Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Agentic Mermaid

REMOTE · AGENTIC-MERMAID.DEV · 2 COMPONENTS · SCANNED SEP 20

Render, verify, describe, and safely edit Mermaid diagrams through MCP.

0 this week 83 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security80
Transport & Reachability100
Schema Quality & AI Usability60
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 5241 tokens (~582/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "execute" implies "execute" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Fail
  • An AI judge read all 10 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the Agentic Mermaid MCP server?

Agentic Mermaid is a hosted endpoint at https://agentic-mermaid.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · agentic-mermaid.dev

# add to Claude Code
claude mcp add --transport http adewale-agentic-mermaid 'https://agentic-mermaid.dev/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "adewale-agentic-mermaid": {
      "url": "https://agentic-mermaid.dev/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "adewale-agentic-mermaid": {
      "type": "http",
      "url": "https://agentic-mermaid.dev/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.adewale-agentic-mermaid]
url = "https://agentic-mermaid.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "adewale-agentic-mermaid": {
      "type": "remote",
      "url": "https://agentic-mermaid.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add adewale-agentic-mermaid --url 'https://agentic-mermaid.dev/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  adewale-agentic-mermaid:
    url: "https://agentic-mermaid.dev/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "adewale-agentic-mermaid": {
      "Transport": "http",
      "Url": "https://agentic-mermaid.dev/mcp"
    }
  }
}
# add to Vellum
assistant mcp add adewale-agentic-mermaid -t streamable-http -u 'https://agentic-mermaid.dev/mcp'
// mcp.json
{
  "mcpServers": {
    "adewale-agentic-mermaid": {
      "type": "http",
      "url": "https://agentic-mermaid.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 27 Aug 26 0
    • Stability: 0.97 → pass security
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 23 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • The server no longer declares the “resources” capability functional
    • The server no longer declares the “prompts” capability functional
    • Server version: 0.3.2 → 0.4.0 functional
  • 29 Jul 26 0
    • Stability: unverified → 0.03 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://agentic-mermaid.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=agentic-mermaid.dev CN=WE1,O=Google Trust Services,C=US 30 Aug 2026 29 Nov 2026 ECDSA 256 ECDSA-SHA256 2cdfccd0e317be1713464951ed52aaeb
SANs: agentic-mermaid.dev, www.agentic-mermaid.dev, *.www.agentic-mermaid.dev
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of agentic-mermaid.dev. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
agentic-mermaid.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000
x-content-type-options nosniff

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://agentic-mermaid.dev/mcp Verified 200
http (plaintext) http://agentic-mermaid.dev/mcp HTTPS enforced 301 https://agentic-mermaid.dev/mcp
MCP tools · 9 exposed · ~4,986 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
build ~158

Author a new Mermaid diagram from blank by folding a list of structured ops over an empty diagram of `family`. The declarative counterpart to hand-writing source. Returns the same envelope as `mutate`: { ok, family, source, verify } or { ok:false, family, opIndex, error }. Call `describe_sdk` for the family before authoring unfamiliar ops.

NameTypeReqDescription
familystringyesDiagram family to author (one of: flowchart, state, sequence, timeline, class, er, journey, architecture, xychart, pie, quadrant, gantt, mindmap, gitgraph, radar).
opsarrayyesNon-empty ordered list of ops; each is { kind, ...fields }.

No output schema declared.

No examples provided.

describe ~105

Describe a Mermaid diagram. format=text returns { ok, text } with one or two summary sentences; format=json returns { ok, tree } with the AX tree; format=facts returns { ok, facts } with deterministic semantic fact lines for machine checking (for example edge A -> B : label, member Duck +quack()).

NameTypeReqDescription
formatstringtext (default), json AX tree, or facts semantic read-back.
sourcestringyesMermaid source.

No output schema declared.

No examples provided.

describe_sdk ~106

Return version-matched mutation operations for one diagram family. Use detail=signatures for the compact op menu or detail=fields (default) for exact field types, required flags, enum values, defaults, and constraints. Call this before build, mutate, or execute when the family schema is not already known.

NameTypeReqDescription
detailstringsignatures for a compact menu; fields for the complete schema (default).
familystringyesDiagram family whose mutation operations are needed.

No output schema declared.

No examples provided.

execute ~3,766

Run JavaScript in an isolated sandbox; return a value. One call composes edits. Submit JavaScript; declaration types are guidance. No promises, async/await, dynamic import, or type annotations. Hosted note: execute runs in an on-demand isolate and costs more than the direct render_svg/render_ascii/render_png/verify/describe tools — prefer those for plain render/verify calls. For straightforward structured edits, prefer the declarative mutate/build tools; reserve execute for logic the ops don't express. Hosted mermaid.renderMermaidSVG*, renderMermaidASCII*, and layoutMermaidWithReceipt calls force security:'strict' and embedFontImport:false; caller code cannot weaken that host policy. SDK declaration: type DiagramKind = 'flowchart' | 'state' | 'sequence' | 'timeline' | 'class' | 'er' | 'journey' | 'architecture' | 'xychart' | 'pie' | 'quadrant' | 'gantt' | 'mindmap' | 'gitgraph' | 'radar' type MutationOp = { kind: string; [field: string]: unknown } type Result<T, E = { code: string; message: string }> = { ok: true; value: T } | { ok: false; error: E } interface SourceLocation { readonly line: number; readonly col: number } interface SourceMapSpans { readonly preserved: PreservedSourceSpans; readonly nodes: ReadonlyMap<string, SourceSpan>; readonly edges: ReadonlyMap<string, SourceSpan>; readonly groups: ReadonlyMap<string, SourceSpan>; readonly labels: ReadonlyMap<string, SourceSpan> } interface SourceMap { readonly nodes: ReadonlyMap<string, SourceLocation>; readonly edges: ReadonlyMap<string, SourceLocation>; readonly groups: ReadonlyMap<string, SourceLocation>; readonly labels: ReadonlyMap<string, SourceLocation>; readonly spans?: SourceMapSpans } interface ValidDiagram { readonly kind: DiagramKind; readonly source: SourceMap } type ExternalFamilyId = `family:${string}` interface ExtensionCompatibility { readonly [contract: string]: string | undefined readonly core?: string readonly scene?: string } interface ExtensionProvenance { readonly owner: string; r…

