Atlas / MCP servers / attalla1 / Photopea

PhotopeaCAUTION

mcp/attalla1/photopea

MCP server for AI-driven image editing with Photopea

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
34 19r · 13w · 2d
Transport
stdio
License
MIT
Stars
42
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Photopea MCP Server

Design posters, edit photos, and transform images directly from your terminal. Powered by Photopea -- a free, browser-based alternative to Photoshop -- connected to your AI agent via MCP.

Demo

Prompt used in this demo: examples/album-cover-demo.md

How It Works

graph LR
A[Agent] |stdio| B[MCP Server]
B |WebSocket| C[Browser]
C |postMessage| D[Photopea]

Your agent sends editing commands through the MCP protocol. The server translates these into Photopea JavaScript API calls and executes them via a WebSocket bridge to the browser.

Note: A browser window will open automatically on the first tool call. This is expected -- Photopea runs entirely in the browser and the server needs

Read from source at commit f87b1760ae56OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add photopea-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "photopea-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (34)

19 read · 13 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
photopea_add_fill_layerwrite
photopea_add_gradientwrite
photopea_add_layerwrite
photopea_add_shapewrite
photopea_add_textwrite
photopea_apply_adjustmentwrite
photopea_apply_filterwrite
photopea_clear_selectiondestructive
photopea_close_documentread
photopea_create_documentwrite
photopea_delete_layerdestructive
photopea_duplicate_layerread
photopea_edit_textwrite
photopea_export_imageread
photopea_fill_selectionread
photopea_get_document_inforead
photopea_get_layersread
photopea_group_layersread
photopea_list_fontsread
photopea_load_fontread
photopea_make_selectionread
photopea_modify_selectionwrite
photopea_move_layerwrite
photopea_open_fileread
photopea_place_imageread
photopea_redoread
photopea_reorder_layerread
photopea_resize_documentread
photopea_run_scriptwrite
photopea_select_layerread
photopea_set_layer_propertieswrite
photopea_transform_layerread
photopea_undoread
photopea_ungroup_layersread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/bridge/websocket-server.ts:99
const url = `http://127.0.0.1:${this.port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/bridge/websocket-server.ts:110
reject(new Error(`Photopea did not become ready within ${READY_TIMEOUT_MS / 1000}s. Please open http://127.0.0.1:${this.port} and wait for Photopea to load.`));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/index.ts:41
console.error(`Photopea MCP bridge running on http://127.0.0.1:${port}`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
photopea_clear_selection, photopea_delete_layer
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/websocket-bridge.test.ts:3
import { PhotopeaBridge } from "../../src/bridge/websocket-server.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/script-builder.test.ts:34
} from "../../src/bridge/script-builder.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, open, ws, zod, @types/node, @types/ws, tsx, typescript
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
assets/demo.gif
assets/demo.gif
Why it matters. 4068652 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f87b1760ae56full audit observations/trust-audit/mcp-server/attalla1__photopea.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f87b1760ae56CAUTIONB89first audit
06

Questions

What is the Photopea MCP server?

MCP server for AI-driven image editing with Photopea

What tools does Photopea expose?

34 in total: 19 read-only, 13 that write, and 2 that can delete or overwrite (photopea_clear_selection, photopea_delete_layer). Every one is listed on this page with its risk.

Is Photopea safe to connect to an agent?

With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Photopea need?

No credential environment variables were found in its source, so it appears to need none.

How does Photopea run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as photopea-mcp-server at 0.1.1.

How current is this page?

The grade is for one exact copy of the source (f87b1760ae56), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement