ImageSorceryCAUTION
An MCP server providing tools for image processing operations
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
ComputerVision-based 🪄 sorcery of local image recognition and editing tools for AI assistants
Official website: imagesorcery.net
[](https://opensource.org/licenses/MIT) [](https://github.com/microsoft/mcp) [](https://claude.ai) [](https://cursor.so) [](https://github.com/ClineLabs/cline) [](https://mseep.ai/app/2620351a-15b1-4840-a93a-cbdbd23a6944) [](https://pepy.tech/projects/imagesorcery-mcp)
✅ With ImageSorcery MCP
🪄 ImageSorcery empowers AI assistants with powerful image processing capabilities:
- ✅ Crop, resize, and rotate images with precision
- ✅ Remove background
- ✅ Draw text and shapes on images
- ✅ Add logos and watermarks
- ✅ Detect objects using state-of-the-art models
- ✅ Extract text from images with OCR
- ✅ Use a wide range of pre-trained models for object detection, OCR, and more
- ✅ Do all of this locally, without sending your images to any servers
Just ask your AI to help with image tasks:
"copy photos with pets from folderphotosto folderpets"
"Find a cat at the photo.jpg and crop the image in a half in height and width to make the cat be centered"
😉 **Hint:** Use full path to your files".
"Enumerate form fields on this form.jpg with `foduucom/web-form-5b78e66691d7OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add imagesorcery-mcp --env IMAGESORCERY_AMPLITUDE_API_KEY=${IMAGESORCERY_AMPLITUDE_API_KEY} --env IMAGESORCERY_POSTHOG_API_KEY=${IMAGESORCERY_POSTHOG_API_KEY} -- uvx imagesorcery-mcp{
"mcpServers": {
"imagesorcery-mcp": {
"command": "uvx",
"args": [
"imagesorcery-mcp"
],
"env": {
"IMAGESORCERY_AMPLITUDE_API_KEY": "${IMAGESORCERY_AMPLITUDE_API_KEY}",
"IMAGESORCERY_POSTHOG_API_KEY": "${IMAGESORCERY_POSTHOG_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_metainfo | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
self.logger.debug(f"Amplitude handler enabled with API key: {api_key}")self.logger.debug(f"PostHog handler enabled with API key: {api_key}")"url": "http://127.0.0.1:8000/mcp", // Use your custom host, port, and path if specified
- `python-dotenv` (optional) — used by scripts to load a `.env` file when present
Gates applied: no_behavioural_pass.
5b78e66691d7full audit observations/trust-audit/mcp-server/sunriseapps__imagesorcery.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 5b78e66691d7 | CAUTION | B | 89 | first audit |
Questions
What is the ImageSorcery MCP server?
An MCP server providing tools for image processing operations
What tools does ImageSorcery expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ImageSorcery safe to connect to an agent?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does ImageSorcery need?
It reads IMAGESORCERY_AMPLITUDE_API_KEY and IMAGESORCERY_POSTHOG_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ImageSorcery run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as imagesorcery-mcp.
How current is this page?
The grade is for one exact copy of the source (5b78e66691d7), read on 2026-10-03. The repository is watched and re-audited when it changes.