NameTypeReqDescription
codestringyesJavaScript to execute; mermaid.* SDK is global.
timeoutMsintegerOptional CPU-time budget (default 5000ms, max 30000ms).

No output schema declared.

No examples provided.

mutate ~239

Apply a list of structured edit ops to an existing Mermaid `source` and return the edited diagram. This is the declarative counterpart to `execute`: plain JSON in, plain JSON out, no sandbox. Prefer it for straightforward edits; reserve `execute` for logic the ops don't express. Returns { ok, family, source, verify:{ ok, warnings } } on success, or { ok:false, family, opIndex, error } — where `error` names the offending field and lists the valid ones — when an op is malformed or cannot apply. Ops apply in order and are all-or-nothing: the first failing op stops the batch (its position is `opIndex`) and the input is left untouched. Each op is { "kind": <op>, …fields }. Call `describe_sdk` for the detected family before authoring unfamiliar ops; it returns compact signatures or exact field types, enum values, defaults, and constraints.

NameTypeReqDescription
opsarrayyesNon-empty ordered list of edit ops; each is { kind, ...fields }.
sourcestringyesMermaid source to edit.

No output schema declared.

No examples provided.

render_ascii ~129

Render a Mermaid source string to text. Returns { ok, text }. useAscii true → plain ASCII (+,-,|); false/absent → Unicode box drawing (┌,─,│). targetWidth sets a hard terminal display-cell bound; impossible bounds return a typed error.

NameTypeReqDescription
optionsobjectShared advanced RenderOptions object, including style/palette/config/security.
sourcestringyesMermaid source.
targetWidthintegerHard maximum line width in terminal display cells.
useAsciibooleantrue = ASCII characters, false = Unicode (default).

No output schema declared.

No examples provided.

render_png ~150

Rasterize a Mermaid source string to PNG. Returns { ok, png_base64 }. Hosted rendering uses resvg-wasm with bundled fonts; bytes may differ from the local napi renderer, so hosted PNG is a convenience surface, not part of the byte-determinism contract. For file/URL artifacts use the local stdio server.

NameTypeReqDescription
backgroundstringPortable basic color or hex color painted behind the raster artifact.
fitToobjectExactly one output width or height constraint.
optionsobjectShared advanced RenderOptions object.
scalenumberPositive output scale used when no fitTo constraint is supplied.
sourcestringyesMermaid source.

No output schema declared.

No examples provided.

render_svg ~218

Render a Mermaid source string to themeable SVG. Returns { ok, svg }. Layout is deterministic: identical input produces identical geometry. The hosted boundary forces security:'strict' and embedFontImport:false.

NameTypeReqDescription
optionsobjectShared advanced RenderOptions object. Styles accept a registered Look (crisp, hand-drawn, excalidraw, pen-and-ink, freehand, watercolor, blueprint, look:tufte, accessible-high-contrast, patent-drawin…
sourcestringyesMermaid source.

No output schema declared.

No examples provided.

verify ~115

Parse and verify a Mermaid diagram without rendering it. Returns { ok, family, summary, warnings, layout: { bounds, nodes, edges } } for valid diagrams and { ok: false, errors } for parse failures. `family` is the detected diagram family and `summary` a one-line description — check them: ok:true only means the diagram is structurally valid, not that it is the kind you intended. Warnings use the layout-rubric codes.

NameTypeReqDescription
sourcestringyesMermaid source.

No output schema declared.

No examples provided.

Common questions

What is the Agentic Mermaid MCP server?

Agentic Mermaid is an MCP server listed in the public MCP registry as io.github.adewale/agentic-mermaid. Render, verify, describe, and safely edit Mermaid diagrams through MCP. This page covers its hosted endpoint (https://agentic-mermaid.dev/mcp).

Is the Agentic Mermaid MCP server safe to use?

Agentic Mermaid scores 83 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Agentic Mermaid MCP server expose?

Agentic Mermaid exposes 9 tools: execute, describe_sdk, render_svg, render_ascii, render_png, and 4 more. Their descriptions and schemas cost roughly 4,986 tokens of context every time the server is loaded.

Does the Agentic Mermaid MCP server require authentication?

No. We connected to Agentic Mermaid without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Agentic Mermaid MCP server still maintained?

Agentic Mermaid is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.