$npx skillfedfor your agent
REPO

A clever SolidWorks COM bridge buried under installation scripts you should never run

on: CaptureGrubEnchant/SolidWorks

This repository is a security incident waiting to happen, and that fact overshadows everything else about it.

The installation instructions for Windows, Linux, and macOS all include commands that pipe remote scripts directly into a shell executor without any verification step. The Windows path runs a PowerShell one-liner fetching from a third-party domain. The Linux instructions embed the same pattern alongside legitimate package manager commands. The macOS section base64-decodes a URL at runtime before piping it to zsh - a classic obfuscation technique that should trigger immediate alarm. None of these domains are the project's own GitHub repository. Any security-conscious engineer should stop reading at those code blocks and close the tab.

Set that aside for a moment and look at what the project is actually attempting, because the underlying architecture problem it is solving is real. SolidWorks exposes a COM API where individual calls like FeatureExtrusion3 take more than 20 parameters. Node.js COM bridges via winax reliably fail past 12. The project's response to this is a complexity analyzer that routes calls: short signatures go direct through winax, long ones get transpiled into a VBA macro that SolidWorks executes natively. That is a legitimate engineering decision, not a hack, and the README is unusually honest about why it exists.

The honesty extends to the project's own status. The tool table marks the vast majority of capabilities - drawing tools, export, analysis, VBA execution, macro recording - as untested, meaning they have only been exercised against mocks. Basic sketch geometry and simple extrusions have been verified against a live instance. Everything else is aspirational. The README says this plainly: "Most tools have not been validated against a live SolidWorks instance."

The architecture itself is coherent. Stdio logging routes through Winston rather than console.* because raw console output corrupts JSON-RPC on stdio - a real MCP integration concern that many early MCP servers get wrong. Feature tree traversal uses FeatureByPositionReverse() and GetTypeName2() rather than SelectByID2 because name-based selection is brittle across SolidWorks versions. These are the kinds of details that come from someone who has actually fought with the SolidWorks COM API.

The known limits section is similarly candid: no CI against live SolidWorks, no prebuilt winax binaries, connection pooling and circuit breakers exist in code but are untested, no real performance numbers. The roadmap is a list of things that do not yet exist.

So: a technically interesting approach to a genuine problem in CAD automation, wrapped in installation instructions that should not be followed under any circumstances.

Technically interesting MCP-to-SolidWorks bridge, but the installation scripts pipe from unverified third-party domains - do not run them.

Install it

Sources & links