloud, no setup.
The npm package cad-mcp-server receives a total of 106 weekly downloads. As such, cad-mcp-server popularity was classified as not popular.
We found that cad-mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.