Logo GenerationSAFE
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This server provides logo generation capabilities using FAL AI, with tools for image generation, background removal, and automatic scaling.
Demo
[](https://www.youtube.com/watch?v=Miemu1xEZng)
Installation
- Install
uv(Universal Virtualenv):
curl -LsSf https://astral.sh/uv/install.sh | sh
- Create and activate a virtual environment:
uv venv source .venv/bin/activate # On Unix/macOS # or .venv\Scripts\activate # On Windows
- Install dependencies:
uv pip install -r requirements.txt
- Set up your environment variables:
- Create a
.envfile in the root directory - Add your FAL AI API key:
FAL_KEY=your_fal_ai_key_here
Running the Server
Start the server with:
python run_server.py
The server will be available at http://127.0.0.1:7777
Troubleshooting
If you encounter a FileNotFoundError on Windows when running the server, make sure you're running the command from the root directory of the project. If the issue persists, try updating to the latest version of the repository which includes fixes for Windows compatibility.
For Windows users specifically:
- Make sure you've activated your virtual environment with
.venv\Scripts\activate - Run the server from the root directory of the project with
python run_server.py - If you see any path-related errors, please report them in the issues section of the repository
Cursor IDE Configuration
- Open Cursor Settings
- Navigate to the MCP section
- Add the following configuration:
- URL:
http://127.0.0.1:7777/sse - Connection Type:
SSE - Enable the connection
Notes
- Always reference
@logo-creation.mdcin your Cursor Composer for consistent results - Steps are defined in
@logo-creation.mdcbut tools can be used independently - All generated logos will be saved in the
downloadsd
2a7bc11b8a26OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-tool-server --env FAL_API_KEY=${FAL_API_KEY} --env FAL_KEY=${FAL_KEY} -- uvx mcp-tool-server{
"mcpServers": {
"mcp-tool-server": {
"command": "uvx",
"args": [
"mcp-tool-server"
],
"env": {
"FAL_API_KEY": "${FAL_API_KEY}",
"FAL_KEY": "${FAL_KEY}"
}
}
}
}Exposed tools (4)
2 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
download_image | write | Download an image from a URL and save it locally |
generate_image | read | Generate an image from a text prompt using FAL AI. For best results with logos and icons, use the format: |
remove_background | destructive | Remove background from an image using FAL AI |
scale_image | read | Scale an image to multiple sizes while preserving transparency |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (6)
remove_background
The server will be available at `http://127.0.0.1:7777`
- URL: `http://127.0.0.1:7777/sse`
base64.b64decode(base64_str)
downloads/fighter_jet.glb
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
2a7bc11b8a26full audit observations/trust-audit/mcp-server/sshtunnelvision__logo-generation.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 2a7bc11b8a26 | SAFE | B | 89 | first audit |
Questions
What tools does Logo Generation expose?
4 in total: 2 read-only, 1 that write, and 1 that can delete or overwrite (remove_background). Every one is listed on this page with its risk.
Is Logo Generation safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Logo Generation need?
It reads FAL_API_KEY and FAL_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (2a7bc11b8a26), read on 2026-10-06. The repository is watched and re-audited when it changes.