
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
MatPlotLibNet.Mcp
Advanced tools
MCP (Model Context Protocol) stdio server for MatPlotLibNet. An AI agent renders the library's chart types to PNG, SVG or PDF from a JSON spec, reads the chart's data back as a markdown table, lists the chart types and reads the spec schema — no browser, no service.
mcp-name: io.github.xkqg/matplotlibnet
An MCP (Model Context Protocol) server for MatPlotLibNet. It gives an AI agent (Claude Code, VS Code, Claude Desktop, or any other MCP host) five tools:
| tool | what it does |
|---|---|
render_chart | renders a chart spec to a PNG image the model can look at |
save_chart | writes the chart as PNG, SVG or PDF to a file and returns the path it wrote |
chart_data_table | returns the chart's data as markdown tables the model can read, and the same values as structured content it can compute with |
list_chart_types | lists the chart types the spec accepts; the list is read from the library's own registry |
describe_chart_schema | describes the fields of the spec and gives a worked example for a chart type |
The server communicates over stdio. It is a .NET tool: a host runs it with dnx MatPlotLibNet.Mcp (the .NET 10 SDK
resolves and starts it), or with dotnet tool exec MatPlotLibNet.Mcp.
{
"servers": {
"MatPlotLibNet.Mcp": {
"type": "stdio",
"command": "dnx",
"args": ["MatPlotLibNet.Mcp", "--yes"]
}
}
}
The spec is the library's own figure JSON: the same document that figure.ToJson() writes and
ChartSerializer.FromJson reads. The agent can therefore ask for any chart the library can draw:
{
"width": 800, "height": 600, "title": "Revenue",
"subPlots": [{
"series": [{ "type": "line", "xData": [1, 2, 3, 4, 5], "yData": [2, 4, 3, 5, 1], "label": "Q1" }]
}]
}
The server validates the spec before it renders. It rejects an unknown field, an unknown chart type, a misspelled enum value, a colour the library does not know, or a missing size. The error message names the field that is wrong, so the model can correct the spec instead of receiving a blank picture.
render_chart returns the PNG as an image block. Beside it, it returns a short text summary (chart types, series,
axis ranges), so a model that cannot see the image still knows what it made. SVG and PDF output is large, so it
goes to a file through save_chart and is never returned inline.
The SVG this server writes stores text as glyph outlines (<path>), not as <text> elements. This is because the
PNG backend is loaded in the same process, and the library then embeds its own font so that the drawing is
identical everywhere.
save_chart writes only under one directory: the system temp directory, or the one named by the
MATPLOTLIBNET_MCP_OUTPUT_ROOT environment variable. It never overwrites an existing file unless asked.MATPLOTLIBNET_FONTS environment variable, separated by ;; they are
registered when the server starts. A bad entry is logged and skipped.MIT — see the repository.
FAQs
MCP (Model Context Protocol) stdio server for MatPlotLibNet. An AI agent renders the library's chart types to PNG, SVG or PDF from a JSON spec, reads the chart's data back as a markdown table, lists the chart types and reads the spec schema — no browser, no service.
We found that MatPlotLibNet.Mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.