Atlas / MCP servers / alisaitteke / Photoshop

PhotoshopBLOCK

mcp/alisaitteke/photoshop

MCP for Adobe Photoshop. 118 tools. Control from Cursor, Claude or custom LLMs.

Verdict
BLOCK
Grade
F
Trust score
58 /100
Exposed tools
172 92r · 69w · 11d
Transport
stdio
License
MIT
Stars
566
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Languages: English · 简体中文 · Español · Deutsch · 日本語 · Türkçe · [Website](https://photoshop-mcp.com/)

[](https://www.npmjs.com/package/@alisaitteke/photoshop-mcp) [](https://github.com/alisaitteke/photoshop-mcp/releases) [](docs/standalone-ui.md#action-plan-beta) [](#new-instant-edits-with-jev) [](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) []() [](https://registry.modelcontextprotocol.io) [](https://mcptoplist.com/server/io.github.alisaitteke%2Fphotoshop-mcp) [](https://photoshop-mcp.com/)

[](https://glama.ai/mcp/servers/alisaitteke/photoshop-mcp)

Chat with Photoshop like a colleague. Describe what you want in plain words — "remove this background", "resize the

Read from source at commit 36c0e79852b8OBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add photoshop-mcp -- npx -y @alisaitteke/[email protected]
03

Exposed tools (172)

