JimengpicSAFE
使用即梦 API 生成图片的 MCP 服务
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
基于火山引擎即梦AI的图片生成MCP(Model Context Protocol)服务。
功能特性
- 使用火山引擎即梦AI API生成高质量图片
- 支持多种图片比例:4:3、3:4、16:9、9:16
- 标准化的MCP接口,兼容各种MCP客户端
- 环境变量配置,安全便捷
安装依赖
cd jimengpic-mcp npm install
编译项目
npm run build
环境变量配置
设置以下环境变量:
export JIMENG_ACCESS_KEY="你的火山引擎AccessKey" export JIMENG_SECRET_KEY="你的火山引擎SecretKey"
获取API密钥
- 访问 火山引擎控制台
- 登录后进入"即梦AI"产品页面,开通服务(可选择免费试用)
- 在"访问控制"页面创建访问密钥,获取Access Key和Secret Key
- 确保账号已开通即梦AI图像生成相关权限和策略
注意: 根据官方文档,请确保使用正确的reqkey参数值 `jimenghighaesgeneralv21L`
使用方法
直接运行
node build/index.js
作为MCP服务器
在MCP客户端(如Claude Desktop、Cursor等)中配置此服务:
{
"mcpServers": {
"jimengpic": {
"command": "node",
"args": ["/path/to/jimengpic-mcp/build/index.js"],
"env": {
"JIMENG_ACCESS_KEY": "你的AccessKey",
"JIMENG_SECRET_KEY": "你的SecretKey"
}
}
}
}API接口
generate-image
当用户需要生成图片时使用的工具。
参数:
text(string): 用户需要在图片上显示的文字illustration(string): 根据用户要显示的文字,提取3-5个可以作为图片配饰的插画元素关键词color(string): 图片的背景主色调ratio(enum): 图片比例,支持以下选项:"4:3": 512×384"3:4": 384×512"16:9": 512×288"9:16": 288×512
提示词生成规则: 工具会自动将输入参数组合成以下格式的提示词:
字体设计:"{text}",黑色字体,斜体,带阴影。干净的背景,白色到{color}渐变。点缀浅灰色、半透明{illustration}等元素插图做配饰插画。返回:
- 成功时返回图片URL和详细信息
- 失败时返回错误信息
使用示例
// 在MCP客户端中调用
const result = await mcp.callTool("generate-image", {
text: "新年快乐",
illustration: "烟花, 灯笼, 祥云, 星星, 礼花",
color: "红色",
ratio: "4:3"
});项目结构
jimengpic-mcp/ ├── src/ │ └── index.ts # 主服务文件 ├── build/ # 编译输出目录 ├── package.json # 项目配置 ├── tsconfig.json # TypeScript配置 └── README.md # 项目说明
注意事项
- 确保网络连接正常,能够访问火山引擎API
- API调用需要消耗积分,请注意使用量
- 生成的图片URL有时效性,建议及时下载保存
- 请遵守火山引擎的使用条款和即梦AI的内容政策
故障排除
常见错误
- 环境变量未设置:确保设置了正确的ACCESSKEY和SECRET
8cf42e856a82OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add jimengpic-mcp --env JIMENG_ACCESS_KEY=${JIMENG_ACCESS_KEY} --env JIMENG_SECRET_KEY=${JIMENG_SECRET_KEY} -- npx -y [email protected]{
"mcpServers": {
"jimengpic-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"JIMENG_ACCESS_KEY": "${JIMENG_ACCESS_KEY}",
"JIMENG_SECRET_KEY": "${JIMENG_SECRET_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
generate-image | read | 当用户需要生成图片时使用的工具 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
@modelcontextprotocol/sdk, zod, @types/node, typescript
Gates applied: no_behavioural_pass.
8cf42e856a82full audit observations/trust-audit/mcp-server/comeonzhj__jimengpic.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 8cf42e856a82 | SAFE | B | 89 | first audit |
Questions
What is the Jimengpic MCP server?
使用即梦 API 生成图片的 MCP 服务
What tools does Jimengpic expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Jimengpic safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Jimengpic need?
It reads JIMENG_ACCESS_KEY and JIMENG_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Jimengpic run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as jimengpic-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (8cf42e856a82), read on 2026-10-07. The repository is watched and re-audited when it changes.