MCP server that scans web pages for WCAG accessibility issues with axe-core, so AI agents can audit and fix accessibility. By
Pincushion is installed from its publisher's own source and answers where it runs, so this marketplace is not in the path of a single call. There is no address here to send one to, and a panel that pretended otherwise would be showing you an answer we made up. Install it and call it from your own client — the Installation tab has the entry for each one.
Open InstallationWhat it does
Visual feedback as agent work packets. Stakeholders drop pins on your live app; your AI coding agent reads each pin (selector, screenshot, DOM, thread, acceptance criteria) via MCP and ships the fix.
Quickstart
# 1 — run it from where its publisher ships it
npx -y pincushion-mcp
# 2 — ask your agent something
> Visual feedback as agent work packets. Stakeholders drop pins on your live app; your AI coding agent reads each pin (selector, screenshot
Pincushion is free: there is no plan to choose, no cap to set and nothing that can bill you.
Collected from a public index. Nobody has claimed this account, so nothing here was written by its author — claim it if it is yours.
Where are you running it?
Every route below installs the same thing and ends at the same approval screen. This one runs on your machine: your client starts Pincushion as a process under your own user, with your files and your network, so the tool surface below is what it can do to your computer rather than to a server somewhere else. It is scanned, signed and pinned to the version you choose — read the surface before you approve it.
This is a public server: you run it yourself and this marketplace is not in the path. Claude Code registers it in one command.
claude mcp add pincushion-mcp -- npx -y pincushion-mcpReconnect, or start a new session, and the tools appear in the model’s tool list.
One config entry your client uses to start the process locally. A local server runs with your file system and your network, which is why it is priced without metering.
37 tools, with what each one reads, writes and reaches shown before you agree — the same list on every route above. Read the tool surface.
Tool surface
What the model actually sees. Descriptions are diffed on every release — see version history.
Retrieve annotation pins from the .feedback/ directory. Filter by page URL, LWC component name, or status. Use this to understand what feedback exists before making changes.
Takes no parameters.
Full-text search across all annotation comments, selectors, component names, and tags.
Takes no parameters.
Get a high-level rollup of all open feedback: counts by status, page, and component. Use this to plan what to address first.
Takes no parameters.
Get all feedback pins targeting a specific LWC component, with a plain-language summary ready for implementation. Returns element selectors, comments, and thread history.
Takes no parameters.
Mark an annotation as resolved after addressing the feedback. Optionally add a resolution comment explaining what was changed.
Takes no parameters.
Add a reply to an annotation thread (e.g. to ask a clarifying question or note a finding).
Takes no parameters.
Used by /pincushion-replies. Returns pins where Pincushion AI should respond, with each candidate tagged by trigger reason. Two triggers: (a)
Takes no parameters.
Post a Pincushion AI reply to a pin\
Takes no parameters.
Lists production deployment frame-refresh work independently of the Critique queue. Use this even when autoCritique is false. The result is redacted: it contains no deployment URL/hash, browser state, storage path, or capture proof. Start a selected run before capturing.
Takes no parameters.
Requests server-side frame-refresh completion after all exact page/device receipts have been recorded. The server rejects missing, stale, replayed, cross-deployment, or expired capture-run evidence and never treats a queue state as a current frame.
Takes no parameters.
Mark a critique_queue request as completed after the critic subagent has run on its page URLs. Pass the request id (from get_pending_critiques) and the total pin_count produced. The server scopes the update to your license — you cannot complete another tenant\
Takes no parameters.
Register the exact bounded URL inventory discovered in one local browser context before staging deployment captures. The backend returns accepted pending pages; upload snapshots and record terminal results only for that returned subset, never for a locally guessed URL.
Takes no parameters.
Resolve a pin after applying a code fix. Transitions the pin directly to
Takes no parameters.
Compute median + p25/p75 time-to-fix from resolved pins. Returns sample size + threshold flag so callers can honestly hide the metric when the dataset is too small (< 5 resolved pins). This is the marketing proof point that distinguishes Pincushion from
Takes no parameters.
Record the outcome of Pincushion AI\
Takes no parameters.
Link a deploy URL to a resolved pin. Typically called by the deploy-hook edge function once a deploy that includes the pin\
Takes no parameters.
Get instructions for setting up and connecting the Pincushion browser extension to this MCP server. Includes configuration examples for Cursor, Claude Desktop, Claude Code, VS Code, Windsurf, and other agents.
Takes no parameters.
Finish the quickstart demo loop after editing the demo copy. Confirms the change, returns the bridge to real usage, and cleans up the throwaway .feedback/.quickstart/ files. Does NOT create or resolve any real pin.
Takes no parameters.
Read-only lookup of a project\
Takes no parameters.
Register a Pincushion project and associate it with your app\
Takes no parameters.
Lightweight write-only path for the layered critique-context system. Use this from /setup and /refresh-brand after the dev agent has gathered repo signals (README, theme tokens, sample copy, competitor URLs, recent resolved pins) and compiled them into a critique brief. Unlike
Takes no parameters.
Get all pins waiting for developer attention. Returns three categories: (1)
Takes no parameters.
Claim an actionable pin before starting work on it. Transitions the pin from
Takes no parameters.
Mark a pin as approved for implementation. Only approved pins should be implemented by agents. This transitions the pin from
Takes no parameters.
Assign a pin directly to your local coding agent. Promotes the pin to
Takes no parameters.
Get a single implementation packet for one page URL. Useful when you want to batch-fix one page at a time. Returns the same shape as a single entry in implement_approved_pins.packets — pins, aggregated selectors, suggested branch, traceability config. Matches by exact URL or partial substring.
Takes no parameters.
Get pins that the developer has selected for implementation from the dashboard or PINS.md checkboxes. Returns the selected pin IDs with full context (element, thread, deep link). Use this to know which pins the developer wants you to work on next.
Takes no parameters.
Add a collaborator to a Pincushion project. Developers consume a paid seat and can implement pins. Commenters are free and unlimited. Returns an upgrade prompt if the seat limit is reached.
Takes no parameters.
List all members of a Pincushion project with their roles, plus seat usage info.
Takes no parameters.
Remove a collaborator from a Pincushion project. Frees up the seat if they were an editor.
Takes no parameters.
Turns supplied real captures into a report receipt; it does not inspect a page or generate feedback. By default it mints a Crit and therefore requires the exact Pincushion AI pin IDs the critic just created, each positioned in a supplied capture. Set purpose:
Takes no parameters.
Generate an Add-to-Slack OAuth URL pre-bound to a project. Most users should prefer the public storefront URL (also returned, https://pincushion.io/install/slack) — since May 2026, that auto-links to a Pincushion license when the installer\
Takes no parameters.
List Slack and Microsoft Teams webhook subscriptions for a Pincushion project. Webhook URLs are masked.
Takes no parameters.
LEGACY FALLBACK. Since May 2026, Slack installs auto-link to a Pincushion license when the installer\
Takes no parameters.
Remove a Slack, Microsoft Teams, or Discord webhook subscription from a Pincushion project.
Takes no parameters.
Preview the Slack, Teams, or Discord notification shape and recommended event routing before connecting a real webhook.
Takes no parameters.
Read or update the caller\
Takes no parameters.
- Every tool, no call limit
- No card, no account needed
- Source published under a licence you can read
- Runs on your machine — nothing of it reaches our gateway
- Nothing to cap, because nothing bills
What counts against your monthly calls
| Tool | Unit | Calls used | Out of the allowance |
|---|
Nothing here is billable. Pincushion costs nothing to install and nothing to call, at any volume.
Two independent axes, because powerful and malicious are different questions. The grade is threat only. The capability level is blast radius, and it is never a penalty on the grade — it is priced as one subtract-only term in the score, where you can see it.
| Term | Level | What it prices | Points |
|---|---|---|---|
| capability-exposure | high | capability blast radius (high) — client exposure if the model is manipulated | −6 |
| verification-discount | repo | publisher verification (public source) — no provenance, but the source is public and inspectable | −1 |
| coverage-honesty | source | inspection depth (source) — how much of the target the scan could see | −0 |
What the scan could actually read
A grade is only as meaningful as its coverage, so the scanner publishes its own depth before it publishes its result.
