io.github.pixelvault-dev/pixelvault

MCPCommunitylive
v0.3.0io.github.pixelvault-devUnknownAktualisiert vor 2 Mon.

Agent-first image hosting — upload images and get instant CDN URLs.

Endpunkt-Statuslive
geprüft vor 8 Tagen · 202 ms · 2 Endpunkte · Authentifizierung erforderlich
100 % der letzten 5 Prüfungen haben diesen Endpunkt erreicht
Läuft in
ClaudeCursorCopilotChatGPTGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Automatisch aus öffentlichen Quellen indexiert. Vom Entwickler auf Forge noch nicht verifiziert.Diesen Eintrag beanspruchen →
vor 2 Mon.Letzte Aktualisierung
Paket
Autorio.github.pixelvault-dev
LizenzUnknown
Version0.3.0
Quellemcp-registry
Trust-Status
D
30/100Risiko
✓Im Forge-Index gelistet+10/10
—Publisher-Identität verifiziert+0/30
→ Publisher: für diesen Eintrag ist kein Repository hinterlegt, daher kann `forge publish` die Inhaberschaft nicht automatisch prüfen. Nutze oben „Diesen Eintrag beanspruchen“ — Forge prüft diese Fälle von Hand.
—Domain-Verifizierung+0/10
→ Für diesen Eintragstyp derzeit nicht verfügbar — die Domain-Prüfung läuft heute nur für npm-gestützte Pakete, diese Zeile lässt sich hier also noch nicht erreichen, unabhängig davon, was auf der Domain liegt.
—Prompt-Injection-Scan · Befunde+0/30
→ Publisher: entferne aus dem Quellcode Anweisungen, die sich an KI-Clients statt an menschliche Leser richten
✓Obfuskations-/Exfiltrations-Scan · sauber+20/20
StatusVon der Community indexiert
PublisherNicht verifiziert
SignaturNicht signiert
Domain—
Herkunft—
AbhängigkeitenNicht auditiert
Tool-Oberfläche8 Tools · 3 privilegiert
Sicherheits-Scan⚠ Warnungen (1)vlive · vor 25 TWie gut funktioniert dieser Scan?
PROMPTtool:get_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:list_imagesLinks to undeclared domain: pixelvault.dev
PROMPTtool:upload_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:upload_batchLinks to undeclared domain: pixelvault.dev
PROMPTtool:transform_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:rescue_imgurExfiltration-shaped instruction
EvaluierungenKeine
Indexiert20. Juni 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

8 Tools · 3 privilegiert · 1 wegen Injektion markiert
Live am Endpunkt des Anbieters beobachtet25d ago

Aus einem echten MCP-Handshake initialize → tools/list gegen den deklarierten Endpunkt gelesen. Es wurde nie ein Tool aufgerufen — tools/list ist der lesende Introspektionsaufruf, den das Protokoll dafür vorsieht. Es spiegelt wider, was der Server in diesem Moment angeboten hat; ein gehosteter Endpunkt ist an keine Version gebunden und kann sich ohne Ankündigung ändern.

  • https://mcp.pixelvault.dev/mcp8 Tools · 259 ms
  • https://mcp.pixelvault.dev/mcp/oauthAuthentifizierung erforderlich
get_imageGet metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…

Get metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…

HINWEISLinks to undeclared domain: pixelvault.dev
ParameterTypBeschreibung
id*stringImage id to fetch, e.g. img_abc123
list_imagesList images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…

List images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…

HINWEISLinks to undeclared domain: pixelvault.dev
ParameterTypBeschreibung
pageintegerPage number (default 1)
per_pageintegerItems per page (default 20, max 100)
delete_imageprivilegiertPermanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.

Permanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.

