Atlas / MCP servers / jochenyang / Luma

LumaCAUTION

mcp/jochenyang/luma-1

多模型视觉理解 MCP 服务器,为不支持图片理解的 AI 编码模型提供视觉能力:分析截图、报错、UI 与文档,可接入多家主流视觉大模型。Multi-model vision MCP server that adds image understanding to AI coding models without native vision — analyze screenshots, errors, UI and documents via major vision LLM providers.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
115
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

多模型视觉理解 MCP 服务器,为不支持原生视觉能力的 AI 助手提供统一的图片分析能力。

English | 中文

特性

  • 多模型支持:GLM-4.6V、DeepSeek-OCR、Qwen3-VL-Flash、Doubao-Seed-1.6、Hunyuan-Vision
  • 单工具设计:统一通过 image_understand 完成图片理解,兼容旧客户端
  • 面向复杂截图优化:大图自动多裁剪、文本密集场景保真处理
  • 统一预处理链路:本地文件、远程 URL、Data URI 都进入同一套处理流程
  • 适用场景完整:代码截图、UI 截图、报错截图、文档截图、OCR
  • 标准 MCP 协议:可接入 Claude Desktop、Cline、Claude Code 等客户端
  • HTTP / Docker 部署:局域网内多客户端共享一个实例(v1.7.0+)
  • 内置重试:降低临时网络或模型请求失败带来的影响

快速开始

前置要求

  • Node.js >= 18
  • 任意一个模型提供商的 API Key

安装

直接通过 npx 运行(无需本地安装):

npx -y luma-mcp

或从源码构建:

git clone https://github.com/JochenYang/luma-mcp.git
cd luma-mcp
npm install
npm run build

不使用 MCP?Luma Vision Skill(轻量替代)

不想安装 MCP 服务器,或你使用的 AI 客户端(如 Kimi Code)支持 skill 而不支持 MCP?可直接使用仓库内的 vision-skill/:

  • 安装:把 vision-skill/ 目录复制到你所用 agent 的 skills 目录(如 ~/.agents/skills/vision-skill)
  • 激活:发送图片时以 /skill luma-vision 开头,skill 会执行 scripts/vision.js 直连视觉模型 API 完成分析
  • 配置:在系统环境变量中设置(与 MCP 版 custom provider 共用同一组变量):

与 MCP 版的差异:skill 是零依赖轻量脚本,只做"单图直连"——支持本地路径、HTTP(S) URL、Data URI,图片参数留空时自动扫描常见缓存目录找最新图片;但不包含 MCP 版的多裁剪、压缩、重试、SSRF 防护等能力。

配置

基础配置(npx 方式)

在 MCP 客户端的 mcpServers 中注册(Claude Desktop、Cline / VSCode 通用):

{
"mcpServers": {
"luma": {
"command": "npx",
"args": ["-y", "luma-mcp"],
"env": {
"MODEL_PROVIDER": "zhipu",
"ZHIPU_API_KEY": "your-api-key"
}
}
}
}

将 MODEL_PROVIDER 与对应的 API Key 环境变量替换为实际使用的提供商:

Read from source at commit b611f6131b74OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add luma-mcp --env CUSTOM_API_KEY=${CUSTOM_API_KEY} --env CUSTOM_AUTH_HEADER=${CUSTOM_AUTH_HEADER} --env CUSTOM_AUTH_HEADER_VALUE=${CUSTOM_AUTH_HEADER_VALUE} --env DASHSCOPE_API_KEY=${DASHSCOPE_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "luma-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CUSTOM_API_KEY": "${CUSTOM_API_KEY}",
        "CUSTOM_AUTH_HEADER": "${CUSTOM_AUTH_HEADER}",
        "CUSTOM_AUTH_HEADER_VALUE": "${CUSTOM_AUTH_HEADER_VALUE}",
        "DASHSCOPE_API_KEY": "${DASHSCOPE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
image_understandread图像理解工具(单一入口): - 何时调用:用户提到看图/截图/界面/报错/OCR/布局,或对话中出现图片附件并询问图片相关问题时,优先调用本工具。 - 图片来源:粘贴图路径、本地路径、HTTP(S) URL、Data URI。 - prompt:直接传入用户原始问题即可;服务端会拼接基础视觉协议与可选 task 指引。 - task_type(可选):auto|general|ocr|ui|debug|describe。省略或 auto 时与旧版行为兼容(按 prompt 启发式)。
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:22
CMD wget -qO- http://127.0.0.1:3000/ || exit 1
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tsconfig.check.json:1
{
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/test-mcp-http.ts:60
const base = `http://127.0.0.1:${port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/test-mcp-http.ts:200
const ttlBase = `http://127.0.0.1:${ttlPort}`;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, sharp, zod, @types/node, tsx, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b611f6131b74full audit observations/trust-audit/mcp-server/jochenyang__luma-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b611f6131b74CAUTIONB89first audit
06

Questions

What is the Luma MCP server?

多模型视觉理解 MCP 服务器,为不支持图片理解的 AI 编码模型提供视觉能力:分析截图、报错、UI 与文档,可接入多家主流视觉大模型。Multi-model vision MCP server that adds image understanding to AI coding models without native vision — analyze screenshots, errors, UI and documents via major vision LLM providers.

What tools does Luma expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Luma safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Luma need?

It reads CUSTOM_API_KEY, CUSTOM_AUTH_HEADER, CUSTOM_AUTH_HEADER_VALUE, DASHSCOPE_API_KEY, HUNYUAN_API_KEY, MAX_TOKENS, MCP_HTTP_TOKEN, SILICONFLOW_API_KEY, VOLCENGINE_API_KEY and ZHIPU_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Luma run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as luma-mcp at 1.7.1.

How current is this page?

The grade is for one exact copy of the source (b611f6131b74), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement