scumbleBLOCK
Free, open-source desktop editor for AI inpainting: select, prompt, get a colour-matched layer. FLUX 3 Image, FLUX.2, GPT Image, Nano Banana, Seedream and Qwen through your API key or your own ComfyUI. Layers, PSD export, MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Scumble
An AI-native image editor for ComfyUI and the models you already use. Inpaint, edit, upscale and generate, and every edit comes back as a layer of its own.
⭐ Star on GitHub · Download · Microsoft Store
Get Scumble
b30ff3ae3b27OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add scumble -- npx -y [email protected]
{
"mcpServers": {
"scumble": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (32)
22 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Default | read | the look Scumble ships with |
activate_document | read | Bring a tab to the front. |
add_paint_layer | write | A new paint layer. |
ailabel_add | write | Add the AI label. |
ailabel_info | read | About the AI label. |
ailabel_remove | destructive | Remove the AI label. |
boom | read | A command that throws. |
close_document | read | Close a tab. |
export | write | Write the picture to a file. |
extend_canvas | read | Extend or crop the canvas. |
film.apply_look | write | Apply a film stock. |
flatten | read | Flatten every visible layer. |
generate | read | Render. |
generate_new | read | Render a new base image. |
list_commands | read | Every command. |
list_documents | read | The open tabs. |
list_layers | read | The layers of a document. |
new_document | read | A new tab. |
ping | read | Whether Scumble answers. ${err.message}. Call ping again once it runs: the other tools come then. |
read_log | read | The app log. |
realism_pass | read | The pass. |
remove_layer | destructive | Remove a layer. |
run_action | write | A plugin action. |
screenshot | read | A JPEG of the image, base64 in |
select_by_text | read | Select by text, on ComfyUI. |
select_rect | read | Select a rectangle. |
set_layer | write | Change a layer. |
set_prompt | write | The prompt of a document. |
set_status | write | The status line. |
status | read | What is loaded. |
tint.layer | read | Tint a layer (a plugin tool with a layer but no doc). |
undo | read | One step back. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
b64decode( ... eval(
px.wasm
px_scalar.wasm
let head = "", body = String(text || "").replace(/^/, "");
const K = { openai: "sk-proj-openai-0123456789abcdef", gemini: "AIzaSyGemini0123456789abcdef", anthropic: "sk-ant-api03-0123456789abcdef", toapis: "sk-toapis-0123456789abcdef", compat: "sk-compat-0123ailabel_remove, remove_layer
const hash = crypto.createHash("sha1").update(String(userData).toLowerCase()).digest("hex").slice(0, 12);} from '../../three.module.js';
} from '../../three.module.js';
} from '../../three.module.js';
} from '../../three.module.js';
const e5 = await throws(() => router.edit(editReq(v, { model: "openai/../../x" }), ctxFor(fakeServer())));bar (default `http://127.0.0.1:8188`) and press Connect. Then open a picture (Ctrl+O, drop, paste), paint a
Your own ComfyUI is free to run, keeps every pixel on your machine, and gives you the models you already downloaded. It needs the node pack ComfyUI-InpaintCanvas installed there, and the models the re
documented hosts, or `http://127.0.0.1:<port>` with no path.
`http://127.0.0.1:<port>` (the test mock); anything else, a path included, is ignored. It never comes
`http://127.0.0.1:<port>` (the test mock); anything else is ignored: a path (`/api/v1` included), a query,
return m.group(1), base64.b64decode(m.group(2), validate=True)
data = base64.b64decode(r["data"])
return m.group(1), base64.b64decode(m.group(2), validate=True)
return "base64", base64.b64decode(s, validate=True)
out.append(("inlineData", d.get("mimeType"), base64.b64decode(d.get("data") or "")))@modelcontextprotocol/sdk, electron-updater, onnxruntime-node, ws, @types/node, electron, electron-builder, eslint
About 1 day: graphs 1 h, `comfyrefs.js` 3 h, `queueGenerate` and host 2 h, Info panel 1 h, tests 2 h, docs 1 h. It shares a session with 26f. Commit as DenRakEiw (`git -c user.name=DenRakEiw -c user.e
docs/images/readme/hero.gif
Gates applied: critical_finding, no_behavioural_pass.
b30ff3ae3b27full audit observations/trust-audit/mcp-server/denrakeiw__scumble.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | b30ff3ae3b27 | BLOCK | D | 69 | first audit |
Questions
What is the scumble MCP server?
Free, open-source desktop editor for AI inpainting: select, prompt, get a colour-matched layer. FLUX 3 Image, FLUX.2, GPT Image, Nano Banana, Seedream and Qwen through your API key or your own ComfyUI. Layers, PSD export, MCP.
What tools does scumble expose?
32 in total: 22 read-only, 8 that write, and 2 that can delete or overwrite (ailabel_remove, remove_layer). Every one is listed on this page with its risk.
Is scumble safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does scumble need?
No credential environment variables were found in its source, so it appears to need none.
How does scumble run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as scumble at 0.1.43.
How current is this page?
The grade is for one exact copy of the source (b30ff3ae3b27), read on 2026-10-08. The repository is watched and re-audited when it changes.