io.github.pixelvault-dev/pixelvault

MCPcomunidaden línea
v0.3.0io.github.pixelvault-devUnknownActualizado hace 2 m

Agent-first image hosting — upload images and get instant CDN URLs.

Estado del endpointen línea
comprobado hace 8 días · 202 ms · 2 endpoints · requiere autenticación
100 % de las últimas 5 comprobaciones llegaron a este endpoint
Funciona en
ClaudeCursorCopilotChatGPTGemini

Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Indexado automáticamente desde fuentes públicas. Aún sin verificar por su desarrollador en Forge.Reclamar este listado →
hace 2 mÚltima actualización
Paquete
Autorio.github.pixelvault-dev
LicenciaUnknown
Versión0.3.0
Fuentemcp-registry
Estado de confianza
D
30/100Riesgo
✓Listado en el índice de Forge+10/10
—Identidad del publicador verificada+0/30
→ Publicador: este listado no tiene ningún repositorio registrado, así que `forge publish` no puede verificar la propiedad de forma automática. Usa «Reclamar este listado» arriba — en Forge lo revisamos a mano.
—Verificación de dominio+0/10
→ Ahora mismo no está disponible para este tipo de listado: hoy la comprobación de dominio solo se ejecuta para paquetes publicados en npm, así que esta fila todavía no se puede conseguir aquí, sea lo que sea lo que haya alojado en el dominio.
—Análisis de inyección de prompts · con hallazgos+0/30
→ Publicador: elimina del código las instrucciones dirigidas a clientes de IA en lugar de a lectores humanos
✓Análisis de ofuscación / exfiltración · limpio+20/20
EstadoIndexado por la comunidad
PublicadorSin verificar
FirmaSin firmar
Dominio—
Procedencia—
DependenciasSin auditar
Superficie de herramientas8 herramientas · 3 privilegiadas
Análisis de seguridad⚠ Avisos (1)vlive · hace 26 d¿Qué tan bien funciona este análisis?
PROMPTtool:get_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:list_imagesLinks to undeclared domain: pixelvault.dev
PROMPTtool:upload_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:upload_batchLinks to undeclared domain: pixelvault.dev
PROMPTtool:transform_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:rescue_imgurExfiltration-shaped instruction
EvaluacionesNinguna
Indexado20 jun 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

8 herramientas · 3 privilegiadas · 1 marcadas por inyección
Observado en vivo desde el endpoint del proveedor26d ago

Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.

  • https://mcp.pixelvault.dev/mcp8 herramientas · 259 ms
  • https://mcp.pixelvault.dev/mcp/oauthrequiere autenticación
get_imageGet metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…

Get metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…

NOTALinks to undeclared domain: pixelvault.dev
ParámetroTipoDescripción
id*stringImage id to fetch, e.g. img_abc123
list_imagesList images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…

List images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…

NOTALinks to undeclared domain: pixelvault.dev
ParámetroTipoDescripción
pageintegerPage number (default 1)
per_pageintegerItems per page (default 20, max 100)
delete_imageprivilegiadaPermanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.

Permanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.

ParámetroTipoDescripción
id*stringImage id to delete, e.g. img_abc123
upload_imageprivilegiadaUpload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…

Upload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…

NOTALinks to undeclared domain: pixelvault.dev
ParámetroTipoDescripción
source_urlstringPublic http(s) URL of an image to fetch and upload. Provide this OR data.
datastringBase64-encoded image bytes (data URLs accepted). Provide this OR source_url.
folderstringOptional folder/path prefix for the image.
filenamestringOptional original filename, e.g. photo.png.
expires_inintegerOptional time-to-live in seconds. The image is auto-deleted after this many seconds (must be 60–2,592,000, i.e. 1 minute to 30 days). Omit for a permanent imag…
upload_batchprivilegiadaUpload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…

Upload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…

NOTALinks to undeclared domain: pixelvault.dev
ParámetroTipoDescripción
images*array1–50 images to upload into the collection.
typestringCollection type/discriminator (e.g. ci_build, generation). Default 'batch'.
namestringIdempotency key — re-running with the same (type, name) upserts the same collection.
visibilitystring'private' returns a signed URL per image (free plan: up to 100 private images); 'public' returns a plain CDN URL. Default 'public'.
expires_inintegerImage deletion TTL in seconds (60–2,592,000). Omit for permanent.
sign_expires_inintegerSignature lifetime for private URLs in seconds (60–2,592,000, default 7 days).
metadataobjectFreeform collection metadata, e.g. { commit, pr_number, branch }.
sign_urlMint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…

Mint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…

ParámetroTipoDescripción
id*stringImage id to mint a signed URL for, e.g. img_abc123.
expires_inintegerSignature lifetime in seconds (60–2,592,000). Default 3600 (1 hour).
transform_imageBuild an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…

Build an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…

NOTALinks to undeclared domain: pixelvault.dev
ParámetroTipoDescripción
urlstringAbsolute CDN URL of a PixelVault image, as returned by upload_image / get_image / list_images. Provide this OR id.
idstringPixelVault image id (e.g. img_abc123); its CDN URL is resolved via the API. Provide this OR url. Requires an API key when used.
sizestringNamed size preset: s=256px, m=640px, l=1280px, social=1200x630 OG card. Wins over width/height.
widthintegerTarget width in px (1..4000). Snapped UP to the nearest allowed step. scale-down never upscales.
heightintegerTarget height in px (1..4000). Snapped UP to the nearest allowed step.
fitstringResize mode. scale-down (default) never enlarges; contain/cover/crop/pad resize to the exact box and may upscale. Only meaningful alongside width/height.
formatstringOutput format. auto negotiates WebP/AVIF from the client's Accept header.
qualitystringOutput quality. auto lets Cloudflare choose.
segmentstringAI background removal (BiRefNet): foreground keeps the subject and makes the background transparent. Output is forced to PNG unless an opaque background is set…
backgroundstringFill color behind a removed (segment) or padded (fit=pad) background: hex (#ffaa00), rgb()/rgba(), or a common CSS color name. No effect otherwise.
gravitystringCrop anchor, only with fit=cover|crop: face, left, right, top, bottom, auto, or 'XxY' coords 0.0-1.0. face enables zoom.
zoomnumberFace-crop tightness 0.0-1.0, only with gravity=face.
blurnumberGaussian blur (0-250); snapped to the nearest of 10/30/60/120. <=0 is ignored.
sharpennumberSharpen strength (0-10); snapped to the nearest of 1/3/5.
rotatenumberRotate clockwise; rounded to the nearest right angle (90/180/270).
flipstringMirror horizontally (h), vertically (v), or both (hv).
brightnessnumberBrightness multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2.
contrastnumberContrast multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2.
saturationnumberSaturation multiplier 0-2 (1=no change, 0=grayscale); snapped to 0/0.5/1.5/2.
tilestringFilename (optionally folder-prefixed, with extension) of another image in the SAME project to tile edge-to-edge as a watermark, e.g. watermark.png.
rescue_imgurriesgo de inyecciónScan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…

Scan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…

INYECCIÓNExfiltration-shaped instructionot permanent storage. Maps to POST /v1/imgur-scan (server-side page fetch; no API key required). Provide `page_url`…
ParámetroTipoDescripción
page_url*stringPublic https:// URL of a page to scan for hotlinked Imgur images.

8 de 8 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Agent-first image hosting — upload images and get instant CDN URLs.

Palabras clave
mcp
Alternativas
Comparando superficies de herramientas…

Sin cobertura de dependencias

Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.