Atlas / MCP servers / maorcc / GIMP

GIMPBLOCK

mcp/maorcc/gimp

GIMP MCP server

Verdict
BLOCK
Grade
D
Trust score
62 /100
Exposed tools
79 50r · 25w · 4d
Transport
—
License
GPL-3.0
Stars
255
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.gnu.org/licenses/gpl-3.0) [](https://claude.ai/desktop) [](https://gimp.org) [](https://modelcontextprotocol.io) [](https://coderabbit.ai)

Demo

Full demo (with audio): https://github.com/maorcc/gimp-mcp/raw/main/docs/demo.mp4

AI agent using GIMP MCP to remove a background, edit a character's expression, and verify results — all through natural language via Claude

Overview

GIMP MCP bridges GIMP's professional image editing capabilities with AI assistants through the Model Context Protocol. It lets you edit images by describing what you want — and gives the AI a live visual feedback channel to verify each change before moving on.

What makes it different from other GIMP integrations:

  • The AI can see the image at any point in the workflow without saving to disk (get_state_snapshot)
  • Supports fully autonomous multi-step pipelines: open → edit → verify → refine → export
  • 56 dedicated tool commands covering every major GIMP operation
  • Fully compatible with GIMP 3.2.x (all breaking API changes resolved)

Key Features

Read from source at commit 01fdc0e7cac1OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add gimp-mcp -- uvx gimp-mcp
claude-desktop
{
  "mcpServers": {
    "gimp-mcp": {
      "command": "uvx",
      "args": [
        "gimp-mcp"
      ]
    }
  }
}
03

Exposed tools (79)

50 read · 25 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_textwriteAdd a text layer to an image.
adjust_brightness_contrastreadAdjust brightness and contrast of a layer.
adjust_color_balancereadAdjust color balance (shadows / midtones / highlights) of a layer.
adjust_curvesreadAdjust tonal curves for a layer.
adjust_hue_saturationreadAdjust hue, saturation, and lightness of a layer.
apply_drop_shadowdestructiveApply a drop shadow effect to a layer.
apply_embosswriteApply an emboss (bas-relief) effect to a layer.
apply_gaussian_blurwriteApply Gaussian blur as a destructive filter operation.
apply_noisewriteAdd noise/grain to a layer.
apply_pixelatewritePixelate a layer using a mosaic/block effect.
apply_vignettewriteApply a vignette darkening effect around the edges of a layer.
auto_levelsreadAutomatically stretch the tonal range of an image (auto levels / auto stretch contrast).
batch_exportreadExport all open images (or a specific one) to a directory.
batch_resizereadResize all open images to a common target size.
blurwriteApply Gaussian blur to a layer.
call_apireadCall GIMP 3.2 API methods through PyGObject console.
check_serverreadCheck whether the GIMP MCP plugin socket is reachable and responding.
close_imagereadClose an image, optionally saving as XCF first.
convert_color_modereadConvert an image to a different color mode.
create_layerwriteCreate and insert a new layer into an image.
crop_to_rectreadCrop the image canvas to an explicit rectangle.
crop_to_selectionreadCrop the image canvas to the current selection bounds.
delete_layerdestructiveDelete a layer from an image.
denoisereadReduce noise in a layer using GEGL noise-reduction.
desaturatereadConvert a layer to grayscale (desaturate).
draw_ellipsereadDraw an ellipse outline (stroke only) on a layer.
draw_linereadDraw a straight line on a layer.
draw_rectanglereadDraw a rectangle outline (stroke only) on a layer.
duplicate_layerwriteDuplicate a layer and insert the copy above it.
edit_textwriteEdit an existing text layer
export_icon_sizeswriteExport an image as a complete icon set for Android or iOS.
export_imagereadExport the current image to a raster file (PNG, JPEG, WEBP, TIFF).
export_social_media_kitreadExport an image resized for multiple social media platforms.
export_sprite_sheetreadCombine multiple frames into a sprite sheet PNG.
export_web_optimizedreadExport an image as both JPEG and PNG, choosing the smaller format.
fill_ellipsereadFill an elliptical region with a solid color.
fill_layerreadFill an entire layer with a solid color.
fill_rectanglereadFill a rectangular region with a solid color.
fill_selectionreadFill the current selection with a color or fill type.
flatten_imagereadFlatten all layers into a single background layer.
flip_imagereadFlip the entire image horizontally or vertically.
get_context_statereadGet the current GIMP context state (colors, brush, settings).
get_gimp_inforeadGet comprehensive information about the GIMP installation and environment.
get_histogramreadGet histogram statistics for a channel of the active layer.
get_image_bitmapreadGet the current open image in GIMP as an Image object with optional scaling and region selection.
get_image_metadatareadGet metadata about the current open image in GIMP without the bitmap data.
get_pixel_colorreadGet the color of a single pixel.
get_selection_boundsreadGet the bounding rectangle of the current selection.
get_state_snapshotwriteReturn a live visual snapshot of the current image state — no file save needed.
gradient_fillreadFill a layer or selection with a gradient.
invert_colorswriteInvert all colors in a layer (create a negative).
invert_selectionreadInvert the current selection (select what is not selected).
list_fontsreadList available fonts installed in GIMP.
list_imagesreadList all images currently open in GIMP.
list_layersreadList all layers in an image with their properties.
merge_visible_layerswriteMerge all visible layers into a single layer.
modify_selectionwriteGrow, shrink, feather, border, or sharpen the current selection.
new_canvaswriteCreate a new blank canvas in GIMP and open it in a display window.
open_imagewriteOpen an image file in GIMP and create a display window.
redoreadRedo one or more previously undone operations on an image.
rename_layerwriteRename a layer.
reorder_layerwriteMove a layer to a new stack position.
resize_canvasreadResize the image canvas without scaling the content.
restart_serverdestructiveDrop and re-establish the connection to the GIMP MCP plugin.
rotate_imagereadRotate the entire image.
save_xcfwriteSave the current image as a GIMP XCF file (preserves all layers and metadata).
scale_imagereadScale an image to exact pixel dimensions.
scale_to_fitreadScale an image to fit within a bounding box, preserving aspect ratio.
select_allreadSelect the entire image canvas.
select_by_colorreadSelect regions by color similarity.
select_ellipsewriteCreate an elliptical selection.
select_nonedestructiveRemove / deselect all selections.
select_rectanglewriteCreate a rectangular selection.
set_active_imagewriteRaise a specific image to the front / make it active in GIMP.
set_colorswriteSet the GIMP foreground and/or background color.
set_layer_propertieswriteSet properties on an existing layer.
sharpenreadSharpen a layer using unsharp mask.
undoreadUndo one or more operations on an image.
warp_regionreadWarp / liquify a region of the image by pushing pixels in a direction.
04

Trust audit

BLOCKgrade D · trust 62/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (4 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (15)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
gimp-mcp-plugin.py:42
exec(command, context)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
gimp-mcp-plugin.py:438
vals = [str(eval(e)) for e in a[1]]
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
gimp-mcp-plugin.py:1646
exec(cmd, self.context)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
gimp-mcp-plugin.py:1247
__import__(module_name)
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
apply_drop_shadow, delete_layer, restart_server, select_none
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coderabbit.yaml
.coderabbit.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
agent_edit_demo.py:64
raw = base64.b64decode(b64)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
bg_remove_iterative.py:60
raw = base64.b64decode(r['results']['image_data'])
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gimp_mcp_server.py:235
as_bytes = base64.b64decode(base64_data)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gimp_mcp_server.py:360
raw_bytes = base64.b64decode(b64_data)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/continuous_edit_test/continuous_edit_test.py:128
raw = base64.b64decode(r['results']['image_data'])
INFOInventory / provenance · inv.oversize · CWE-1104
docs/demo.mp4
docs/demo.mp4
Why it matters. 4657474 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/mcpInAction.gif
docs/mcpInAction.gif
Why it matters. 1994839 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
tests/continuous_edit_test/files/bg_night_2048.png
tests/continuous_edit_test/files/bg_night_2048.png
Why it matters. 1481513 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 01fdc0e7cac1full audit observations/trust-audit/mcp-server/maorcc__gimp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0601fdc0e7cac1BLOCKD62first audit
06

Questions

What is the GIMP MCP server?

GIMP MCP server

What tools does GIMP expose?

79 in total: 50 read-only, 25 that write, and 4 that can delete or overwrite (apply_drop_shadow, delete_layer, restart_server, select_none). Every one is listed on this page with its risk.

Is GIMP safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (62/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GIMP need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (01fdc0e7cac1), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement