Atlas / MCP servers / aidc-ai / Pixelle

PixelleBLOCK

mcp/aidc-ai/pixelle

An Open-Source Multimodal AIGC Solution based on ComfyUI + MCP + LLM https://pixelle.ai

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
4 3r · 0w · 1d
Transport
streamable-http
License
MIT
Stars
1,119
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🎨 Pixelle MCP - Omnimodal Agent Framework

English | 中文

✨ An AIGC solution based on the MCP protocol, supporting both local ComfyUI and cloud ComfyUI (RunningHub) modes, seamlessly converting workflows into MCP tools with zero code.

https://github.com/user-attachments/assets/65422cef-96f9-44fe-a82b-6a124674c417

📋 Recent Updates

  • ✅ 2025-09-29: Added RunningHub cloud ComfyUI support, enabling workflow execution without local GPU and ComfyUI environment
  • ✅ 2025-09-03: Architecture refactoring from three services to unified application; added CLI tool support; published to PyPI
  • ✅ 2025-08-12: Integrated the LiteLLM framework, adding multi-model support for Gemini, DeepSeek, Claude, Qwen, and more

🚀 Features

  • ✅ 🔄 Full-modal Support: Supports TISV (Text, Image, Sound/Speech, Video) full-modal conversion and generation
  • ✅ 🚀 Dual Execution Modes: Local ComfyUI self-hosted environment + RunningHub cloud ComfyUI service, users can flexibly choose based on their needs
  • ✅ 🧩 ComfyUI Ecosystem: Built on ComfyUI, inheriting all capabilities from the open ComfyUI ecosystem
  • ✅ 🔧 Zero-code Development: Defines and implements the Workflow-as-MCP Tool solution, enabling zero-code development and dynamic addition of new MCP Tools
  • ✅ 🗄️ MCP Server: Based on the MCP protocol, supporting integration with any MCP client (including but not limited to Cursor, Claude Desktop, etc.)
  • ✅ 🌐 Web Interface: Developed based on the Chainlit framework, inheriting Chainlit's UI controls and supporting integration with more MCP Servers
  • ✅ 📦 One-click Deployment: Supports PyPI installation, CLI commands, Docker and other deployment methods, ready to us
Read from source at commit 124abd9690e5OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add pixelle -- uvx pixelle
claude-desktop
{
  "mcpServers": {
    "pixelle": {
      "command": "uvx",
      "args": [
        "pixelle"
      ]
    }
  }
}
03

Exposed tools (4)

3 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
get_workflow_tool_detailread
list_workflows_toolread
reload_workflows_toolread
remove_workflow_tooldestructive
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (7 observation(s))
Shell
declared (4 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (8)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pixelle/manager/workflow_manager.py:208
exec(func_def, {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
pixelle/utils/dynamic_util.py:23
importlib.import_module(module_name_with_ext)
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
remove_workflow_tool
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
pixelle/middleware/static_cache_middleware.py:183
hash_object = hashlib.md5(content.encode())
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
pixelle/utils/os_util.py:65
f.write(base64.b64decode(base64_str))
INFOInventory / provenance · inv.oversize · CWE-1104
docs/easy-workflow.png
docs/easy-workflow.png
Why it matters. 1237744 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/t2i_by_flux_turbo.png
docs/t2i_by_flux_turbo.png
Why it matters. 2208436 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 124abd9690e5full audit observations/trust-audit/mcp-server/aidc-ai__pixelle.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-25124abd9690e5BLOCKD69first audit
06

Questions

What is the Pixelle MCP server?

An Open-Source Multimodal AIGC Solution based on ComfyUI + MCP + LLM https://pixelle.ai

What tools does Pixelle expose?

4 in total: 3 read-only, 0 that write, and 1 that can delete or overwrite (remove_workflow_tool). Every one is listed on this page with its risk.

Is Pixelle safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Pixelle need?

No credential environment variables were found in its source, so it appears to need none.

How does Pixelle run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as pixelle.

How current is this page?

The grade is for one exact copy of the source (124abd9690e5), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement