MoondreamSAFE
Moondream MCP Server in Python
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A FastMCP server for Moondream, an AI vision language model. This server provides image analysis capabilities including captioning, visual question answering, object detection, and visual pointing through the Model Context Protocol (MCP).
Features
- 🖼️ Image Captioning: Generate short, normal, or detailed captions for images
- ❓ Visual Question Answering: Ask natural language questions about images
- 🔍 Object Detection: Detect and locate specific objects with bounding boxes
- 📍 Visual Pointing: Get precise coordinates of objects in images
- 🔗 URL Support: Process images from both local files and remote URLs
- ⚡ Batch Processing: Analyze multiple images efficiently
- 🚀 Device Optimization: Automatic detection and optimization for CPU, CUDA, and MPS (Apple Silicon)
Installation
Prerequisites
- Python 3.10 or higher
- PyTorch 2.0+ (with appropriate device support)
Using uvx (Recommended for Claude Desktop)
# Run without installation uvx moondream-mcp # Or specify a specific version uvx moondream-mcp==1.0.2
Install from PyPI
pip install moondream-mcp
Install from Source
git clone https://github.com/ColeMurray/moondream-mcp.git cd moondream-mcp pip install -e .
Development Installation
git clone https://github.com/ColeMurray/moondream-mcp.git cd moondream-mcp pip install -e ".[dev]"
Quick Start
Running the Server
# Using uvx (no installation needed) uvx moondream-mcp # Using pip-installed command moondream-mcp # Or run directly with Python python -m moondream_mcp.server
Claude Desktop Integration
Add to your Claude Desktop configuration file:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json
Using uvx (Recommended)
{
"mcpServers": {
"moondream": {
"comm809c5148331eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add moondream-mcp --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx moondream-mcp{
"mcpServers": {
"moondream-mcp": {
"command": "uvx",
"args": [
"moondream-mcp"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_image | read | |
batch_analyze_images | read | |
caption_image | read | |
detect_objects | read | |
point_objects | read | |
query_image | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
agents, openai, python-dotenv, rich, click, requests, pathlib2
Gates applied: no_behavioural_pass.
809c5148331efull audit observations/trust-audit/mcp-server/colemurray__moondream-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 809c5148331e | SAFE | B | 89 | first audit |
Questions
What is the Moondream MCP server?
Moondream MCP Server in Python
What tools does Moondream expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Moondream safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Moondream need?
It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Moondream run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as moondream-mcp.
How current is this page?
The grade is for one exact copy of the source (809c5148331e), read on 2026-10-08. The repository is watched and re-audited when it changes.