92 read · 69 write · 11 destructive. Blast radius: 11 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
angle_degreadOptional gradient angle override in degrees.
assets_dirreadAbsolute path to the directory containing the source asset images (jpeg/png/psd). Subdirectories are not recursed.
auto_groupreadWhen true, group layers by kind (text / image / shape / adjustment) into folders. Default true.
auto_select_subjectwriteRun Select Subject when no selection (true/false, default false)
blend_modereadLayer blend mode after placement: normal (default), multiply, screen, overlay, soft_light.
csv_pathreadAbsolute path to the CSV file (first row = variable names matching the template variables).
directionreadleft | right | top | bottom | all (default all)
end_pctreadGradient end along the fade axis (0-100). Default 100.
feather_pctreadHalf-width of the transition zone around the horizon (0-50). Default 15.
feather_pxdestructiveEdge feather 0-20 before remove (default 0)
formatreadJPEG or PNG. Default JPEG.
horizon_pctreadDocument-height percentage where sky meets landscape (0-100). Default 50.
image_pathreadAbsolute path to the image file to place (sky, background, texture). Required.
intensityreadRetouch strength: low (subtle), medium (default), or high (heavy smoothing).
keep_shadowreadWhen true, records intent for a contact shadow in the recipe response. Shadow layer creation is not yet implemented. Default false.
logo_pathreadAbsolute path to a logo image (transparent PNG recommended).
make_sheetreadtrue to also export a 10×15 cm print sheet with multiple copies. Default false.
max_dimension_pxreadLongest-edge pixel cap. Default 2048. Common values: 1080, 1600, 2048, 2560.
naming_schemewriteHow to rename layers. One of: type_index (default, e.g. text_01), content_summary (text layers get a slug of their content), preserve (do not rename, only group).
opacityreadWatermark opacity 0-100. Default 40.
output_dirreadDirectory where generated files are written.
photoshop-previewreadInteractive preview of the active Photoshop document.
photoshop_adjust_brightness_contrastwriteApply Image > Adjustments > Brightness/Contrast once to the active layer. Values are deltas on pixels, not an adjustment layer.\n\n
photoshop_adjust_curveswriteCreate a Curves adjustment layer on the active document.\n\n
photoshop_adjust_exposurewriteCreate an Exposure adjustment layer (stops, offset, gamma correction).\n\n
photoshop_adjust_hue_saturationreadShift hue, saturation, and lightness on the active layer via Image > Adjustments > Hue/Saturation. Values are applied once to pixels, not stored as an adjustment layer.\n\n
photoshop_adjust_vibrancewriteCreate a Vibrance adjustment layer. Vibrance boosts muted colors while protecting skin tones.\n\n
photoshop_apply_gaussian_blurwriteApply Gaussian Blur filter to the active layer
photoshop_apply_gradient_mapwriteCreate a Gradient Map adjustment layer (black→white by default) for duotone/B&W tonal remapping.\n\n
photoshop_apply_gradient_maskwriteApply a linear black-to-white gradient on the active layer mask channel (fade/blend).\n\n
photoshop_apply_high_passwriteApply the High Pass filter to the active raster layer — edge/detail extraction for sharpening workflows or frequency separation prep.\n\n
photoshop_apply_layer_maskdestructiveBake the active layer mask into its pixels and remove the mask. Pixels the mask hid are deleted.\n\n
photoshop_apply_layer_styledestructiveApply a layer style (drop shadow, outer glow, stroke, bevel & emboss) to the active layer via Action Manager layer effects.\n\n
photoshop_apply_lutwriteApply a Color Lookup (3D LUT) adjustment layer for cinematic color grading. Accepts a built-in LUT name (e.g.
photoshop_apply_motion_blurwriteApply Motion Blur to the active raster layer (angle in degrees, distance in pixels).\n\n
photoshop_apply_noisewriteApply Add Noise to the active raster layer (amount percent, UNIFORM or GAUSSIAN, optional monochromatic).\n\n
photoshop_apply_photo_filterwriteCreate a Photo Filter adjustment layer (warming/cooling/custom tint with density control).\n\n
photoshop_apply_sharpenwriteApply Unsharp Mask to the active raster layer (amount, radius, threshold). This is a pixel filter on one layer, not a web-export sharpen pass.\n\n
photoshop_apply_smart_blurwriteApply the Smart Blur filter to the active raster layer — edge-preserving blur for smoothing skin or simplifying backgrounds.\n\n
photoshop_auto_contrastwriteRun Auto Contrast on the active layer. Photoshop picks the contrast; there is no amount parameter.\n\n
photoshop_auto_levelswriteRun Auto Levels on the active layer. Photoshop sets the black, white, and gray points; there is no amount parameter.\n\n
photoshop_close_documentreadClose a Photoshop document tab. Defaults to the active document; pass document_id to close a specific open file.\n\n
photoshop_content_aware_fillreadFill the current pixel selection using Content-Aware Fill.\n\n
photoshop_contract_selectionreadContract (shrink) the active pixel selection inward by a pixel amount.\n\n
photoshop_convert_to_smart_objectreadConvert the active layer (or a named layer) to an embedded Smart Object.\n\n
photoshop_create_artboardwriteCreate a Photoshop artboard (AM artboardSection) at an explicit origin or placed to the right of existing artboards.\n\n
