Atlas / MCP servers / deepfates / Replicate

ReplicateCAUTION

mcp/deepfates/replicate-1

Model Context Protocol server for Replicate's API

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
28 25r · 2w · 1d
Transport
stdio
License
MIT
Stars
94
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol server implementation for Replicate. Run Replicate models through a simple tool-based interface.

NOT IN ACTIVE DEVELOPMENT

This repo was an experiment in MCP tooling for Replicate. The company now offers an official MCP server. This repo will stay up for those who find it useful or want to fork it, but it's not in active development and issues won't be addressed. Contributions might be folded in but no promises. Enjoy at your own risk.

Quickstart

  1. Install the server:
npm install -g mcp-replicate
  1. Get your Replicate API token:
  1. Configure Claude Desktop:
  2. Open Claude Desktop Settings (⌘,)
  3. Select the "Developer" section in the sidebar
  4. Click "Edit Config" to open the configuration file
  5. Add the following configuration, replacing your_token_here with your actual Replicate API token:
{
"mcpServers": {
"replicate": {
"command": "mcp-replicate",
"env": {
"REPLICATE_API_TOKEN": "your_token_here"
}
}
}
}
  1. Start Claude Desktop. You should see a 🔨 hammer icon in the bottom right corner of new chat windows, indicating the tools are available.

(You can also use any other MCP client, such as Cursor, Cline, or Continue.)

Alternative Installation Methods

Install from source

git clone https://github.com/deepfates/mcp-replicate
cd mcp-replicate
npm install
npm run build
npm start

Run with npx

npx mcp-replicate

Features

Models

  • Search models using semantic search
  • Browse models and collections
  • Get detailed model information and versions

Predictions

  • Create predictions with text or structured input
  • Track predict
Read from source at commit 396ecc8f584fOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-replicate --env REPLICATE_API_TOKEN=${REPLICATE_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-replicate": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "REPLICATE_API_TOKEN": "${REPLICATE_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (28)

25 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AnimereadJapanese anime and manga style
BalancedreadGood balance between quality and speed
CinematicreadMovie-like scenes with dramatic lighting
DraftreadQuick, low-quality preview with minimal steps
ExtremereadMaximum quality with extensive steps
LandscapereadHorizontal format for landscapes
MinimalistreadClean, simple minimalist style
PanoramicreadExtra wide format for panoramas
PhotorealisticreadHighly detailed, realistic photography style
PortraitreadVertical format for portraits
QualityreadHigh-quality output with more steps
SquarereadPerfect square format
WatercolorreadSoft watercolor painting style
Widescreenread16:9 format for modern displays
cancel_predictionreadCancel a running prediction
clear_image_cachedestructiveClear the image viewer cache
create_and_poll_predictionwriteCreate a new prediction and wait until it
create_predictionwriteCreate a new prediction using either a model version (for community models) or model name (for official models)
get_collectionreadGet details of a specific collection
get_image_cache_statsreadGet statistics about the image cache
get_modelreadGet details of a specific model including available versions
get_predictionreadGet details about a specific prediction
list_collectionsreadList available model collections
list_modelsreadList available models with optional filtering
list_predictionsreadList recent predictions
sdxlreadTest model
search_modelsreadSearch for models using semantic search
view_imagereadDisplay an image in the system
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (6)

MEDIUMInventory / provenance · inv.binary · CWE-1104
mcp-replicate-0.1.0.tgz
mcp-replicate-0.1.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
mcp-replicate-0.1.1.tgz
mcp-replicate-0.1.1.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tests/protocol.test.ts:213
secret: "1234567890abcdef1234567890abcdef",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_image_cache
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/templates/prompts/text_to_image.ts:5
import type { MCPMessage } from "../../types/mcp.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, replicate, @biomejs/biome, @types/node, typescript, vitest
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 396ecc8f584ffull audit observations/trust-audit/mcp-server/deepfates__replicate-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07396ecc8f584fCAUTIONB85first audit
06

Questions

What is the Replicate MCP server?

Model Context Protocol server for Replicate's API

What tools does Replicate expose?

28 in total: 25 read-only, 2 that write, and 1 that can delete or overwrite (clear_image_cache). Every one is listed on this page with its risk.

Is Replicate safe to connect to an agent?

With care. The audit graded it B (85/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Replicate need?

It reads REPLICATE_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Replicate run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-replicate at 0.1.1.

How current is this page?

The grade is for one exact copy of the source (396ecc8f584f), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement