Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

SlideForge

PYPI · SLIDEFORGE-MCP · 2 COMPONENTS · SCANNED SEP 20

Deterministic, fully editable PowerPoint from typed slide intents. 200+ layouts, brand templates.

0 this week 63 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security50
  • Malware scan not yet available for this package.Unverified
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs hatchling.build at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
  • 2 of 41 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability50
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 5782 tokens (~826/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
  • Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage97
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 91% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the SlideForge MCP server?

SlideForge runs locally as a PyPI package, launched with uvx slideforge-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · slideforge-mcp

# add to Claude Code
claude mcp add dev-slideforge-slideforge -- uvx slideforge-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "dev-slideforge-slideforge": {
      "command": "uvx",
      "args": [
        "slideforge-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "dev-slideforge-slideforge": {
      "command": "uvx",
      "args": [
        "slideforge-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add dev-slideforge-slideforge -- uvx slideforge-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-slideforge-slideforge": {
      "type": "local",
      "command": [
        "uvx",
        "slideforge-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dev-slideforge-slideforge --command uvx --arg slideforge-mcp
# ~/.hermes/config.yaml
mcp_servers:
  dev-slideforge-slideforge:
    command: "uvx"
    args: ["slideforge-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "dev-slideforge-slideforge": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "slideforge-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add dev-slideforge-slideforge -t stdio -c uvx -a slideforge-mcp
// mcp.json
{
  "mcpServers": {
    "dev-slideforge-slideforge": {
      "command": "uvx",
      "args": [
        "slideforge-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 19 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

  • 17 Sept 26 −3
    • Stability: pass → 0.80 functional
  • 16 Sept 26 +1
    • Stability: 0.97 → pass security
  • 14 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.

  • 12 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

  • 10 Sept 26 −3
    • Stability: pass → 0.80 functional
  • 9 Sept 26 +1
    • Stability: 0.97 → pass security
    • Package version: 5.5.1 → 5.9.0 functional
  • 8 Sept 26 0
    • Package version: 5.5.1 → 5.9.0 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Analysed pypi/slideforge-mcp@5.9.0

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem pypi

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted hatchling.build

Background: Why install scripts are a supply-chain risk →

Dependencies 41 packages
Packages resolved 41
Stale 1
No linked repository 1
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 7 exposed · ~5,725 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
browse_catalog ~523

Browse the PowerPoint slide catalog progressively. No args -> form overview (when-to-use, bound fields, variant counts). family=<form> -> variant one-liners. q=<text> -> ranked search. variant=/prior_id= -> example payload. type=schema + family -> a compact family-level variant chooser (not a sendable contract); type=schema + family + variant -> that variant's exact payload contract (JSON Schema, capacity, field mapping, examples). Free. Code path: type=widgets = the add_widget() catalog (name=<widget> for its contract + thumbnail); type=helpers = python-pptx helper signatures. type=themes + an uploaded theme_id -> that template's branded FURNITURE layouts (its own cover/agenda/divider/closing slides + fill schemas + previews) — render via create_slide(form=template_layout, theme_id, data={layout, fills}).

NameTypeReqDescription
familystring
limitintegerMax results (with q= or family=).
namestringWidget name (with type=widgets): returns the full contract + worked example + a rendered thumbnail.
offsetintegerPagination offset (with q= or family=).
prior_idstring
qstringSemantic search across all variants; returns ranked form/variant matches with scores.
sourcestringTheme source filter (with type=themes). Default all (built-in + your saved).
theme_idstringWith type=themes: an uploaded theme's id -> its branded furniture layouts + fill schemas (render via create_slide(form=template_layout)).
topintegerMax results (with type=themes).
typestringOmit for the form overview (or family=/q= to drill in). schema (+family, optionally +variant=) = schema-first discovery: family only returns a compact variant chooser; family+variant returns that var…
variantstring

No output schema declared.