photoshop_create_clipping_maskwriteCreate a clipping mask on the active layer (or a named layer).\n\n
photoshop_create_documentwriteCreate a new empty Photoshop document with specified dimensions and color mode.\n\n
photoshop_create_layerwriteCreate a new empty layer above the active layer.\n\n
photoshop_create_layer_maskwriteCreate a layer mask on the active layer from the current selection (reveal selection).\n\n
photoshop_create_smart_object_via_copywriteCreate an independent Smart Object via Copy — unlinked duplicate with its own embedded contents.\n\n
photoshop_create_text_layerwriteCreate a text layer with content, position, font, and optional typography (tracking, leading, paragraph box, alignment, color).\n\n
photoshop_crop_documentreadCrop the active document to a pixel rectangle (left, top, right, bottom). Pixels outside that rectangle are deleted and the canvas shrinks.\n\n
photoshop_delete_layerdestructiveDelete the active layer, including its pixels, mask, and effects.\n\n
photoshop_delete_layer_maskdestructiveDelete the layer mask from active layer
photoshop_desaturatereadDesaturate the active layer (convert to grayscale)
photoshop_deselectdestructiveClear the current pixel selection. Pixels are unchanged.\n\n
photoshop_duplicate_layerreadDuplicate the active layer. The duplicate becomes the active layer;
photoshop_edit_smart_object_contentswriteOpen a Smart Object for editing (double-click / Edit Contents). The embedded .psb becomes the active document until you save and close it.\n\n
photoshop_execute_scriptwriteExecute custom ExtendScript (JSX) code inside Photoshop (advanced escape hatch).\n\n
photoshop_expand_selectionreadExpand the active pixel selection outward by a pixel amount.\n\n
photoshop_export_artboardsreadExport every artboard in the active document to a folder (duplicate + crop to artboardRect, then PNG/JPEG/WebP/AVIF).\n\n
photoshop_export_asreadExport a copy of the active document as PNG, JPEG, WebP or AVIF without changing the open document. WebP/AVIF require Photoshop 23.2+/recent builds and return a clear error when unsupported.\n\n
photoshop_feather_selectionreadFeather (soften) the edges of the active pixel selection.\n\n
photoshop_fill_gradientreadPaint a two-color linear gradient on the active layer pixels.\n\n
photoshop_fill_layerreadFill the active layer with a solid RGB color. If a selection exists, only that region is filled and the selection stays; otherwise the whole layer is filled and the selection is cleared.\n\n
photoshop_fit_layer_to_documentreadScale the active layer to the document canvas, keeping aspect ratio.
photoshop_flatten_imagereadFlatten the active document into a single Background layer. Hidden layers are discarded.\n\n
photoshop_generate_from_datasetswriteBatch-export the active document once per data set: applies each data set, saves a copy, moves on.
photoshop_generate_imagewritePhotoshop Generate Image (Firefly ImageGen): create an image from a text prompt.\n\n
photoshop_generative_expandreadExtend the canvas beyond its edges using Generative Expand (Firefly).\n\n
photoshop_generative_fillreadFill the current selection using Adobe Generative Fill (Firefly) with a text prompt.\n\n
photoshop_generative_removedestructiveRemove content using the AI Remove tool (or generative fill fallback) on the current selection.\n\n
photoshop_generative_upscalereadUpscale the active document using Generative Upscale (PS 27+).\n\n
photoshop_get_capabilitiesreadReturn version-aware feature flags for the installed Photoshop (Select Subject v2, Generative Fill, etc.).\n\n
photoshop_get_document_inforeadRead the active document id, name, size, resolution, and color mode. Does not change pixels or which tab is active.\n\n
photoshop_get_historyreadRead the history stack of the active document, including which state is current. Does not change pixels.\n\n
photoshop_get_layersreadList all layers in the active document with kind, visibility, and opacity.\n\n
photoshop_get_previewreadExport the active document as a base64 JPEG preview for visual verification.\n\n
photoshop_get_selection_boundsreadRead the active pixel selection bounds in document pixels (read-only).\n\n
photoshop_get_statereadReturn a cheap read-only snapshot of Photoshop session state (active document, layer, selection).\n\n
photoshop_get_versionreadReturn the detected Photoshop version string.\n\n
photoshop_image_stackwriteLoad 2+ image files into one document, convert to a smart object and apply a stack mode (mean/median/max/min/...). Classic
photoshop_import_datasetswriteImport a Photoshop variables/data-sets XML file into the active document (the same file Image > Variables > Data Sets > Import accepts).\n\n
photoshop_install_fontwriteInstall a font file for the current user and reload Photoshop\
photoshop_invertreadInvert colors of the active layer
photoshop_invert_selectionreadInvert the current pixel selection: selected pixels become unselected and the rest become selected. Layer pixels are unchanged.\n\n
photoshop_list_artboardsreadList artboards in the active document with id, name, pixel bounds, and which one contains the active layer.\n\n
photoshop_list_datasetsreadList the data sets defined on the active document (Image > Variables > Data Sets).\n\n
photoshop_list_documentsreadList every open Photoshop document with id, dimensions, saved flag, artboard_count, and which tab is active.\n\n
photoshop_list_fontsreadList installed fonts available to Photoshop.\n\n
photoshop_merge_visible_layerswriteMerge every visible layer into one layer. Hidden layers stay in the stack.\n\n
photoshop_move_layerwriteMove the active layer by specified offset
photoshop_move_layer_downwriteMove the active layer down one position in the layer stack
photoshop_move_layer_to_bottomwriteMove the active layer to the bottom of the layer stack
photoshop_move_layer_to_positionwriteReorder the active layer relative to a named layer.
photoshop_move_layer_to_topwriteMove the active layer to the top of the layer stack
photoshop_move_layer_upwriteMove the active layer up one position in the layer stack
photoshop_neural_filterwriteApply a Photoshop Neural Filter via the companion UXP bridge plugin.\n\n
photoshop_open_imagereadOpen an image file as a new Photoshop document.\n\n
photoshop_pingwriteVerify that the Photoshop scripting engine can run a script.\n\n
photoshop_place_imagereadPlace an external image file as a new layer in the active document.\n\n
photoshop_play_actionwritePlay a named action from a named action set in the Actions panel. The action runs whatever steps were recorded; this tool does not limit them.\n\n
photoshop_rasterize_layerreadRasterize the active layer (convert text/smart object to normal layer)
photoshop_redoreadRedo the previously undone operation(s), equivalent to Ctrl/Cmd+Shift+Z.\n\n
photoshop_release_clipping_maskdestructiveRelease (remove) the clipping mask from the active layer (or a named layer).\n\n
photoshop_rename_layerwriteRename the active layer. Does not change pixels, order, or visibility.\n\n
photoshop_replace_smart_object_contentsreadReplace the embedded contents of a Smart Object layer from an image file. Preserves transforms, warps, and Smart Filters on the layer.\n\n
photoshop_resize_imagereadResample the active document to a new pixel width and height (bicubic). Every layer scales and the canvas size changes.\n\n
photoshop_rotate_layerreadRotate the active layer by
photoshop_save_documentwriteSave the active document to disk in PSD, JPEG, or PNG format.\n\n
photoshop_save_selectionwriteSave the active pixel selection to a new alpha channel.\n\n
photoshop_scale_layerreadScale the active layer by a percentage (100 leaves the size unchanged).
photoshop_select_allreadSelect every pixel of the active document. Does not change layer pixels.\n\n
photoshop_select_ellipsewriteCreate an elliptical pixel selection from a bounding box (anti-aliased).\n\n
photoshop_select_layer_by_namereadSelect the active layer by exact name, including layers inside groups.\n\n
photoshop_select_rectanglewriteCreate a rectangular pixel selection from corner coordinates.\n\n
photoshop_select_subjectwriteRun Select Subject on the active layer (creates a pixel selection only, no mask).\n\n
photoshop_set_active_artboardwriteSelect an artboard layer group by artboard_id (preferred) or unique name so subsequent edits and Select All target that board.\n\n
photoshop_set_active_documentwriteSwitch the active document tab by document_id (preferred), zero-based index, or name.\n\n
photoshop_set_layer_blend_modewriteSet the blend mode of the active layer.\n\n
photoshop_set_layer_lockedwriteSet the all-lock flag on the active layer.
photoshop_set_layer_opacitywriteSet the active layer opacity to an absolute 0–100 value. The number replaces the current opacity; it is not added to it.\n\n
photoshop_set_layer_visibilitywriteShow or hide the active layer
photoshop_set_text_alignmentwriteSet justification on the whole active text layer (LEFT through FULLYJUSTIFIED).\n\n
photoshop_set_text_colorwriteSet one RGB color on the whole active text layer.\n\n
photoshop_set_text_fontwriteSet font family and size for active text layer.\n\n
photoshop_set_text_rangeswriteApply mixed fonts, sizes, and colors inside a single text layer (Action Manager textStyleRange).\n\n
photoshop_set_text_stylewriteSet layer-wide typography on the active text layer: tracking, leading, point vs paragraph box, alignment, font, size, color.\n\n
photoshop_sky_replacementreadReplace the sky using Photoshop native Sky Replacement when available.\n\n
photoshop_submit_feedbackwriteRecord the user
photoshop_undoreadStep the active document back through history (Ctrl/Cmd+Z). Each call moves the active history state earlier by
photoshop_update_text_contentwriteReplace the string contents of the active text layer. Font, color, and alignment stay as they are.\n\n
platformsreadComma-separated platform slugs. Known: instagram_post, instagram_story, instagram_reel, x_post, x_header, facebook_post, facebook_cover, linkedin_post, linkedin_banner, youtube_thumbnail, tiktok_vertical, pinterest_pin. Default: instagram_post,instagram_story,x_post.
positionreadOne of: ${POSITIONS.join(
presetreadPreset name. One of: cinematic, vintage, teal_orange, bw, warm_film, cool_dusk. Default: cinematic.
promptreadHow to extend the image (default: extend the background naturally)
ps.apply_color_gradewriteApply a named color grading preset (curves + hue/saturation + selective color) as a single non-destructive recipe. Users often say: cinematic, teal orange, moody grade, color grade.
