# io.github.cueqzapper/picorn

Picorn turns AI briefs into editable social images and videos with layers, timelines, and renders.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 2.2.0
- **Author:** io.github.cueqzapper
- **License:** Unknown
- **Endpoints:** streamable-http https://picorn.com/mcp
- **Source:** https://picorn.com/mcp
- **Endpoint health:** reachable (last checked 2026-09-25T12:15:21.825Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 10 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-25T12:15:21.825Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

32 declared. Observed from a live `tools/list` probe.
- `picorn_capabilities` — List live canvas formats, fonts, layouts, image models, GPU reachability and fair-use limits.
- `picorn_projects_create` — Create a marketing project that can hold many editor files and imported image assets. Keep the returned workspaceProjectId and workspaceProjectKey together; use
- `picorn_projects_inspect` — List every editor file, imported asset, and the project brand profile with named colors and saved logos or visual references. File entries include their current
- `picorn_projects_update` — Update the name, description, or named color scheme of a marketing project, then return its complete file, asset, and brand index.
- `picorn_design_image` — CODEX-ONLY. The calling Codex supplies the complete SVG, including copy and layout. Picorn resolves declared placeholders and renders it through Fabric/SVG. No 
- `picorn_generate_image` — Generate a raw image with self-hosted Z-Image Turbo. Returns an inline preview and public creationUrl.
- `picorn_generate_vector_assets` — Use Picorn's native editor engine: first generate raster artwork with self-hosted Z-Image Turbo on ComfyUI, remove its background, then convert it through the b
- `picorn_edit_image` — Transform an existing image with Flux 2 Klein. Returns an inline preview and public creationUrl.
- `picorn_render_svg` — Render your SVG through Picorn with real typography and declarative image workers. Put placeholder <rect> elements inside the SVG and choose their backend with 
- `picorn_editor_import_image` — Import image bytes from any external or agent-native image generator into Picorn storage. Pass imageBase64 with or without a data: prefix, then use the returned
- `picorn_editor_create_project` — Create a persistent native Picorn editor project. For a finished static layout, pass svg: a complete SVG containing text/shapes plus declarative data-clipart pl
- `picorn_editor_create_slideshow` — Create, persist and render a complete 1–20 slide Picorn file in one deterministic call from finished agent-authored SVG and/or native editable layers. The calli
- `picorn_editor_inspect_project` — Read the complete project, including every slide, layer, property, z-index, and latest rendered image URL.
- `picorn_video_create_project` — Create a persistent video project with a real 30fps timeline, native layers, keyframes and a canonical /video/editor link.
- `picorn_video_import_media` — Upload agent-owned MP4, WebM, MOV, MP3, WAV, AAC, M4A or OGG bytes into Picorn storage for use by video/audio timeline layers. Maximum 15 MB.
- `picorn_editor_add_slide` — Add another slide to an editor project. Projects support up to 20 slides. Returns the new slide as an inline preview.
- `picorn_editor_update_slide` — Change a slide background, semantic role, or image prompt. Returns the changed slide as an inline preview.
- `picorn_editor_delete_slide` — Delete a slide and its layers. A project always keeps at least one slide.
- `picorn_editor_add_layer` — Add a native editor layer. Supported types: text, image, shape, group, qr, video, audio. SVG uses an image layer with isSvg:true. Position is the layer CENTER i
- `picorn_editor_update_layer` — Patch any editable property on a layer: content, position, size, transform, style, filters, masks, effects, blend mode, visibility, lock state, SVG overrides, t
- `picorn_video_add_clip` — Add a video or audio clip to a Picorn timeline. Source URLs must use an approved public media host. Video positions are center coordinates; timing and trim valu
- `picorn_editor_delete_layers` — Delete one or more layers and clean their group references.
- `picorn_editor_reorder_layers` — Set layer order. objectIds are bottom-to-top; omitted existing IDs retain their relative order on top.
- `picorn_editor_group_layers` — Create the same metadata group used by the visual editor. Grouping preserves world positions and render output.
- `picorn_editor_ungroup_layers` — Remove a group while preserving all child layers.
- `picorn_editor_align_layers` — Align positioned layers to their shared left, center, right, top, middle, or bottom bound.
- `picorn_editor_distribute_layers` — Evenly distribute three or more positioned layers horizontally or vertically.
- `picorn_editor_duplicate_layer` — Duplicate a non-group layer, including all style, filter, effect, mask, and animation properties.
- `picorn_editor_render_project` — Render selected or all slides through Picorn's real Fabric editor pipeline. Returns persistent public image URLs, a multi-page PDF, or a page-faithful DOCX down
- `picorn_video_render_project` — Render the native timeline to a finished MP4/H.264 or WebM/VP9 file. The render includes multi-slide sequencing, timed layers, video frames, keyframe animation 
- `picorn_search_icons` — Search Picorn's vector icon library before composing a design.
- `picorn_search_areas` — Find approved torn, wavy, blob, banner and other decorative shapes for a design.

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"picorn\": {\n      \"type\": \"http\",\n      \"url\": \"https://picorn.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive blast radius — deletes data; runs on someone else's infrastructure.
- Floor 34, ceiling 58 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.cueqzapper%2Fpicorn
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.cueqzapper%2Fpicorn/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.cueqzapper%2Fpicorn
- HTML page: https://forgeregistry.com/registry/io.github.cueqzapper%2Fpicorn
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
