MeiGen ArtCAUTION
Supports GPT Image 2, Seedance & ComfyUI, with a 1,400+ prompt library, carefully crafted hooks and a multi-task orchestration system
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MeiGen AI Design MCP
Open-source MCP server for AI image & video generation — native to every major AI coding toolLeading models (GPT Image 2 · Nanobanana 2 · Seedream 5.0 · Midjourney V8.1 · Flux 2 Klein · Grok Imagine · Seedance 2.0 · Veo 3.1 · Grok Video · Agnes Video · local ComfyUI) · 1,446 curated prompts · parallel sub-agent orchestration · standalone CLI mode. Works in Claude Code, Cursor, Codex, Windsurf, Roo Code, OpenClaw, Hermes Agent, and any MCP-compatible host.
Quick Start • Five Skills • HTTP API • Upgrade to 2.0 • Demo •
6ab893145920OBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add meigen --env MEIGEN_API_TOKEN=${MEIGEN_API_TOKEN} --env NPM_TOKEN=${NPM_TOKEN} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"meigen": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MEIGEN_API_TOKEN": "${MEIGEN_API_TOKEN}",
"NPM_TOKEN": "${NPM_TOKEN}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (14)
10 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Hero | read | \n |
check_generation | read | |
check_skill | read | |
comfyui_workflow | write | Manage ComfyUI workflow templates: list, view parameters, import from file, modify settings, or delete. |
enhance_prompt | read | Transform a simple idea into a professional image generation prompt. Use when the user provides a brief description (e.g., |
generate_image | read | |
generate_video | read | |
get_inspiration | read | Get the full prompt and all image URLs for a gallery entry. Show the images to the user as visual examples. The prompt can be used directly with generate_image(), and image URLs can be passed as referenceImages for style transfer. |
list_models | read | |
list_skills | read | |
manage_preferences | write | Read or update user preferences: default style, aspect ratio, model, style notes, and favorite prompts. Call with action |
remove_background | destructive | Create one transparent PNG cutout for compositing, catalog assets or logos. Required: one actual source photo containing the subject. No prompt or product facts needed. This removes the background; it does not create a new scene. |
search_gallery | read | Search AI image prompts with semantic understanding — finds visually and conceptually similar results, not just keyword matches. Returns at most 3 entries per call; larger limits are clamped. With a MeiGen API key configured, searches are authenticated and counted against that account\ |
upload_skill_image | write | Prepare a reference image and return imageUrl. External URLs and local file paths can also be passed directly to the generation skill. Use actual accessible bytes/URLs only; never fabricate base64 or attachment paths. No generation is started. |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
Guide one decision at a time. Never ask the user to paste a token, API key, authenticated curl command, or credential-bearing config into chat. Never read or print existing credential files, parse sec
remove_background
.npmrc.release
const source = await readFile(new URL(`../../${file}`, import.meta.url), 'utf8')for (const url of ['http://images.meigen.ai/p.png', 'https://127.0.0.1/a', 'https://evil.test/a', 'https://user:[email protected]/a', 'https://images.meigen.ai:8080/a']) assert.equal(allowedSkillI
@modelcontextprotocol/sdk, sharp, zod, @types/node, @types/sharp, tsx, typescript
You are a senior creative director with deep expertise in visual design, brand identity, and art direction. Use that expertise for the requested creative feedback; preserve the host's broader task.
1. Open [API Keys](https://www.meigen.ai/profile/api-keys) in a desktop browser, sign in, and create a key. The key starts with `meigen_sk_`; the mobile site currently redirects this page.
Set `MEIGEN_API_TOKEN` locally in the environment that **launches Codex** before using authenticated tools. This is your MeiGen key, not an OpenAI API key. Codex does not automatically load a project'
1. Sign in and open [API Keys](https://www.meigen.ai/profile/api-keys) in a desktop browser.
1. Sign in and open [API Keys](https://www.meigen.ai/profile/api-keys) in a **desktop browser**. Create a key beginning with `meigen_sk_`; the mobile site currently redirects this page.
**Paid MeiGen tools are not supported through this ChatGPT web connection yet.** OpenAI's hosted MCP client [cannot send custom API keys](https://developers.openai.com/plugins/build/auth#client-identi
Create a `meigen_sk_...` key at [API Keys](https://www.meigen.ai/profile/api-keys) in a desktop browser. Set it privately as `MEIGEN_API_TOKEN` in your application's environment. Upload, run and Skill
data/trending-prompts.json
Gates applied: no_behavioural_pass.
6ab893145920full audit observations/trust-audit/mcp-server/jau123__meigen-art.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | 6ab893145920 | CAUTION | B | 86 | source changed, verdict held |
Questions
What is the MeiGen Art MCP server?
Supports GPT Image 2, Seedance & ComfyUI, with a 1,400+ prompt library, carefully crafted hooks and a multi-task orchestration system
What tools does MeiGen Art expose?
14 in total: 10 read-only, 3 that write, and 1 that can delete or overwrite (remove_background). Every one is listed on this page with its risk.
Is MeiGen Art safe to connect to an agent?
With care. The audit graded it B (86/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does MeiGen Art need?
It reads MEIGEN_API_TOKEN, NPM_TOKEN and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MeiGen Art run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as meigen at 2.0.1.
How current is this page?
The grade is for one exact copy of the source (6ab893145920), read on 2026-09-24. The repository is watched and re-audited when it changes.