No examples provided.

create_deck ~721

Create a complete PowerPoint presentation (.pptx): a whole multi-slide deck, native and editable, in one call. `slides` is a list of create_slide intents (same form menu + data shapes — see create_slide). Slides fill in parallel and merge into one themed PPTX with page numbers. Include furniture: a hero_statement cover, section_divider breaks, and a closing (hero_statement variant=contact_closing via blocks-free slots). BLOCKED ($0)? If an error has `can_autofix:true`, merge its `patch` into the args at `patch_target`. Unchanged retries repeat the block. New form: browse_catalog(type=schema) first. Also: mode=assemble merges existing slide job_ids as-rendered (free; theme_id does NOT re-theme them — render with create_deck(slides=[…], theme_id=…) for a unified theme); mode=fork clones a deck (free). Polling: deck_id == job_id — manage_account(action=job, job_id=<deck_id>).

NameTypeReqDescription
allow_partialbooleanIGNORED. A deck bills per rendered slide and always returns its pptx; slides that failed or rendered badly are free and named in repair_actions.
deck_idstringExisting deck ID (for mode=fork, or mode=render to update)
directionstringDeck-level writing direction, inherited by every slide (a slide-level direction wins) — set it once for an Arabic/Hebrew deck. Covers/dividers rendered on an UPLOADED brand template keep that templat…
dry_runbooleanDeck-level free pre-flight (cost:0, NO render/PPTX): returns a per-slide validation manifest [{i, form, fidelity_forecast, status, errors}] so you can fix bad slides before spending. A deck is one ar…
force_renderbooleanIGNORED (deck-level). pptx_url is always returned when at least one slide rendered, so there is nothing to force. Still meaningful on create_slide.
imagerystringDeck-level imagery mode, inherited by every slide (a slide-level imagery wins). See create_slide.imagery.
imagery_tagstringDeck-level subject declaration, inherited by every slide (a slide-level imagery_tag wins). Declare it once for a whole deck. See create_slide.imagery_tag.
job_idsarraySlide job IDs to merge (for mode=assemble)
languagestringTarget language
logo_idstringOptional brand logo (from upload_asset purpose=logo) applied as chrome to every content slide in the deck.
modestringDefault render. assemble/fork are free deck plumbing.
namestring
slidesarrayeach item is a create_slide intent (same form menu, typed fields, and data shapes as create_slide).
strict_policyobjectOptional CI-style gate for automated report pipelines. dry_run returns policy_result; render returns rejected/cost:0 if the policy fails.
stylingstringDeck-level topical-design switch, inherited by every slide (a slide-level styling wins). See create_slide.styling.
theme_idstring
titlestringDeck title (PowerPoint metadata)

No output schema declared.

No examples provided.

create_slide ~2,623

Create one PowerPoint slide (.pptx, native, editable) from a structured intent in ONE call: pick a `form` from the menu and put your content in the typed fields (placed on the slide as given), or pass a `brief` and let the server route it. Fields tagged (per-form) bind only where the form has that slot — ignored-with-warning elsewhere; see each form's `binds` in browse_catalog. BLOCKED ($0)? If an error has `can_autofix:true`, merge its `patch` into the args at `patch_target`. Unchanged retries repeat the block. New form: browse_catalog(type=schema) first. FORM MENU: agenda_list: an ordered list of sections/topics or learning objectives to walk through bar_rank_chart: bars comparing magnitudes across categories calendar_grid: events on a real calendar - week planner (day x hour) or month grid with event chips (data.events) card_grid: several equal, unordered peer blocks (features, options, pillars, a concept's defined parts, rules/guidelines/common mistakes) case_story: one named story told as evidence: challenge, action, measured result comparison_matrix: options x criteria grid: data.columns x data.rows cycle_flow: a closed loop of ordered stages where the last feeds the first (recurring process) data_table: a plain factual table of records by fields editorial_split: two side-by-side halves: contrast (before/after, problem/solution) or copy/numbered steps beside a picture (image_src) exercise_prompt: an exercise/practice/discussion prompt: instruction + hints; optional problem items with blank answer boxes funnel: a quantity narrowing through ordered stages gantt_plan: tasks as bars across named periods on a schedule grid gauge_score: one score on a dial against a scale hero_statement: a statement slide: covers (typographic/image/exec), from->to/thesis-quote transitions, statement/contact/next-steps closings; supporting points -> takeaway_stack, contacts -> data.contacts, next steps -> data.next_steps hub_spoke: one central elemen…

NameTypeReqDescription
allow_fabricationbooleanBrief mode only: a bare brief on a DATA form (kpi/funnel/comparison/…) returns would_fabricate at $0 rather than INVENT numbers. Send typed fields for verbatim, or true to let the brief author them (…
allow_low_confidencebooleanBrief routing only: by default a brief that doesn't match a form clearly returns status=needs_confirmation + candidates at cost:0 (no guessed render). Set true to render the top guess and bill it. De…
allow_truncationbooleanMore items than the form holds blocks (it would drop your data); the response names the dropped count + a suggested_split. true renders the capacity subset (fidelity=verbatim_truncated). Default fals…
allow_variant_fallbackbooleanIf the pinned variant is unknown, render the form's default variant (with a warning) instead of rejecting. Default false.
blocksarraylist: [{"label","sub","detail":[str],"emphasis","icon":lucide-name,"metric":{value,label}}]
briefstringprose fallback / extra context for fills
cautionstringone-line risk / caveat callout (per-form).
codestringPython code defining build(prs). Canvas 13.33×7.5", coords in inches. Pre-imported: Presentation, Inches, Pt, Emu, RGBColor, MSO_ANCHOR, PP_ALIGN. Helpers: add_text_box(slide, left, top, w, h, text,…
contextstringone-line subtitle/standfirst
dataobjectfamily-specific payload — see the documented shapes
datestringdate callout (per-form).
detailstringResponse verbosity. Default `compact`: status, form/variant, fidelity (verbatim|mixed|ai_completed), warnings[]/errors[] (only when present), urls, cost. `full` adds a debug object (engine internals,…
directionstringrtl typesets AND mirrors the slide right-to-left (Arabic/Hebrew). Never inferred — pass it.
dry_runbooleanFree pre-commit check (intent or mode=code), cost:0, no PPTX: status + warnings/errors, plus fidelity_forecast (verbatim|mixed|ai_completed|would_reject) and which fields bind vs get authored. Fix er…
force_renderbooleanOn completed_with_errors, pptx_url is null (broken slide). Set true to get it anyway. No cost/status effect.
formstringthe form menu pick (see description) — the routing field
form_descriptionstring
headlinestringthe assertion-style slide title
highlightstringone-line emphasis callout (per-form).
image_promptstringgenerate an image when no image_src (+$0.05)
image_srcstringhttps URL | asset:<id> for image-bearing forms
imagerystringCover/section-divider imagery: photo (default — curated stock photo, half-bleed), wash (abstract color wash), off (typographic only). Content slides are never photo-decorated.
imagery_tagstringSubject/industry: steers cover/section photos AND the topical palette. Omit = general; `education` = teaching.
include_previewstringInline-preview PAYLOAD only (not execution). Default: default (768px). none omits the inline image and returns just the URLs — it does NOT change sync/async. Use `wait` to control execution.
job_idstringPrevious job ID (for mode=status, or mode=code patching)
languagestringTarget language (default: en)
logo_idstringOptional brand logo (from upload_asset purpose=logo) drawn as chrome on content slides; covers/section breaks stay clean.
metricobject
min_font_ptnumberBinding type floor for prose (exhibit furniture has its own). Type grows to meet it; content that can't fit is a $0 min_font_not_met naming the size needed. Typical: 12.
modestringDefault: structured intent / brief. safe = validate-then-render in ONE call (renders + bills only if faithful; else $0 invalid report with the fix — recommended, no dry_run round-trip). code = python…
namestring
quality_profilestringThresholds layout.presentation_ready is judged against (executive strictest). Measurement only — never blocks a render or changes cost.
replacementsarrayString replacements on loaded code [{old, new}] (for mode=code with job_id)
source_notestringsource / footnote line (per-form).
stylingstringTopical design on default themes (default on; the note names it): designed cover + a subject palette (from imagery_tag, or the brief). clean = neutral. Pins never take it.
subjectstringcentral entity for forms that have one — hub label, org root, section #, fork origin, media label (per-form).
takeawaystringoptional verdict band (per-form). Put the so-what in the headline; add only for a verdict the title can't carry — not every slide.
theme_idstringOptional theme id from browse_catalog(type=themes). Omit for Default (slideforge_standard).
variantstringpin a specific variant within the form (list them via browse_catalog). Unknown variant -> rejected ($0) with the valid list; set allow_variant_fallback to render the family default instead.
variant_policystringRouted-variant maturity policy: production_safe = if the ROUTED variant is draft/beta, render the family's demo-safe sibling instead (warning names both). Never overrides an explicit variant=. Defaul…
verifystringmode=code tier. Default `lint`: static geometry linter (overlap/off-canvas/zero-size) + composer content validators — no LLM. `lint+vlm` adds a VLM second-look (~+3s) and makes a blank/contentless re…
waitstringAI-image slides block ~10-15s; `false` returns a job_id to poll, not block (mode=brief).

