# @tesserai/cli

Install a tesserai design system into your project as components you own, keep it in sync, and give your coding agent an MCP server that reads it.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.2.2
- **Author:** design.tesserai
- **License:** MIT
- **npm:** @tesserai/cli
- **Source:** https://github.com/tesseraihq/tesserai
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 8 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-28T15:22:59.768Z
- **Version scanned:** 0.2.2
- **CVEs:** none found by OSV at scan time

## Tools

11 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `import_design_system`
- `outline` — A compact outline of the design system: palettes, meanings (intents), surfaces, type, spacing, radius, and every component with its parts and options.
- `guidelines` — Design guidelines on a topic (WCAG, Apple, Material and settled practice, with sources): the rule, why it matters, where it comes from. Read it before answering
- `list_operations` — Every operation apply_changes accepts, by group, with what it does. describe_operation gives one operation's exact input.
- `describe_operation` — One operation's input, as JSON Schema.
- `apply_changes` — Change the design system with operations, applied in order, all or nothing, and checked before anything is written. Then the theme CSS and components are regene
- `scan`
- `upload_scan` — Scan the app and keep the result with its design system in the builder (Pro), where the team sees usage beside the system and how it changes over time. Sends co
- `sync` — Bring the project up to date with its design system: for a project that follows a tesserai link, pull the latest version first (the latest release of a private 
- `component_guide` — How to build with the system's components. Without a component: each one with what it's for and its import. With one: its import, its props and their allowed va
- `example_page`

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"cli\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@tesserai/cli\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: mutates data; runs on your machine.
- Floor 28, ceiling 52 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40tesserai%2Fcli
- Install plan: https://forgeregistry.com/api/v1/packages/%40tesserai%2Fcli/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40tesserai%2Fcli
- HTML page: https://forgeregistry.com/registry/%40tesserai%2Fcli
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
