Agentic Mermaid
REMOTE · AGENTIC-MERMAID.DEV · 2 COMPONENTS · SCANNED AUG 3
Render, verify, describe, and safely edit Mermaid diagrams through MCP.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability48
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 5241 tokens (~582/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
- Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · agentic-mermaid.dev
claude mcp add --transport http adewale-agentic-mermaid https://agentic-mermaid.dev/mcp
[mcp_servers.adewale-agentic-mermaid] url = "https://agentic-mermaid.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"adewale-agentic-mermaid": {
"type": "remote",
"url": "https://agentic-mermaid.dev/mcp",
"enabled": true
}
}
} openclaw mcp add adewale-agentic-mermaid --url https://agentic-mermaid.dev/mcp --transport streamable-http
mcp_servers:
adewale-agentic-mermaid:
url: "https://agentic-mermaid.dev/mcp" {
"mcpServers": {
"adewale-agentic-mermaid": {
"type": "http",
"url": "https://agentic-mermaid.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +5
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- The server no longer declares the “prompts” capability functional
- The server no longer declares the “resources” capability functional
- Server version: 0.3.2 → 0.4.0 functional
- 29 Jul 26 +1
- Stability: unverified → 0.03 ▲ functional
- 28 Jul 26 +46
- Authorization: unverified → partial ▲ security
- Transport: fail → pass ▲ security
- MCP protocol: unverified → pass ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 100 functional
- First check of Schema quality: good functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 16
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://agentic-mermaid.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=agentic-mermaid.dev | CN=WE1,O=Google Trust Services,C=US | 2 Jul 2026 | 1 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | 53ffd78bb0418d250e3de9ceb581e0d5 |
| SANs: agentic-mermaid.dev, *.agentic-mermaid.dev | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC insecure
Validation of agentic-mermaid.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| agentic-mermaid.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
| x-content-type-options | nosniff |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://agentic-mermaid.dev/mcp | Verified | 200 | |
| http (plaintext) | http://agentic-mermaid.dev/mcp | HTTPS enforced | 301 | https://agentic-mermaid.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
build Build Mermaid diagram ~158
Author a new Mermaid diagram from blank by folding a list of structured ops over an empty diagram of `family`. The declarative counterpart to hand-writing source. Returns the same envelope as `mutate`: { ok, family, source, verify } or { ok:false, family, opIndex, error }. Call `describe_sdk` for the family before authoring unfamiliar ops.
| Name | Type | Req | Description |
|---|---|---|---|
| family | string | yes | Diagram family to author (one of: flowchart, state, sequence, timeline, class, er, journey, architecture, xychart, pie, quadrant, gantt, mindmap, gitgraph, radar). |
| ops | array | yes | Non-empty ordered list of ops; each is { kind, ...fields }. |
No output schema declared.
No examples provided.
describe Describe Mermaid diagram ~105
Describe a Mermaid diagram. format=text returns { ok, text } with one or two summary sentences; format=json returns { ok, tree } with the AX tree; format=facts returns { ok, facts } with deterministic semantic fact lines for machine checking (for example edge A -> B : label, member Duck +quack()).
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | — | text (default), json AX tree, or facts semantic read-back. |
| source | string | yes | Mermaid source. |
No output schema declared.
No examples provided.
describe_sdk Describe Mermaid SDK operations ~106
Return version-matched mutation operations for one diagram family. Use detail=signatures for the compact op menu or detail=fields (default) for exact field types, required flags, enum values, defaults, and constraints. Call this before build, mutate, or execute when the family schema is not already known.
| Name | Type | Req | Description |
|---|---|---|---|
| detail | string | — | signatures for a compact menu; fields for the complete schema (default). |
| family | string | yes | Diagram family whose mutation operations are needed. |
No output schema declared.
No examples provided.
