# FindMe Photo (npm · findme-mcp)

Create wedding galleries, upload photos, and pull analytics on FindMe Photo from any AI assistant.

- Trust score: 67/100 (medium)
- Change this week: +42
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-04

## Components

- npm · `findme-mcp`: 67/100 (this document), [markdown](https://verifymcp.io/servers/findmephoto-findme-mcp/findme-mcp.md), [page](https://verifymcp.io/servers/findmephoto-findme-mcp/findme-mcp)

## Channel facts

- Registry: `npm`
- Package: `findme-mcp`
- Version: `0.7.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-04.

- **Supply Chain Security**: 83/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (127 of 131), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 42 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 70/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2454 tokens (~175/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 30/100
  - Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 91/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 73% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add findmephoto-findme-mcp -- npx -y findme-mcp
```

### Codex

```bash
codex mcp add findmephoto-findme-mcp -- npx -y findme-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "findmephoto-findme-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "findme-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add findmephoto-findme-mcp --command npx --arg -y --arg findme-mcp
```

### Hermes

```yaml
mcp_servers:
  findmephoto-findme-mcp:
    command: "npx"
    args: ["-y", "findme-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "findmephoto-findme-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "findme-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-04 (score 67, 0)

- [security regression] CVE-2026-69207 affects this package: medium
- [security regression] Known CVEs: partial → fail

### 2026-08-03 (score 67, +4)

- [functional improvement] Stability: unverified → 0.27

### 2026-08-02 (score 63, +40)

- [security regression] Provenance: unverified → fail
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Install scripts: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional regression] Capabilities: pass → unverified
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] License: unverified → pass
- [functional improvement] Schema quality: unverified → excellent
- [functional improvement] Maintenance: unverified → pass
- [functional] Licence: MIT

### 2026-08-01 (score 23, +5)

- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] MCP protocol: unverified → pass

### 2026-07-31 (score 18, −6)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 24, −1)

- [security regression] Malware scan: pass → unverified
- [functional regression] Dependency health: partial → unverified
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: unverified
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 73

### 2026-07-28 (score 25, +1)

- [functional improvement] Dependency health: unverified → partial

### 2026-07-27 (score 24)

First indexed and scored.

## MCP tools (14)

### `get_account_info` (~147 tokens)

Confirm which FindMe account and Google Drive connection this MCP session is operating on. Returns the FindMe email, plan tier, active event count, and the Google email that Drive is connected with (or null if not connected). ALWAYS call this once at the start of any conversation that involves listing events, uploading photos, importing from Drive, or any account-scoped action — and surface the result to the photographer in one short sentence so they can confirm or correct before any action is taken. If the FindMe email and the Drive Google email differ, name both explicitly. If Drive is not connected and the user asks to import, point them at https://findme.photo/profile to connect it.

### `get_upload_link` (~187 tokens)

Get a no-login "tap-to-upload" link for an event. Returns a URL the photographer opens on any device (phone or computer) to upload photos through the browser's native picker — no account or login required. THIS IS THE WAY TO UPLOAD when you can't read the photographer's local files (i.e. always, in ChatGPT and in Claude web/mobile — anywhere except a locally-installed Claude Desktop with the findme-mcp filesystem tool). When the photographer asks to add or upload photos, call this, then give them the link and tell them to tap it and pick their photos. The link is reusable and scoped to this one event; photos are resized to the album's quality automatically. FindMe has a playful, confident voice — hand over the link with a short, specific one-liner.

Input parameters:

- `event_id` (string, required): UUID of the event to upload to.

