image-mcp (standardbeagle/image-mcp) is an MCP server listed on the M8ven Trust Index. It scores 50 out of 100, grade D. It declares 5 tools. No publisher has claimed this listing.
Provides 80+ image processing tools including AI generation, background removal, upscaling, local manipulation, and diagram rendering, all with built-in cost tracking and health monitoring.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
standardbeagle
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
fetch_imageFetch an image from a URL with authentication, security validation, and caching. Features: - Downloads images from HTTP/HTTPS URLs - Supports bearer token and basic authentication - Validates URLs (blocks localhost and private IPs for security) - Enforces size limits (max 10MB by default) - Configu…
fetch_imagesBatch fetch multiple images from URLs with concurrent processing. Features: - Download multiple images in parallel - Configurable concurrency limit - Individual error handling per image - Shared authentication and caching settings - Progress reporting Use cases: - Download image galleries - Batch …
url_to_base64Convert an image URL to base64-encoded data for MCP transport. Features: - Fetches image and encodes to base64 - Returns both base64 string and MIME type - Supports authentication - Uses caching for efficiency Use cases: - Prepare images for inline embedding - Convert URLs for APIs requiring base6…
base64_to_fileSave base64-encoded image data to a file. Features: - Decodes base64 to binary - Validates image format - Writes to specified path - Supports data URI format Use cases: - Save base64 images from APIs - Persist inline images - Convert embedded images to files
get_image_from_urlFetch image from URL and return with comprehensive metadata. Features: - Fetches image with full metadata - Returns data as base64 or buffer - Includes size, MIME type, and cache status - Supports all fetch and cache options Use cases: - Get image with detailed information - Inspect image properti…
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
image-size: JXL and HEIF parsers allow denial of service through infinite loops
image-size: ICNS parser allows denial of service through an infinite loop
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
SVGO removeScripts plugin leaves some executable scripts intact
ADOBE_CLIENT_IDADOBE_CLIENT_SECRETFAL_KEYIDEOGRAM_API_KEYIOPAINT_API_KEYIOPAINT_ENDPOINTMAX_MEMORY_MBMAX_TEMP_FILES_MBOPENAI_API_KEYPHOTOROOM_API_KEYPROVIDER_COST_ALERTSPROVIDER_COST_ALERT_THRESHOLDSPROVIDER_DAILY_COST_LIMITPROVIDER_FALLBACKSPROVIDER_GRACEFUL_DEGRADATIONPROVIDER_HEALTH_CHECK_ENABLEDPROVIDER_HEALTH_CHECK_INTERVALPROVIDER_HEALTH_CHECK_RETRIESPROVIDER_HEALTH_CHECK_TIMEOUTPROVIDER_MONTHLY_COST_LIMITPROVIDER_PER_OPERATION_LIMITREMOVE_BG_API_KEYREPLICATE_API_TOKENSEEDREAM_API_KEYSTABLE_DIFFUSION_ENDPOINTDependencies
20 runtime dependencies (10 dev), 1 flagged: puppeteer
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
5/5 tools missing one or more hints — fetch_image (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); fetch_images (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); url_to_base64 (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +2 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Production dependencies are patched
0 critical, 6 high severity in production deps — @modelcontextprotocol/sdk@1.25.2 (high), image-size@2.0.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
3/20 production deps abandoned (no release in 2+ years): exifr@2022-05-01 (4.3y), gifenc@2022-05-03 (4.3y), svgson@2023-07-17 (3.1y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/standardbeagle/image-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check