No output schema declared.

No examples provided.

manage_account ~872

SlideForge account for PowerPoint generation: balance, billing, job history, feedback, data controls. All free. Actions: status (balance+plan), usage (spend breakdown), jobs (history), job (single job detail — slide jobs include `quality_warnings[]`; deck jobs add `slides_completed/slides_failed/failed_slides[]`), feedback (submit), feedback_list (read your reports back: status + resolution), onboarding (capabilities overview), topup (Stripe checkout link; wallet credits automatically), webhooks/webhook_add/webhook_remove/webhook_test (push endpoint instead of polling to terminal), download_url (fresh short-TTL PPTX link for an owned job — when a result carries no inline URL), security_status (retention + access-model + deletion posture), delete_job (irreversible: job + versions + files) Action delete_asset irreversibly deletes a user-owned uploaded/generated image asset.

NameTypeReqDescription
actionstringyesOperation (required). feedback → report a defect or request against a render; pass job_id so it is actionable, and ask the user before filing. feedback_list → read YOUR OWN filed reports back, with `…
amountnumberUSD top-up amount (for action=topup, default 10, min 10, max 1000). Volume bonus: $50→+10%, $100→+15%, $200→+20%.
asset_idstringImage asset ID (for action=delete_asset). Logos are content-addressed/shared and are not deleted by this action.
categorystringFeedback category (action=feedback to file under it, action=feedback_list to filter by it). The first nine are slide-quality categories — pair them with job_id.
daysintegerLookback period (for action=usage, default 30)
detailbooleanFor action=status only: default false masks identity fields; true returns full email/user_id diagnostics for the authenticated user.
eventsarrayEvent types to subscribe to (for action=webhook_add; default all): job.completed, job.failed, deck.completed, deck.partial, deck.failed.
include_childrenbooleanFor action=jobs: include deck child slides (each carries parent_deck_id) so a deck's slides are discoverable by listing. Default false (parents only). Deck rows roll child cost up to the deck.
include_previewstringPreview (for action=job)
job_idstringJob ID (for action=job, action=download_url and action=delete_job)
limitintegerMax rows (action=jobs default 10; action=feedback_list default 50, max 100)
messagestringWhat went wrong or what you want, in the user's own words (for action=feedback).
severitystringFor action=feedback: `bug` = it is broken, `quality` = it rendered but reads poorly, `suggestion` = a request. Defaults to suggestion, so file real defects explicitly or they are triaged as wishes.
slugstringReport slug (for action=reports — returns one report's full metadata; omit to list all).
statusstringFilter — action=jobs: queued/generating/complete/failed; action=feedback_list: open/resolved
urlstringHTTPS endpoint to receive events (for action=webhook_add). Must be public HTTPS (private/loopback rejected).
webhook_idstringWebhook subscription id (for action=webhook_remove / webhook_test).

No output schema declared.

No examples provided.

plan_slide ~278

Plan a PowerPoint slide before rendering (free): send a short brief, get ranked candidates + a separated verdict — route (which slide: selected|needs_confirmation|ambiguous), input (can it render: ready|extractable_from_brief|needs_structured_data) and next_action. Free (one embedding). Then call create_slide with the chosen form(+variant). route.confidence: calibrated = measured P(route correct) with label high/medium/low cut on it; retrieval_score/retrieval_margin = the raw family-aggregated classifier values (not probabilities; margin can be negative when families contest); source = classifier | structural_router (LLM-rescued). candidate_margin on the top candidate = literal gap between the two shown scores.