ps.batch_mockup_replacereadIterate a directory of asset images, swap each one into the named Smart Object in the active mockup PSD, and export a flattened JPEG per asset.
ps.batch_watermarkwriteApply a text or logo watermark to every image in a folder and export watermarked JPEGs. Users often say: watermark these photos, add my logo to all, toplu filigran.
ps.color_correctreadFix flat or dull tonality with auto levels or brightness/contrast — stepping stone until curves atomics ship.
ps.composite_blendwritePlace an external image into the active document, mask it, and set blend mode — interim workflow for sky replacement and compositing.
ps.csv_to_cardsreadGenerate one image per CSV row from the active template PSD (data-driven graphics /
ps.dodge_burnreadOne-shot dodge & burn setup: 50% gray layer in Overlay or Soft Light for non-destructive light sculpting. Users often say: dodge and burn, sculpt light, lighten face, darken shadows. User paints white (dodge) and black (burn) manually after setup.
ps.dodge_burn_guidewriteSet up a non-destructive dodge & burn layer (50% gray + Overlay or Soft Light) for manual light sculpting.
ps.enhance_portraitreadMulti-step retouch plan for a portrait: non-destructive skin smoothing via frequency separation, mild dodge & burn, and auto-tone — wrapped in a single undoable history step. Users often say: smooth skin, retouch portrait, fix blemishes.
ps.export_social_variantsreadGenerate one JPEG per social-media platform from the active document, each at the platform
ps.frequency_separationwriteSet up a frequency separation stack on the active layer (Low Frequency + High Frequency layers) so the user can smooth tones and retouch texture independently — without applying any actual smoothing. Users often say: frequency separation, split texture and color.
ps.generative_expandreadGenerative Expand beyond canvas edges. Users often say: extend canvas, outpainting, expand background, generative expand.
ps.generative_fillreadGenerative Fill inside the current selection with a text prompt. Users often say: add object, replace selection, generative fill, firefly fill.
ps.generative_removedestructiveAI Remove tool on the current selection. Users often say: remove person, erase distraction, generative remove, delete object.
ps.gradient_blendreadFade the active layer into the background using a linear gradient on the layer mask — common for soft compositing and horizon blends.
ps.gradient_fadereadOne-shot gradient fade on the active layer mask — soft edge blending into the background. Users often say: fade into background, gradient mask, blend subject, soft edge fade, arka planı yumuşat. Applies a linear gradient on the layer mask, not a Gradient Fill layer.
ps.organize_layerswriteClean up a messy PSD: rename layers using a consistent scheme and optionally auto-group them by kind or spatial proximity. Users often say: organize layers, rename mess, tidy layers.
ps.passport_photoreadTurn the active portrait into a passport/ID photo: white background, ICAO-style framing, exact official pixel size at 300 DPI, optional 10×15 cm print sheet. Users often say: passport photo, visa photo, ID photo, vesikalık, biyometrik.
ps.prepare_for_webreadConvert the active document to sRGB, downscale its longest edge, sharpen for screen, and export at the chosen format and quality. Does not mutate the source document. Users often say: for web, web export, optimize for web.
ps.remove_backgrounddestructiveRemove the background from the active document in one recipe call. The recipe unlocks a Background layer itself and prefers Photoshop\
ps.remove_distractiondestructiveOne-shot distraction removal: generative AI remove when available, else content-aware fill. Users often say: remove that person, erase distraction, content aware remove, clone out object.
ps.sky_blendreadPlace an external sky image and blend it at the horizon with a gradient mask — one undo. Users often say: replace sky, fix blown sky, better clouds, swap sky background. Photoshop Sky Replacement menu is not scriptable via ExtendScript.
ps.split_carouselreadSplit the active wide document into N equal vertical slices exported as sequentially numbered files for a seamless Instagram/TikTok carousel. Users often say: carousel, seamless carousel, swipe, split panorama, slayt.
qualityreadJPEG quality 1-12 (Photoshop scale). Default 9. Ignored for png.
radius_pxreadGaussian blur radius in pixels used for the low-frequency layer. 4-8 for portraits, 10-20 for products. Default 6.
sizereadOptional final slide size as WxH (e.g. 1080x1350 for Instagram portrait). Omit to keep native slice dimensions.
skin_smoothingwriteWhether to apply frequency separation skin smoothing. Default true.
sky_image_pathreadAbsolute path to the sky image file (JPEG, PNG, etc.). Required.
slidesreadNumber of slides to split into (2-10).
smart_object_layer_namereadExact name of the Smart Object layer inside the active document whose contents will be replaced for each asset.
specreadTarget size: us_2x2 (US 2×2 in), eu_35x45 (EU/Schengen 35×45 mm), tr_50x60 (Türkiye 50×60 mm). Default us_2x2.
start_pctwriteGradient start along the fade axis (0-100). Default 0.
textreadWatermark text (e.g.
xreadPlacement X offset in pixels. Default 0.
yreadPlacement Y offset in pixels. Default 0.
04

