Back to Home
pasie15 icon

tripo-ai-mcp-server

by pasie15

Overview

Facilitate AI assistant interaction with Tripo3D AI API for 3D model generation, animation, and stylization.

Installation

Run Command
tripo-ai-mcp-server

Environment Variables

  • TRIPO_API_SECRET

Security Notes

CRITICAL VULNERABILITY: The `upload_file` tool (and implicitly `image_to_3d`, `multiview_to_3d` which auto-upload local files) accepts a `file_path` (or `image_path`, `files[].path`) directly from the AI model's arguments. This path is then used without sanitization or restriction in `fs.createReadStream()`. An attacker controlling the AI model's input could exploit this to perform an Arbitrary File Read (CWE-22), exfiltrating sensitive files (e.g., `/etc/passwd`, environment variables, API keys if stored on disk) from the server's host system. This is a severe security risk.

Similar Servers

Stats

Interest Score0
Security Score2
Cost ClassLow
Avg Tokens300
Stars0
Forks0
Last Update2025-11-22

Tags

Tripo3D3D GenerationAIMCP ServerModel Context Protocol