gemini-vision-mcp-safe
A privacy-conscious MCP server that enables image analysis via Google Gemini with safety features like two-step confirmation and SSRF defenses.
README
gemini-vision-mcp-safe
English|简体中文
A minimal, privacy-conscious MCP server that lets an MCP client (Claude Code, Claude Desktop, etc.) ask Google Gemini to look at an image — local file or URL — and return a description, text extraction, comparison, and so on.
The "safe" in the name is a design goal:
- Two-step handshake before any image leaves the machine. The first call
returns a Chinese confirmation prompt; the second call (with
confirm_send_to_gemini=true) is the only one that actually talks to Gemini. This stops a model from silently uploading user files to Google. - SSRF defenses for URL inputs: protocol allowlist, manual redirect handling, per-hop DNS check against private/loopback ranges, HTTPS→HTTP downgrade refused.
- Magic-byte sniffing instead of trusting file extensions or
Content-Type. - Configurable size cap with both
Content-Lengthpre-check and a hard streaming limit; remote bodies stream to a temp file that is removed infinally. - Proxy aware via
HTTPS_PROXY/HTTP_PROXY. Useful where Google APIs are not directly reachable (e.g. mainland China through clash/mihomo). The proxy URL is redacted in logs. - API key in
.env, not in the MCP config. The repo's.gitignoreexcludes.envso the key never ends up in git.
Result text and error messages are in Chinese.
Tools
analyze_image_with_gemini
Send one local image or one HTTP/HTTPS image URL to Gemini.
| Parameter | Required | Description |
|---|---|---|
image_source |
yes | Local path (C:/path/to.png) or URL (https://…). |
prompt |
no | What to ask Gemini. Defaults to a Chinese "describe this image" prompt. |
model |
no | Override the model for this call (e.g. gemini-2.5-flash). Falls back to GEMINI_VISION_MODEL. |
confirm_send_to_gemini |
no | Must be true to actually send. Defaults to false. |
analyze_images_batch
Send 2–5 images in a single Gemini call (good for "compare these screenshots" or multi-page documents).
| Parameter | Required | Description |
|---|---|---|
image_sources |
yes | Array of 2–5 paths or URLs. Mixed is fine. |
prompt |
no | What to ask Gemini across all images. |
model |
no | Same as above. |
confirm_send_to_gemini |
no | Same handshake. |
If one image fails to load, the error message tells you which one
(第 N 张: …).
Install
git clone https://github.com/nianshou555qiansui/gemini-vision-mcp-safe.git
cd gemini-vision-mcp-safe
npm install
npm run build
cp .env.example .env # then edit .env, paste your Gemini API key
Get a key at https://aistudio.google.com/apikey.
Wire it up
Claude Code
~/.claude.json (or claude_desktop_config.json for Claude Desktop):
{
"mcpServers": {
"gemini-vision-safe": {
"type": "stdio",
"command": "node",
"args": [
"--env-file=/absolute/path/to/gemini-vision-mcp-safe/.env",
"/absolute/path/to/gemini-vision-mcp-safe/dist/index.js"
],
"env": {
"HTTPS_PROXY": "http://127.0.0.1:7890",
"HTTP_PROXY": "http://127.0.0.1:7890"
}
}
}
}
--env-file requires Node ≥ 20.6. The env block in MCP config is for
non-secret settings (proxy address); the API key lives in .env so it
never ends up in version control or shared configs.
On Windows where the launcher needs a shell, use cmd /c node … instead of
node ….
Configuration
.env keys (see .env.example):
| Key | Default | Notes |
|---|---|---|
GEMINI_API_KEY |
(required) | Your key from Google AI Studio. |
GEMINI_VISION_MODEL |
gemini-2.5-flash |
Default model. Per-call model arg overrides this. |
GEMINI_VISION_MAX_IMAGE_MB |
10 |
Hard cap. Remote images that exceed this via Content-Length are rejected before download; the streaming reader also enforces it. |
GEMINI_VISION_REQUEST_TIMEOUT_MS |
20000 |
Per-hop URL fetch timeout. |
GEMINI_VISION_GEMINI_TIMEOUT_MS |
60000 |
SDK-level timeout for the Gemini call. |
GEMINI_VISION_ALLOW_URL |
true |
Set false to refuse URL inputs entirely. |
GEMINI_VISION_ALLOW_LOCAL_FILE |
true |
Set false to refuse local file inputs. |
GEMINI_VISION_BLOCK_LOCAL_URLS |
true |
Set false to disable SSRF/private-IP blocking (not recommended). |
HTTPS_PROXY / HTTP_PROXY |
unset | Used by both fetch and the Gemini SDK via undici's global dispatcher. |
Privacy notes
- A local file path stays local; only the bytes of the file you confirm travel to Gemini.
- A URL is fetched from your machine first, then forwarded to Gemini — the original host sees your IP (or your proxy's), but never sees Google. Conversely Google never sees the original host.
- The repo never contains an API key. Verify before committing:
git ls-files | grep -F .envshould print nothing.
Caveats
- DNS rebinding / TOCTOU is not mitigated: the SSRF check uses the OS resolver, but the actual TCP connect resolves again. Acceptable for local use; not safe to expose this MCP as a public service.
- The OS resolver does not go through
HTTPS_PROXY. If your local DNS is unreliable, prefer URLs whose hostnames you've already pre-resolved or run a trusted DNS upstream. - Per-region Gemini availability is Google's decision. The error mapper will tell you when it sees 403 / 429 / 503.
License
MIT — see LICENSE.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。