Back to Browse

Study Design Diagram Studio MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Read and edit a live study design canvas through its predefined WebMCP tools.

About

Read and edit a live study design canvas through its predefined WebMCP tools.

Remote endpoints: streamable-http: https://sdds-webmcp-bridge.jdiazdecaro.workers.dev/mcp

Security Report

4.2
Use Caution4.2High Risk

This is a legitimate epidemiologic study design tool with a WebMCP bridge component. The application itself is well-structured with proper input validation and no malicious patterns. However, the MCP bridge has moderate security concerns: authentication relies on a single bearer token sent via HTTP headers (not scope-limited), the bridge temporarily exposes tool execution to anyone with the token for up to 2 hours, and there is no rate limiting on tool invocations. Additionally, sensitive study data can flow through the Cloudflare relay when the optional remote connection is enabled, though this is disclosed to users. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 2 high severity).

6 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

clipboard

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Study Design Diagram Studio

A browser workspace by Black Swan Causal Labs for creating, reviewing, and exporting epidemiologic study design diagrams.

Live app: https://sdds.blackswancausallabs.com

Features

  • Model washout, inclusion, exclusion, covariate assessment, and follow-up windows relative to an index event.
  • Edit window dates by dragging timeline edges or entering values, with keyboard controls and Undo.
  • Record study details, assessment rules, source notes, footnotes, and abbreviations.
  • Save and import structured JSON; export SVG, PDF, and editable PowerPoint diagrams.
  • Review a completeness checklist and work with a compatible browser agent through 10 WebMCP tools.

The workspace is session-only. Use Save JSON to preserve edits before leaving. The preloaded example was transcribed from a reference figure and has not been verified against its manuscript. Completeness checks establish information presence, not methodological validity or source accuracy. The app does not extract information from PDFs.

Connect an AI agent

The app exposes ten predefined tools for reading, editing, validating, and exporting the current study design. Human and agent edits share the same canvas and Undo history. There are two ways to connect:

ConnectionRequirementsSetup
Native WebMCPA WebMCP-capable browser and agentOpen the studio and let the agent discover the page's tools
Remote MCP bridgeA Streamable HTTP MCP client that supports custom authorization headersEnable a temporary connection in the studio and configure the client with its URL and key

For a remote MCP client:

  1. Open Study Design Diagram Studio, select Connect MCP, then Enable connection.
  2. Add https://sdds-webmcp-bridge.jdiazdecaro.workers.dev/mcp to your client. Set its Authorization header to the complete copied value, including Bearer , or use Copy MCP config if the client accepts that format.
  3. Keep the tab open. Ask the agent to read the current study specification before editing; mutations require its latest revision.
  4. Select Disconnect to revoke access. Closing or reloading the page also ends the session. Keys expire after two hours; reconnect for a new key.

The remote bridge is published in the official MCP Registry as io.github.Black-Swan-Causal-Labs/sdds-webmcp. Its metadata is in server.json; see the bridge README for detailed connection, session, development, and deployment instructions.

A website URL alone does not enable arbitrary agents to use WebMCP. Native access needs browser and agent support; remote access needs pairing and custom-header support. The bridge currently does not implement OAuth discovery.

Pairing is optional and sends study tool arguments and results through the Cloudflare relay to the connected agent provider. Anyone with the temporary key can invoke that canvas's tools while connected. Loading the page does not create a relay session, and native WebMCP works without this relay; the browser agent's own data handling still applies.

Local development

Requires Node.js 22.13 or later and npm. Node.js 24 was used for the initial deployment.

npm ci
npm run dev

Create and preview a production build:

npm run build
npm run preview

The app uses React, TypeScript, Vite, Tailwind CSS, Zod, jsPDF, and PptxGenJS. The studio is a static application. Its optional remote MCP bridge runs separately on Cloudflare Workers and Durable Objects; ordinary manual editing and native WebMCP do not require a paired relay session.

Cloudflare deployment

The existing Cloudflare Pages project is sdds, with production branch main and build output dist.

SettingValue
Custom domainsdds.blackswancausallabs.com
Pages hostnamesdds-1wj.pages.dev
Wrangler configurationwrangler.json
DNS recordCNAME sddssdds-1wj.pages.dev

From a checkout with access to the Cloudflare account:

npm ci
npx wrangler login
npm run build
npx wrangler pages deploy dist --project-name sdds --branch main

Wrangler opens authentication in your default browser. The Pages project and custom domain are already configured; normal redeployments do not require recreating them. For a new environment, create a separate Pages project and add its custom domain through Cloudflare's Pages dashboard.

Deployment is currently manual through Wrangler. Pushing to this GitHub repository does not automatically deploy to Cloudflare. Never commit Cloudflare tokens, .env files, .dev.vars files, or local Wrangler state.

WebMCP tool reference

The app detects document.modelContext, with a fallback to navigator.modelContext. Manual editing remains available in browsers without WebMCP support. Tools operate on the current page's in-memory study, and mutations require expected_revision to protect against stale edits.

ToolPurpose
get_study_specRead the current specification and revision
update_design_elementUpdate a window
add_design_elementAdd a window
remove_design_elementRemove a window
reorder_design_elementsReorder timeline rows
update_study_detailsUpdate study-level metadata
import_study_specReplace the current specification
clear_study_specStart a blank design
validate_study_specRead completeness checks and review items
export_schematicReturn SVG without triggering a download

Unknown dates are represented by null; unresolved text stays blank. Source notes should distinguish documented evidence from researcher-defined choices.

Source layout

  • components/study/: editor, timeline, and information panels
  • components/ui/: reusable interface components
  • lib/study/: schema, validation, timeline layout, export, and WebMCP tools
  • app/globals.css: application styling
  • public/: PDF font and its license
  • vendor/: vendored stylesheet and its license

Licensing and contact

The original canvas application, native WebMCP integration, and remote MCP bridge are licensed under the Apache License 2.0. Copyright 2026 Black Swan Causal Labs, LLC. See NOTICE.

Third-party components retain their own licenses; see THIRD_PARTY_NOTICES.txt, public/DejaVu-font-license.txt, and vendor/shadcn-tailwind-4.13.0.LICENSE.md. The software license does not change rights in user-provided study content or third-party reference material, or grant trademark rights. License and notice files are also distributed with the deployed app.

Black Swan Causal Labs: https://blackswancausallabs.com · info@blackswancausallabs.com

Reviews

No reviews yet

Be the first to review this server!