Trust audit

BLOCKgrade F · trust 58/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (8 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (23)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/api/extendscript.ts:262
var opts2 = eval('new ' + saveCandidates[c] + '()');
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/utils/extendscript-result.ts:21
return new Function(`return ${trimmed}`)() as unknown;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/utils/extendscript-result.ts:25
return new Function(`return ${trimmed.slice(1, -1)}`)() as unknown;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/platform/uxp-bridge-client.ts:13
const res = await fetch(`http://127.0.0.1:${port}/health`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/platform/uxp-bridge-server.ts:48
const url = new URL(req.url ?? '/', `http://127.0.0.1:${listenPort}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
uxp-plugin/main.js:10
const BRIDGE_BASE = `http://127.0.0.1:${BRIDGE_PORT}`;
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/test-ui-auth.ts:170
body: JSON.stringify({ apiKey: 'sk-test-key-0123456789abcdef' }),
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
feather_px, photoshop_apply_layer_mask, photoshop_apply_layer_style, photoshop_delete_layer, photoshop_delete_layer_mask, photoshop_deselect, photoshop_generative_remove, photoshop_release_clipping_ma
Why it matters. 11 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/js-string.test.ts:48
expect(eval(`"${literal}"`)).toBe(nasty);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/js-string.test.ts:63
expect(eval(jsStringLiteral('São Paulo — "skyline"'))).toBe('São Paulo — "skyline"');
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
site/.vitepress/theme/composables/useClientChoice.ts:2
import type { Os } from '../../../data/clients';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
site/.vitepress/theme/composables/useSiteI18n.ts:3
import en from '../../../i18n/en.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
site/.vitepress/theme/composables/useSiteI18n.ts:4
import tr from '../../../i18n/tr.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
site/.vitepress/theme/composables/useSiteI18n.ts:5
import zh from '../../../i18n/zh.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
site/.vitepress/theme/composables/useSiteI18n.ts:6
import es from '../../../i18n/es.json';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/troubleshooting.md:92
curl -H "x-psmcp-token: $TOKEN" http://127.0.0.1:5174/api/status
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/troubleshooting.md:101
**Fix:** Reach the UI through the exact URL the CLI printed (`http://127.0.0.1:<port>`), not through a hostname that merely points at your machine, and not from a page served on another port.
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@ai-sdk/anthropic, @ai-sdk/google, @ai-sdk/mcp, @ai-sdk/openai, @anthropic-ai/claude-agent-sdk, @hono/node-server, @modelcontextprotocol/sdk, @openrouter/ai-sdk-provider
Why it matters. 27 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
site/package.json
@fontsource-variable/ibm-plex-sans, @fontsource/ibm-plex-mono, tsx, typescript, vitepress
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
web/package.json
@fontsource-variable/source-sans-3, @lucide/vue, @vueuse/core, class-variance-authority, clsx, lucide-vue-next, reka-ui, tailwind-merge
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/troubleshooting.md:83
**Cause:** The UI server holds your LLM provider API keys and can drive Photoshop, so every `/api/*` request must present the token generated when the server starts. The browser gets it automatically 
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
images/frame_generic_light.png
images/frame_generic_light.png
Why it matters. 7939338 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 36c0e79852b8full audit observations/trust-audit/mcp-server/alisaitteke__photoshop.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0536c0e79852b8BLOCKF58first audit
06

Questions

What is the Photoshop MCP server?

MCP for Adobe Photoshop. 118 tools. Control from Cursor, Claude or custom LLMs.

What tools does Photoshop expose?

172 in total: 92 read-only, 69 that write, and 11 that can delete or overwrite (feather_px, photoshop_apply_layer_mask, photoshop_apply_layer_style, photoshop_delete_layer, photoshop_delete_layer_mask). Every one is listed on this page with its risk.

Is Photoshop safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (58/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 11 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Photoshop need?

It reads PSMCP_UI_TOKEN and RYBBIT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Photoshop run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as photoshop-mcp-ui-web at 0.1.8.

How current is this page?

The grade is for one exact copy of the source (36c0e79852b8), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement