Image RecognitionSAFE
An MCP server that provides image recognition 👀 capabilities using Anthropic and OpenAI vision APIs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server that provides image recognition capabilities using Anthropic and OpenAI vision APIs. Version 0.1.2.
Features
- Image description using Anthropic Claude Vision or OpenAI GPT-4 Vision
- Support for multiple image formats (JPEG, PNG, GIF, WebP)
- Configurable primary and fallback providers
- Base64 and file-based image input support
- Optional text extraction using Tesseract OCR
Requirements
- Python 3.8 or higher
- Tesseract OCR (optional) - Required for text extraction feature
- Windows: Download and install from UB-Mannheim/tesseract
- Linux:
sudo apt-get install tesseract-ocr - macOS:
brew install tesseract
Installation
- Clone the repository:
git clone https://github.com/mario-andreschak/mcp-image-recognition.git cd mcp-image-recognition
- Create and configure your environment file:
cp .env.example .env # Edit .env with your API keys and preferences
- Build the project:
build.bat
Usage
Running the Server
Spawn the server using python:
python -m image_recognition_server.server
Start the server using batch instead:
run.bat server
Start the server in development mode with the MCP Inspector:
run.bat debug
Available Tools
describe_image- Input: Base64-encoded image data and MIME type
- Output: Detailed description of the image
describe_image_from_file- Input: Path to an image file
- Output: Detailed description of the image
Environment Configuration
ANTHROPIC_API_KEY: Your Anthropic API key.OPENAI_API_KEY: Your OpenAI API key.VISION_PROVIDER: Primary vision provider (anthropicoropenai).FALLBACK_PROVIDER: Optional fallback provider.LOG_LEVEL: Logging level (DEBUG, INFO, WARNING, ERROR).ENABLE_OCR: Enable Tesseract OCR text extraction (trueorfalse).TESSERACT_CMD: Optional custom path t
b500395bfa8bOBSERVED · 2026-10-08Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
describe_image | read | Describe the contents of an image using vision AI. |
describe_image_from_file | read | Describe the contents of an image file using vision AI. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
image_bytes = base64.b64decode(image_data)
image_data = base64.b64decode(base64_string)
bytes.fromhex(
image_data = base64.b64decode(TEST_IMAGE_DATA)
pytest, pytest-asyncio, pytest-cov, black, isort, mypy, ruff
mcp, anthropic, openai, python-dotenv, Pillow, numpy, pandas, pytesseract
Gates applied: no_behavioural_pass.
b500395bfa8bfull audit observations/trust-audit/mcp-server/mario-andreschak__image-recognition.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | b500395bfa8b | SAFE | B | 89 | first audit |
Questions
What is the Image Recognition MCP server?
An MCP server that provides image recognition 👀 capabilities using Anthropic and OpenAI vision APIs
What tools does Image Recognition expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Image Recognition safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Image Recognition need?
It reads ANTHROPIC_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (b500395bfa8b), read on 2026-10-08. The repository is watched and re-audited when it changes.