MCP server for generating images using Gemini, supporting multiple aspect ratios and both AI Studio and Vertex AI backends.
SaferSkills independently audited organon-create-image (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for image generation using Gemini.
gemini-3-pro-image-preview)npm install
npm run build| Variable | Required | Default | Description |
|---|---|---|---|
GEMINI_API_KEY | Option 1 | — | AI Studio API key (takes priority over Vertex AI) |
VERTEX_PROJECT | Option 2 | — | Google Cloud project ID (Vertex AI) |
VERTEX_LOCATION | No | us-central1 | Vertex AI location |
Note: Set eitherGEMINI_API_KEYorVERTEX_PROJECT. If both are set,GEMINI_API_KEYtakes priority.
AI Studio (recommended for access to preview models):
{
"mcpServers": {
"create-image": {
"command": "node",
"args": ["/path/to/organon-create-image/dist/index.js"],
"env": {
"GEMINI_API_KEY": "your-api-key"
}
}
}
}Vertex AI:
{
"mcpServers": {
"create-image": {
"command": "node",
"args": ["/path/to/organon-create-image/dist/index.js"],
"env": {
"VERTEX_PROJECT": "your-gcp-project-id"
}
}
}
}generate_imageGenerate an image from a text prompt.
Parameters:
| Parameter | Type | Required | Default | Description |
|---|---|---|---|---|
prompt | string | Yes | — | Text prompt for image generation (English recommended) |
aspect_ratio | enum | No | "1:1" | Aspect ratio: 1:1, 3:2, 2:3, 3:4, 4:3, 4:5, 5:4, 9:16, 16:9, 21:9 |
output_path | string | Yes | — | File path to save the generated image (.png) |
model | string | No | "gemini-3-pro-image-preview" | Gemini model name (e.g. gemini-2.5-flash-image) |
Returns: Generated image saved to output_path, plus inline image via MCP image content type.
Run all quality checks at once:
npm run check:allThis executes the following checks in sequence:
| Script | Check | Tool |
|---|---|---|
typecheck | Type checking (strict) | tsc --noEmit |
lint | Linter + cyclomatic complexity | ESLint + typescript-eslint |
format:check | Code formatting | Prettier |
test:coverage | Tests + coverage report | Vitest + V8 |
audit | Known CVE scan | npm audit |
audit:lockfile | Lockfile integrity | lockfile-lint |
sast | Security static analysis | Semgrep |
Note: Semgrep requires a separate installation via pip. See QUALITY.md for setup details.MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.