export_drill
Generate drill files for a PCB via kicad-cli, exposing the full Excellon/Gerber drill option set (format, drill origin, zero suppression, oval format, units, mirror-Y, minimal header, separate PTH/NPTH files, drill map + map format). Reads the last SAVED state of the .kicad_pcb.
This record as markdown: /tools/mixelpixx-kicad-mcp-server/export-drill.md
What export_drill does on KiCAD-MCP-Server
AI agents invoke export_drill to trigger actions in KiCAD-MCP-Server. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
Why export_drill is rated High
This tool executes an external CLI process (kicad-cli) to generate drill output files. It triggers an external operation and writes output files to disk. The blast radius is medium — it doesn't delete data but does invoke an external program and produce file artifacts whose effects depend on arguments (format, origin, units, etc.).
From the tool's definition Generate drill files for a PCB via kicad-cli... Reads the last SAVED state of the .kicad_pcb
Attacks that exploit this kind of access
The rule that runs export_drill safely
PolicyLayer is an MCP gateway: it sits between your AI agents and KiCAD-MCP-Server, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For export_drill, this is the rule to start with:
export_drill stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect KiCAD-MCP-Server, apply this rule, and every export_drill call is checked against it from then on.
Questions about export_drill
Generate drill files for a PCB via kicad-cli, exposing the full Excellon/Gerber drill option set (format, drill origin, zero suppression, oval format, units, mirror-Y, minimal header, separate PTH/NPTH files, drill map + map format). Reads the last SAVED state of the .kicad_pcb. It is categorised as a Execute tool in the KiCAD-MCP-Server MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
Register the KiCAD-MCP-Server MCP server in PolicyLayer and add a rule for export_drill: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches KiCAD-MCP-Server. Nothing to install.
export_drill is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the export_drill rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for export_drill. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
export_drill is provided by the KiCAD-MCP-Server MCP server (mixelpixx/kicad-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on KiCAD-MCP-Server, and thousands of servers like it.
Across the catalogue