io.github.pixelvault-dev/pixelvault

MCPcommunautéen ligne
v0.3.0io.github.pixelvault-devUnknownMis à jour il y a 2 mois

Agent-first image hosting — upload images and get instant CDN URLs.

État de l’endpointen ligne
vérifié il y a 10 h · 57 ms · 2 endpoints · authentification requise
100 % des dernières 6 vérifications ont atteint cet endpoint
Fonctionne dans
ClaudeCursorCopilotChatGPTGemini

Déduit des transports déclarés par cette annonce (streamable-http). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Indexé automatiquement depuis des sources publiques. Pas encore vérifié par son développeur sur Forge.Revendiquer cette annonce →
il y a 2 moisDernière mise à jour
Paquet
Auteurio.github.pixelvault-dev
LicenceUnknown
Version0.3.0
Sourcemcp-registry
Statut de confiance
D
30/100Risque
✓Listé dans l’index Forge+10/10
—Identité de l’éditeur vérifiée+0/30
→ Éditeur : aucune référence de dépôt n’est enregistrée pour cette annonce, `forge publish` ne peut donc pas vérifier la propriété automatiquement. Utilisez « Revendiquer cette annonce » ci-dessus — Forge les examine à la main.
—Vérification de domaine+0/10
→ Actuellement indisponible pour ce type d’annonce — la vérification de domaine ne s’exécute aujourd’hui que pour les paquets adossés à npm, cette ligne ne peut donc pas encore être obtenue ici, quel que soit le contenu hébergé sur le domaine.
—Analyse d’injection de prompt · constats+0/30
→ Éditeur : retirez du code les instructions destinées aux clients d’IA plutôt qu’à des lecteurs humains
✓Analyse d’obfuscation / exfiltration · propre+20/20
StatutIndexé par la communauté
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance—
DépendancesNon audité
Surface d’outils8 outils · 3 privilégiés
Analyse de sécurité⚠ Avertissements (1)vlive · il y a 29 jQuelle est l’efficacité de cette analyse ?
PROMPTtool:get_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:list_imagesLinks to undeclared domain: pixelvault.dev
PROMPTtool:upload_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:upload_batchLinks to undeclared domain: pixelvault.dev
PROMPTtool:transform_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:rescue_imgurExfiltration-shaped instruction
ÉvaluationsAucune
Indexé20 juin 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

8 outils · 3 privilégiés · 1 signalés pour injection
Observé en direct depuis l’endpoint du fournisseur29d ago

Lu depuis un véritable échange MCP initialize → tools/list contre l’endpoint déclaré. Aucun outil n’a été invoqué — tools/list est l’appel d’introspection en lecture seule que le protocole prévoit pour cela. Cela reflète ce que le serveur annonçait à cet instant ; un endpoint hébergé n’est figé sur aucune version et peut changer sans préavis.

  • https://mcp.pixelvault.dev/mcp8 outils · 259 ms
  • https://mcp.pixelvault.dev/mcp/oauthauthentification requise
get_imageGet metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…

Get metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…

NOTELinks to undeclared domain: pixelvault.dev
ParamètreTypeDescription
id*stringImage id to fetch, e.g. img_abc123
list_imagesList images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…

List images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…

NOTELinks to undeclared domain: pixelvault.dev
ParamètreTypeDescription
pageintegerPage number (default 1)
per_pageintegerItems per page (default 20, max 100)
delete_imageprivilégiéPermanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.

Permanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.

ParamètreTypeDescription
id*stringImage id to delete, e.g. img_abc123
upload_imageprivilégiéUpload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…

Upload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…

NOTELinks to undeclared domain: pixelvault.dev
ParamètreTypeDescription
source_urlstringPublic http(s) URL of an image to fetch and upload. Provide this OR data.
datastringBase64-encoded image bytes (data URLs accepted). Provide this OR source_url.
folderstringOptional folder/path prefix for the image.
filenamestringOptional original filename, e.g. photo.png.
expires_inintegerOptional time-to-live in seconds. The image is auto-deleted after this many seconds (must be 60–2,592,000, i.e. 1 minute to 30 days). Omit for a permanent imag…
upload_batchprivilégiéUpload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…

Upload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…

NOTELinks to undeclared domain: pixelvault.dev
ParamètreTypeDescription
images*array1–50 images to upload into the collection.
typestringCollection type/discriminator (e.g. ci_build, generation). Default 'batch'.
namestringIdempotency key — re-running with the same (type, name) upserts the same collection.
visibilitystring'private' returns a signed URL per image (free plan: up to 100 private images); 'public' returns a plain CDN URL. Default 'public'.
expires_inintegerImage deletion TTL in seconds (60–2,592,000). Omit for permanent.
sign_expires_inintegerSignature lifetime for private URLs in seconds (60–2,592,000, default 7 days).
metadataobjectFreeform collection metadata, e.g. { commit, pr_number, branch }.
sign_urlMint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…

Mint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…

ParamètreTypeDescription
id*stringImage id to mint a signed URL for, e.g. img_abc123.
expires_inintegerSignature lifetime in seconds (60–2,592,000). Default 3600 (1 hour).
transform_imageBuild an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…

Build an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…

NOTELinks to undeclared domain: pixelvault.dev
ParamètreTypeDescription
urlstringAbsolute CDN URL of a PixelVault image, as returned by upload_image / get_image / list_images. Provide this OR id.
idstringPixelVault image id (e.g. img_abc123); its CDN URL is resolved via the API. Provide this OR url. Requires an API key when used.
sizestringNamed size preset: s=256px, m=640px, l=1280px, social=1200x630 OG card. Wins over width/height.
widthintegerTarget width in px (1..4000). Snapped UP to the nearest allowed step. scale-down never upscales.
heightintegerTarget height in px (1..4000). Snapped UP to the nearest allowed step.
fitstringResize mode. scale-down (default) never enlarges; contain/cover/crop/pad resize to the exact box and may upscale. Only meaningful alongside width/height.
formatstringOutput format. auto negotiates WebP/AVIF from the client's Accept header.
qualitystringOutput quality. auto lets Cloudflare choose.
segmentstringAI background removal (BiRefNet): foreground keeps the subject and makes the background transparent. Output is forced to PNG unless an opaque background is set…
backgroundstringFill color behind a removed (segment) or padded (fit=pad) background: hex (#ffaa00), rgb()/rgba(), or a common CSS color name. No effect otherwise.
gravitystringCrop anchor, only with fit=cover|crop: face, left, right, top, bottom, auto, or 'XxY' coords 0.0-1.0. face enables zoom.
zoomnumberFace-crop tightness 0.0-1.0, only with gravity=face.
blurnumberGaussian blur (0-250); snapped to the nearest of 10/30/60/120. <=0 is ignored.
sharpennumberSharpen strength (0-10); snapped to the nearest of 1/3/5.
rotatenumberRotate clockwise; rounded to the nearest right angle (90/180/270).
flipstringMirror horizontally (h), vertically (v), or both (hv).
brightnessnumberBrightness multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2.
contrastnumberContrast multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2.
saturationnumberSaturation multiplier 0-2 (1=no change, 0=grayscale); snapped to 0/0.5/1.5/2.
tilestringFilename (optionally folder-prefixed, with extension) of another image in the SAME project to tile edge-to-edge as a watermark, e.g. watermark.png.
rescue_imgurrisque d’injectionScan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…

Scan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…

INJECTIONExfiltration-shaped instructionot permanent storage. Maps to POST /v1/imgur-scan (server-side page fetch; no API key required). Provide `page_url`…
ParamètreTypeDescription
page_url*stringPublic https:// URL of a page to scan for hotlinked Imgur images.

8 outils sur 8 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Agent-first image hosting — upload images and get instant CDN URLs.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Aucune couverture des dépendances

Cette entrée ne publie aucun paquet npm : Forge n'a donc pas d'arbre de dépendances pour elle. C'est une lacune de couverture — pas une affirmation qu'elle n'a aucune dépendance.