NameTypeReqDescription
briefstringyes
escalatebooleanDefault true: on a low-confidence route the plan runs the SAME LLM rescue create_slide would (small COGS on that tail only), so plan and create always agree. Set false for a classifier-only, fully fr…
topinteger
variant_policystringproduction_safe: if the top routed variant is draft/beta, the family's demo-safe sibling leads and route reports both best_semantic and best_production_safe.

No output schema declared.

No examples provided.

translate_deck ~226

Translate a PowerPoint (.pptx) deck preserving all formatting. $0.02/slide. Supports 32 languages (Latin, Cyrillic, Greek scripts). Provide job_id (from a previous create_slide/create_deck), pptx_url, or pptx_base64.

NameTypeReqDescription
concise_modebooleanPrefer shorter translations for tight text boxes
include_notesbooleanTranslate speaker notes (default false)
include_previewstringWait+embed preview (default=wait)
include_tablesbooleanTranslate table cells (default true)
job_idstringSource: previous slide/deck job ID (preferred — no file transfer needed)
namestringJob name
pptx_base64stringSource: Base64-encoded .pptx (max ~10 MB)
pptx_urlstringSource: HTTPS URL to .pptx
source_languagestringSource language or 'auto' (default auto)
target_languagestringyesTarget language (required)

No output schema declared.

No examples provided.

upload_asset ~482

Upload assets for PowerPoint (.pptx) generation: company template, logo, image, or document — or AI-generate an image. Purposes: • logo — company logo for chrome (PNG/JPG/SVG, max 5MB) → logo_id • image — image for the Image component (max 10MB) → asset_id • theme — company template PPTX → theme_id; slides with it render NATIVELY on the template (masters/layouts/chrome) • generate_image — AI-generate via `prompt` → asset_id ($0.05) • translate — PPTX to translate → deck job_id ($0.02/slide; requires `target_language`) • pdf — PDF → editable slides; pass `target_language` to also translate • recreate — image OF a slide → editable PPTX slide ($0.10; honest annotate/preserve fallback, refusals free). Use `image` to just place a picture Files >3MB (pdf/translate/theme) — and recreate on chat hosts — omit `data`: a drop-zone appears in the result card; bytes never pass through the agent.

NameTypeReqDescription
datastringBase64-encoded file content. Required for logo/image/theme/translate. Optional for pdf — omit to get a drop-zone (recommended for files >3MB).
filenamestringOriginal filename (for type detection)
modelstringExplicit gateway model ID. Overrides `quality`.
positionstringLogo position: top-left / top-right / bottom-left / bottom-right
promptstringImage description (required when purpose=generate_image)
purposestringyesAsset type (required). brand = a .pptx/.potx corporate template imported as your brand kit (theme is the same thing under its old name).
qualitystringdraft = Flux Schnell. balanced (default) = Gemini Flash Image. premium = Imagen 4 Fast. Overridden by `model`.
sizestringImage dimensions for generate_image (default 1024×1024)
target_languagestringRequired for purpose=translate. Optional for purpose=pdf — chains pdf→pptx→translate in one call.
theme_namestringName for extracted theme (purpose=theme)

No output schema declared.

No examples provided.

Common questions

What is the SlideForge MCP server?

SlideForge is an MCP server listed in the public MCP registry as dev.slideforge/slideforge. Deterministic, fully editable PowerPoint from typed slide intents. 200+ layouts, brand templates. This page covers its PyPI package (slideforge-mcp).

Is the SlideForge MCP server safe to use?

SlideForge scores 63 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the SlideForge MCP server expose?

SlideForge exposes 7 tools: browse_catalog, plan_slide, create_slide, create_deck, translate_deck, and 2 more. Their descriptions and schemas cost roughly 5,725 tokens of context every time the server is loaded.

Is the SlideForge MCP server still maintained?

SlideForge is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the SlideForge MCP server under?

SlideForge declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.