refill_zones
Refill all copper zones on the board. WARNING: SWIG path has known segfault risk (see KNOWN_ISSUES.md). Prefer using IPC backend (KiCAD open) or triggering zone fill via KiCAD UI instead.
This record as markdown: /tools/mixelpixx-kicad-mcp-server/refill-zones.md
What refill_zones does on KiCAD-MCP-Server
AI agents invoke refill_zones to trigger actions in KiCAD-MCP-Server. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
Why refill_zones is rated High
This tool triggers a board-level operation (refilling copper zones) which modifies the PCB design state. It is an Execute-class action as it runs an external operation with side effects on the KiCAD board file. The severity is high because misuse or crashes (noted segfault risk) could corrupt the board design, and the operation affects all copper zones globally across the board.
From the tool's definition 'Refill all copper zones on the board' and 'WARNING: SWIG path has known segfault risk (see KNOWN_ISSUES.md)'
Attacks that exploit this kind of access
The rule that runs refill_zones safely
PolicyLayer is an MCP gateway: it sits between your AI agents and KiCAD-MCP-Server, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For refill_zones, this is the rule to start with:
refill_zones stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect KiCAD-MCP-Server, apply this rule, and every refill_zones call is checked against it from then on.
Questions about refill_zones
Refill all copper zones on the board. WARNING: SWIG path has known segfault risk (see KNOWN_ISSUES.md). Prefer using IPC backend (KiCAD open) or triggering zone fill via KiCAD UI instead. It is categorised as a Execute tool in the KiCAD-MCP-Server MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
Register the KiCAD-MCP-Server MCP server in PolicyLayer and add a rule for refill_zones: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches KiCAD-MCP-Server. Nothing to install.
refill_zones is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the refill_zones rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for refill_zones. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
refill_zones is provided by the KiCAD-MCP-Server MCP server (mixelpixx/kicad-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on KiCAD-MCP-Server, and thousands of servers like it.
Across the catalogue