Tools were statically extracted from the published source (66 recovered), not enumerated from a running server. Tool-poisoning, Unicode-smuggling, capability and toxic-flow analysis ran on this inferred surface, but a mis-parsed registration could be missed or mis-attributed, so tool-derived findings are capped below “confirmed”. To grade the real runtime surface, scan the running server: --command "npx -y <package>".
Capability — what it could do if the model were manipulated
Tags derived from each tool’s schema and the implementation, not from what the tool calls itself. high is the level these add up to.
| Tool | Capability tags | Why the tag was assigned |
|---|---|---|
| Verification | no tags | |
| get_annotations | no tags | |
| search_annotations | no tags | |
| get_feedback_summary | no tags | |
| get_component_feedback | no tags | |
| resolve_annotation | no tags | |
| add_agent_reply | no tags | |
| get_reply_candidates | untrusted-input | |
| add_bot_reply | untrusted-input | |
| get_pending_critiques | no tags | |
| get_pending_deployment_frame_refreshes | no tags | |
| start_deployment_capture_run | no tags | |
| complete_deployment_capture_run | no tags | |
| complete_critique_request | no tags | |
| register_deployment_discovered_pages | no tags | |
| record_deployment_page_result | no tags | |
| create_critique_pin | no tags | |
| create_agent_pin | no tags | |
| fix_and_resolve | untrusted-input | |
| get_time_to_fix_metrics | no tags | |
| record_pin_verification | no tags | |
| link_pin_deploy | no tags | |
| get_setup_instructions | no tags | |
| start_quickstart_demo | no tags | |
| resolve_quickstart_demo | no tags | |
| get_project_context | no tags | |
| configure_project | no tags | |
| get_deployment_reconciliation_status | no tags | |
| manage_deployment_automation | external-sink | |
| update_critique_context | no tags | |
| get_actionable_pins | no tags | |
| claim_pin | no tags | |
| approve_pin | no tags | |
| assign_pin_to_agent | no tags | |
| implement_approved_pins | no tags | |
| get_implementation_packet | no tags | |
| get_selected_pins | no tags | |
| add_member | no tags | |
| list_members | no tags | |
| remove_member | no tags | |
| create_invite_link | no tags | |
| create_share_report | no tags | |
| upload_page_snapshot | no tags | |
| generate_critique_report | no tags | |
| configure_collaboration_integration | external-sink | |
| create_slack_install_link | no tags | |
| list_collaboration_integrations | no tags | |
| claim_pending_slack_install | external-sink | |
| remove_collaboration_integration | external-sink | |
| preview_collaboration_notification | external-sink | |
| set_slack_preferences | no tags | |
| pins | no tags | |
| my-pins | no tags | |
| username | no tags | |
| resolve | no tags | |
| pin_id | no tags | |
| feedback-summary | no tags | |
| setup | no tags | |
| urls | no tags | |
| implement | no tags | |
| invite | no tags | |
| emails | no tags | |
| project_id | no tags | |
| report_url | no tags | |
| page_url | no tags | |
| pincushion-quickstart | no tags |
Toxic-flow graph
The lethal trifecta, checked as a graph rather than as a checklist: untrusted input, a sensitive source and an external sink have to meet before there is a path worth worrying about.
Supply chain and provenance
This is the first scan of this surface here, so there is nothing yet to compare it against.
Every result on this tab comes from one deterministic pass over the published package — offline, rule by rule, and auditable line by line above. Same methodology version, same bytes, same score.
Release history
Pinned to 1.11.12 — the install command below asks for that release. A pin is part of an install, so it is kept for this visit and written down when you install.
No release note was published with this version.
Only accounts with at least 50 real tool calls against this server in the last 90 days can post. Ratings are weighted by how much the reviewer actually uses it, and publishers can reply once per review.
Writing one takes an account with at least 50 real tool calls against Pincushion in the last 90 days. That is the whole gate — there is no other way to post, which is why the counts beside each review are worth reading.
Nobody has reviewed this listing. The rating on the card is the mean of the reviews written here and nothing else, so there is no rating until somebody writes the first — which takes an account with 50 real tool calls against it.