ParameterTypBeschreibung
id*stringImage id to delete, e.g. img_abc123
upload_imageprivilegiertUpload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…

Upload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…

HINWEISLinks to undeclared domain: pixelvault.dev
ParameterTypBeschreibung
source_urlstringPublic http(s) URL of an image to fetch and upload. Provide this OR data.
datastringBase64-encoded image bytes (data URLs accepted). Provide this OR source_url.
folderstringOptional folder/path prefix for the image.
filenamestringOptional original filename, e.g. photo.png.
expires_inintegerOptional time-to-live in seconds. The image is auto-deleted after this many seconds (must be 60–2,592,000, i.e. 1 minute to 30 days). Omit for a permanent imag…
upload_batchprivilegiertUpload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…

Upload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…

HINWEISLinks to undeclared domain: pixelvault.dev
ParameterTypBeschreibung
images*array1–50 images to upload into the collection.
typestringCollection type/discriminator (e.g. ci_build, generation). Default 'batch'.
namestringIdempotency key — re-running with the same (type, name) upserts the same collection.
visibilitystring'private' returns a signed URL per image (free plan: up to 100 private images); 'public' returns a plain CDN URL. Default 'public'.
expires_inintegerImage deletion TTL in seconds (60–2,592,000). Omit for permanent.
sign_expires_inintegerSignature lifetime for private URLs in seconds (60–2,592,000, default 7 days).
metadataobjectFreeform collection metadata, e.g. { commit, pr_number, branch }.
sign_urlMint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…

Mint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…

ParameterTypBeschreibung
id*stringImage id to mint a signed URL for, e.g. img_abc123.
expires_inintegerSignature lifetime in seconds (60–2,592,000). Default 3600 (1 hour).
transform_imageBuild an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…

Build an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…

HINWEISLinks to undeclared domain: pixelvault.dev
ParameterTypBeschreibung
urlstringAbsolute CDN URL of a PixelVault image, as returned by upload_image / get_image / list_images. Provide this OR id.
idstringPixelVault image id (e.g. img_abc123); its CDN URL is resolved via the API. Provide this OR url. Requires an API key when used.
sizestringNamed size preset: s=256px, m=640px, l=1280px, social=1200x630 OG card. Wins over width/height.
widthintegerTarget width in px (1..4000). Snapped UP to the nearest allowed step. scale-down never upscales.
heightintegerTarget height in px (1..4000). Snapped UP to the nearest allowed step.
fitstringResize mode. scale-down (default) never enlarges; contain/cover/crop/pad resize to the exact box and may upscale. Only meaningful alongside width/height.
formatstringOutput format. auto negotiates WebP/AVIF from the client's Accept header.
qualitystringOutput quality. auto lets Cloudflare choose.
segmentstringAI background removal (BiRefNet): foreground keeps the subject and makes the background transparent. Output is forced to PNG unless an opaque background is set…
backgroundstringFill color behind a removed (segment) or padded (fit=pad) background: hex (#ffaa00), rgb()/rgba(), or a common CSS color name. No effect otherwise.
gravitystringCrop anchor, only with fit=cover|crop: face, left, right, top, bottom, auto, or 'XxY' coords 0.0-1.0. face enables zoom.
zoomnumberFace-crop tightness 0.0-1.0, only with gravity=face.
blurnumberGaussian blur (0-250); snapped to the nearest of 10/30/60/120. <=0 is ignored.
sharpennumberSharpen strength (0-10); snapped to the nearest of 1/3/5.
rotatenumberRotate clockwise; rounded to the nearest right angle (90/180/270).
flipstringMirror horizontally (h), vertically (v), or both (hv).
brightnessnumberBrightness multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2.
contrastnumberContrast multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2.
saturationnumberSaturation multiplier 0-2 (1=no change, 0=grayscale); snapped to 0/0.5/1.5/2.
tilestringFilename (optionally folder-prefixed, with extension) of another image in the SAME project to tile edge-to-edge as a watermark, e.g. watermark.png.
rescue_imgurInjektionsrisikoScan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…

Scan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…

INJEKTIONExfiltration-shaped instructionot permanent storage. Maps to POST /v1/imgur-scan (server-side page fetch; no API key required). Provide `page_url`…
ParameterTypBeschreibung
page_url*stringPublic https:// URL of a page to scan for hotlinked Imgur images.

8 von 8 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Agent-first image hosting — upload images and get instant CDN URLs.

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Keine Abdeckung der Abhängigkeiten

Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.