### `upload_photos_from_paths` (~280 tokens)

Upload photos or videos from local file paths on the photographer's computer to a FindMe event. Each path can be a file, a directory (all supported files inside are uploaded), or a glob (basic). Supported formats: .jpg .jpeg .png .webp .mp4 .mov .webm. Max 50 files per call; auto-chunks if more are found. Max size per file: 50 MB for photos, 500 MB for videos. Photos are automatically resized to the album's storage quality before upload (full-size albums keep originals). This is the primary upload tool — prefer it when the photographer says things like "upload all photos in ~/Pictures/Sarah" or "add these files to the Johnson event". On success the response includes rich stats (duration, size, photo/video counts, faces indexing). FindMe has a playful, confident voice — present completions with a specific, upbeat one-liner that cites real numbers. Do not use the same phrasing twice.

Input parameters:

- `event_id` (string, required): UUID of the target event.
- `paths` (array, required): File paths or directory paths. `~` expansion supported. Directories upload all supported files inside (non-recursive by default).
- `recursive` (boolean): If true, recurse into subdirectories (max depth 10). Default false.

### `upload_photos_from_urls` (~153 tokens)

Upload photos/videos from public URLs to a FindMe event. Useful when the photographer shares Dropbox links, direct Drive download URLs, or similar. The MCP server downloads each URL to a temp buffer and streams it to the event. Photos are automatically resized to the album's storage quality before upload (full-size albums keep originals). Max 50 URLs per call. On success the response includes rich stats (duration, size, photo/video counts). FindMe has a playful, confident voice — celebrate completions with a specific, upbeat one-liner that cites real numbers. Do not use the same phrasing twice.

Input parameters:

- `event_id` (string, required)
- `urls` (array, required): Public URLs returning image/video bytes.

### `upload_photos_from_drive_folder` (~152 tokens)

Attempt to import photos from a Google Drive folder. IMPORTANT: this is not supported in chat-based AI assistants because Google's drive.file scope (the only Drive scope FindMe is verified for) does not allow apps to list folder contents. The tool always returns a redirect message pointing the photographer at the FindMe web app, where the Google Picker handles authorization in one click. Surface the message verbatim — do not retry or guess folder contents.

Input parameters:

- `event_id` (string)
- `folder_id` (string): Google Drive folder ID (optional, ignored).
- `folder_name` (string): Optional folder name for display.
- `folder_url` (string): Google Drive folder URL (optional, ignored).

### `create_event` (~462 tokens)

Create a new FindMe event (a wedding/photo gallery). Returns the event id, a shareable access code, and gallery + QR URLs. Use when the photographer says things like "create an event for Sarah & Mike on April 22" or "make a new gallery called Johnson Wedding". CRITICAL — three album settings are user preferences: album_quality (storage resolution; tier-capped), enable_downloads (guest downloads on/off), is_collaborative (others can upload). DO NOT guess, infer, or fill in defaults for these three fields yourself — you have no way to know what the photographer prefers. On the FIRST call, omit all three of these fields (only pass name + optional date/description/tag). The tool will respond with either an interactive form (clients with elicitation support) or a structured needs_input JSON listing tier-allowed options and recommended defaults — surface those options to the photographer as a numbered multiple-choice list, never as an open-ended question, and wait for their answer. Only then call create_event again with the photographer's chosen values. The only exception: if the photographer explicitly states a preference in their initial message (e.g. "make it collaborative" or "use 4000px quality"), you may include those specific stated preferences. FindMe has a playful, confident voice — when the event is created, give a short upbeat reaction that names the gallery and its access code, and mention the album_quality (e.g. "stored at 4000px, your plan's top setting"). Do not use the same phrasing twice.

Input parameters:

- `album_quality` (string): Storage resolution. Tier-capped — call without this and the tool will return your allowed options.
- `description` (string): Optional description.
- `enable_downloads` (boolean): Whether guests can download photos from the gallery.
- `event_date` (string): Event date in YYYY-MM-DD format. Optional.
- `is_collaborative` (boolean): Whether the album is shareable/collaborative — other people can upload photos to it.
- `name` (string, required): Event name, e.g. "Sarah & Mike Wedding"
- `tag` (string): Optional tag/category (e.g. "wedding", "corporate").

### `list_events` (~93 tokens)

List the photographer's events, most recent first. Returns up to 20 by default; use `cursor` for pagination. Filter with `created_after` (ISO date) to only show recent events.

Input parameters:

- `created_after` (string): ISO datetime. Only show events created after this.
- `cursor` (string): Pagination cursor from a previous response.
- `limit` (integer): Max 100. Default 20.

### `get_event` (~60 tokens)

Get full details for one event — includes stats: photo_count, video_count, total storage, guest visits, selfie searches. Use when the photographer asks about the status or stats of a specific gallery.

Input parameters:

- `event_id` (string, required): UUID of the event.

### `update_event` (~269 tokens)

Update fields on an existing event: name, event_date, description, tag, access_code, album_quality (storage resolution; changeable only before the first photo is uploaded, and tier-capped), enable_downloads (toggle guest downloads on/off), or is_collaborative (toggle whether other people can upload). Only include the fields you want to change. Use when the photographer wants to rename, re-date, re-code, change quality (pre-upload), or flip the downloads/collaborative toggles. If the photographer asks to change album_quality on an album that already has photos, the API will return a `conflict` error — relay that politely and explain they'd need to delete photos first.

Input parameters:

- `access_code` (string): 4-12 uppercase alphanumeric characters
- `album_quality` (string): Storage resolution. Changeable only before the first photo is uploaded; tier-capped.
- `description` (string|null)
- `enable_downloads` (boolean): Whether guests can download photos.
- `event_date` (string|null): YYYY-MM-DD or null to clear
- `event_id` (string, required)
- `is_collaborative` (boolean): Whether other people can upload to this album.
- `name` (string)
- `tag` (string|null)

### `delete_event` (~66 tokens)

Soft-delete an event. The event is hidden immediately and photos stop appearing in the gallery, but the data is kept for 7 days so it can be restored with restore_event if needed. After 7 days, the data is permanently purged.

Input parameters:

- `event_id` (string, required)

### `restore_event` (~46 tokens)

Restore a soft-deleted event within the 7-day recovery window. Fails if the event is already active or past the 7-day cutoff.

Input parameters:

- `event_id` (string, required)

### `get_event_qr` (~77 tokens)

Get a QR code image (PNG) for an event's public gallery URL. Returns the image so the AI can display it to the photographer or save it. Useful for printing signage at events.

Input parameters:

- `event_id` (string, required)
- `size` (integer): Pixel size per side (128-2048). Default 512.

### `get_event_analytics` (~98 tokens)

Get aggregated analytics for an event: guest visits, unique visitors, photos downloaded, selfie searches, and per-day breakdown. Default window is event creation to now. Use when the photographer asks things like "how many people viewed the Johnson wedding?" or "what was the download count?"

Input parameters:

- `event_id` (string, required)
- `from` (string): YYYY-MM-DD start date
- `to` (string): YYYY-MM-DD end date

### `get_usage` (~58 tokens)

Get the current-month usage for your FindMe account: API requests used/limit, rate limit per minute, storage used/limit, and active event count. Use when the photographer asks about their usage, quota, remaining requests, or plan limits.

## Diagnostics

Captured diagnostic sections: Provenance, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/findmephoto-findme-mcp/findme-mcp#diagnostics

## Score history

- 2026-08-04: 67
- 2026-08-03: 67
- 2026-08-02: 63
- 2026-08-01: 23
- 2026-07-31: 18
- 2026-07-30: 24
- 2026-07-28: 25
- 2026-07-27: 24

## Links

- npm package: https://www.npmjs.com/package/findme-mcp
- Socket report: https://socket.dev/npm/package/findme-mcp
- Repository: https://github.com/findmephoto/findme-mcp
- Website: https://findme.photo/
- Changelog RSS feed: https://verifymcp.io/servers/findmephoto-findme-mcp/findme-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/findmephoto-findme-mcp/findme-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/findmephoto-findme-mcp/findme-mcp