execute Execute Mermaid SDK code ~3,766
Run JavaScript in an isolated sandbox; return a value. One call composes edits. Submit JavaScript; declaration types are guidance. No promises, async/await, dynamic import, or type annotations. Hosted note: execute runs in an on-demand isolate and costs more than the direct render_svg/render_ascii/render_png/verify/describe tools — prefer those for plain render/verify calls. For straightforward structured edits, prefer the declarative mutate/build tools; reserve execute for logic the ops don't express. Hosted mermaid.renderMermaidSVG*, renderMermaidASCII*, and layoutMermaidWithReceipt calls force security:'strict' and embedFontImport:false; caller code cannot weaken that host policy. SDK declaration: type DiagramKind = 'flowchart' | 'state' | 'sequence' | 'timeline' | 'class' | 'er' | 'journey' | 'architecture' | 'xychart' | 'pie' | 'quadrant' | 'gantt' | 'mindmap' | 'gitgraph' | 'radar' type MutationOp = { kind: string; [field: string]: unknown } type Result<T, E = { code: string; message: string }> = { ok: true; value: T } | { ok: false; error: E } interface SourceLocation { readonly line: number; readonly col: number } interface SourceMapSpans { readonly preserved: PreservedSourceSpans; readonly nodes: ReadonlyMap<string, SourceSpan>; readonly edges: ReadonlyMap<string, SourceSpan>; readonly groups: ReadonlyMap<string, SourceSpan>; readonly labels: ReadonlyMap<string, SourceSpan> } interface SourceMap { readonly nodes: ReadonlyMap<string, SourceLocation>; readonly edges: ReadonlyMap<string, SourceLocation>; readonly groups: ReadonlyMap<string, SourceLocation>; readonly labels: ReadonlyMap<string, SourceLocation>; readonly spans?: SourceMapSpans } interface ValidDiagram { readonly kind: DiagramKind; readonly source: SourceMap } type ExternalFamilyId = `family:${string}` interface ExtensionCompatibility { readonly [contract: string]: string | undefined readonly core?: string readonly scene?: string } interface ExtensionProvenance { readonly owner: string; r…
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | JavaScript to execute; mermaid.* SDK is global. |
| timeoutMs | integer | — | Optional CPU-time budget (default 5000ms, max 30000ms). |
No output schema declared.
No examples provided.
mutate Edit Mermaid diagram ~239
Apply a list of structured edit ops to an existing Mermaid `source` and return the edited diagram. This is the declarative counterpart to `execute`: plain JSON in, plain JSON out, no sandbox. Prefer it for straightforward edits; reserve `execute` for logic the ops don't express. Returns { ok, family, source, verify:{ ok, warnings } } on success, or { ok:false, family, opIndex, error } — where `error` names the offending field and lists the valid ones — when an op is malformed or cannot apply. Ops apply in order and are all-or-nothing: the first failing op stops the batch (its position is `opIndex`) and the input is left untouched. Each op is { "kind": <op>, …fields }. Call `describe_sdk` for the detected family before authoring unfamiliar ops; it returns compact signatures or exact field types, enum values, defaults, and constraints.
| Name | Type | Req | Description |
|---|---|---|---|
| ops | array | yes | Non-empty ordered list of edit ops; each is { kind, ...fields }. |
| source | string | yes | Mermaid source to edit. |
No output schema declared.
No examples provided.
render_ascii Render Mermaid as text ~129
Render a Mermaid source string to text. Returns { ok, text }. useAscii true → plain ASCII (+,-,|); false/absent → Unicode box drawing (┌,─,│). targetWidth sets a hard terminal display-cell bound; impossible bounds return a typed error.
| Name | Type | Req | Description |
|---|---|---|---|
| options | object | — | Shared advanced RenderOptions object, including style/palette/config/security. |
| source | string | yes | Mermaid source. |
| targetWidth | integer | — | Hard maximum line width in terminal display cells. |
| useAscii | boolean | — | true = ASCII characters, false = Unicode (default). |
No output schema declared.
No examples provided.
render_png Render Mermaid as PNG ~150
Rasterize a Mermaid source string to PNG. Returns { ok, png_base64 }. Hosted rendering uses resvg-wasm with bundled fonts; bytes may differ from the local napi renderer, so hosted PNG is a convenience surface, not part of the byte-determinism contract. For file/URL artifacts use the local stdio server.
| Name | Type | Req | Description |
|---|---|---|---|
| background | string | — | Portable basic color or hex color painted behind the raster artifact. |
| fitTo | object | — | Exactly one output width or height constraint. |
| options | object | — | Shared advanced RenderOptions object. |
| scale | number | — | Positive output scale used when no fitTo constraint is supplied. |
| source | string | yes | Mermaid source. |
No output schema declared.
No examples provided.
render_svg Render Mermaid as SVG ~218
Render a Mermaid source string to themeable SVG. Returns { ok, svg }. Layout is deterministic: identical input produces identical geometry. The hosted boundary forces security:'strict' and embedFontImport:false.
| Name | Type | Req | Description |
|---|---|---|---|
| options | object | — | Shared advanced RenderOptions object. Styles accept a registered Look (crisp, hand-drawn, excalidraw, pen-and-ink, freehand, watercolor, blueprint, look:tufte, accessible-high-contrast, patent-drawin… |
| source | string | yes | Mermaid source. |
No output schema declared.
No examples provided.
verify Verify Mermaid diagram ~115
Parse and verify a Mermaid diagram without rendering it. Returns { ok, family, summary, warnings, layout: { bounds, nodes, edges } } for valid diagrams and { ok: false, errors } for parse failures. `family` is the detected diagram family and `summary` a one-line description — check them: ok:true only means the diagram is structurally valid, not that it is the kind you intended. Warnings use the layout-rubric codes.
| Name | Type | Req | Description |
|---|---|---|---|
| source | string | yes | Mermaid source. |
No output schema declared.
No examples provided.