Definitive MCP server for Ableton Live: complete LOM coverage, embedded knowledge base and music recipes.
Sudomock is installed from its publisher's own source and answers where it runs, so this marketplace is not in the path of a single call. There is no address here to send one to, and a panel that pretended otherwise would be showing you an answer we made up. Install it and call it from your own client — the Installation tab has the entry for each one.
Open InstallationWhat it does
SudoMock MCP server for Claude, Cursor, and VS Code. Generate photorealistic product mockups from Photoshop PSD templates.
Quickstart
# 1 — run it from where its publisher ships it
npx -y @sudomock/mcp
# 2 — the plan is chosen at checkout, in the browser
# 3 — ask your agent something
> SudoMock MCP server for Claude, Cursor, and VS Code. Generate photorealistic product mockups from Photoshop PSD templates.
Collected from a public index. Nobody has claimed this account, so nothing here was written by its author — claim it if it is yours.
Where are you running it?
Every route below installs the same thing and ends at the same approval screen. This one runs on your machine: your client starts Sudomock as a process under your own user, with your files and your network, so the tool surface below is what it can do to your computer rather than to a server somewhere else. It is scanned, signed and pinned to the version you choose — read the surface before you approve it.
This is a public server: you run it yourself and this marketplace is not in the path. Claude Code registers it in one command.
claude mcp add sudomock-mcp -- npx -y @sudomock/mcpReconnect, or start a new session, and the tools appear in the model’s tool list.
It reaches a system of yours, so it needs your own credential rather than the publisher’s: SUDOMOCK_API_KEY. You set it after installing; the value is sealed here and sent to the server on each call.
One config entry your client uses to start the process locally. A local server runs with your file system and your network, which is why it is priced without metering.
28 tools, with what each one reads, writes and reaches shown before you agree — the same list on every route above. Read the tool surface.
Tool surface
What the model actually sees. Descriptions are diffed on every release — see version history.
List your uploaded mockup templates with UUIDs, names, and thumbnails. Use returned UUIDs with render_mockup or get_mockup_details.
Takes no parameters.
Get full details of a mockup: smart object UUIDs, layer names, dimensions, positions, blend modes, and thumbnail URLs.
Takes no parameters.
Rename a mockup template.
Takes no parameters.
Permanently delete a mockup template. Cannot be undone.
Takes no parameters.
Render a PSD mockup with artwork, editable text, or both. Supports one or multiple smart objects and preserves the template
Takes no parameters.
Remove the background from any image and return a transparent-PNG cutout with clean, production-ready edges. The returned URL is valid for 7 days and can be used as artwork_url during that window. Costs 25 credits per image; credits are refunded automatically if processing fails.
Takes no parameters.
Takes no parameters.
Render artwork across a whole product surface -- an all-over print. Every printable product in the photo is a surface with its own surface_uuid, listed by get_2d_mockup. Returns print_files (each with an export_path) and a render_uuid. Costs 5 credits. Use the dashboard for visual fine-tuning.
Takes no parameters.
Render artwork onto one saved print area -- a bounded zone somebody drew on the product, such as a chest logo. Read the print_area_id values from get_2d_mockup. Returns print_files (each with an export_path) and a render_uuid. Costs 5 credits. Use the dashboard for visual fine-tuning.
Takes no parameters.
List your saved SudoAI 2D mockup templates (no PSD). Returns each mockup
Takes no parameters.
Get one SudoAI 2D mockup
Takes no parameters.
Replace a 2D mockup
Takes no parameters.
Permanently delete a SudoAI 2D mockup template and all of its data. Cannot be undone. Costs 0 credits.
Takes no parameters.
Upload a Photoshop PSD/PSB file as a new mockup template. The PSD must have at least one Smart Object layer. Processing takes 5-30 seconds.
Takes no parameters.
Get the current status of any async render, video, upload, or 2D job by its job_id. Returns status (queued|running|succeeded|failed), completed-result details and credits charged, or an error if failed. To block until done, use wait_for_job instead.
Takes no parameters.
List your async jobs, including PSD renders, videos, uploads, and 2D creation/renders, newest first. Use this when you do not already hold a job_id. Pass the returned next_cursor to fetch the next page.
Takes no parameters.
Poll any async render, video, upload, or 2D job until it succeeds or fails, then return the final result and credits charged. Blocks while polling.
Takes no parameters.
Takes no parameters.
Takes no parameters.
Register a webhook endpoint that SudoMock calls when async jobs finish. The signing secret is returned IN FULL exactly once here -- store it to verify the HMAC carried in the X-SudoMock-Signature header (with X-SudoMock-Timestamp) on incoming deliveries. URL must be https and publicly routable.
Takes no parameters.
List your registered webhook endpoints (id, url, subscribed event_types, enabled state). Secrets are NOT returned here -- only at creation and rotation.
Takes no parameters.
Update a webhook endpoint in place: change its url, description, subscribed event_types, or enable/disable it (enabled:false pauses deliveries without losing the signing secret). All fields optional -- only the ones you pass are changed. The secret is NOT rotated or returned here.
Takes no parameters.
Permanently delete a webhook endpoint. SudoMock stops delivering to it. Cannot be undone.
Takes no parameters.
Rotate the signing secret for a webhook endpoint. A new secret is returned IN FULL exactly once -- update your verifier with it. The old secret stops being valid.
Takes no parameters.
Send a signed webhook.test event to verify endpoint reachability and signature handling. Returns a test job_id; check the result with list_webhook_deliveries.
Takes no parameters.
List delivery attempts for a webhook endpoint (status, event_type, response code, timestamps). Use this to debug failed deliveries before replaying them.
Takes no parameters.
Replay a single webhook delivery while preserving its event identity, e.g. after fixing your endpoint. Get delivery_id from list_webhook_deliveries.
Takes no parameters.
Upload a file from this machine and get back a URL for it. Use this when the file exists on disk and a tool needs a URL: pass the returned file_url as psd_file_url to upload_psd, or as artwork_url to any render tool. Set kind to \
Takes no parameters.
- 25,000 calls a month, included
- 300 calls a minute at peak
- Every tool the listing has
- Cancel any time — the unused days are credited
- Runs behind the gateway, so cancelling stops it
- 200,000 calls a month, included
- 2,400 calls a minute at peak
- Every tool the listing has
- Cancel any time — the unused days are credited
- Runs behind the gateway, so cancelling stops it
What counts against your monthly calls
| Tool | Unit | Calls used | Out of the allowance |
|---|
No call is billed on its own, and this plan carries no monthly call limit. $29 a month covers every tool at any volume.
Two independent axes, because powerful and malicious are different questions. The grade is threat only. The capability level is blast radius, and it is never a penalty on the grade — it is priced as one subtract-only term in the score, where you can see it.
| Term | Level | What it prices | Points |
|---|---|---|---|
| capability-exposure | moderate | capability blast radius (moderate) — client exposure if the model is manipulated | −3 |
| verification-discount | source | publisher verification (provenance) — cryptographic build provenance ties the artifact to its source | −0 |
| coverage-honesty | source | inspection depth (source) — how much of the target the scan could see | −0 |
What the scan could actually read
A grade is only as meaningful as its coverage, so the scanner publishes its own depth before it publishes its result.
Tools were statically extracted from the published source (28 recovered), not enumerated from a running server. Tool-poisoning, Unicode-smuggling, capability and toxic-flow analysis ran on this inferred surface, but a mis-parsed registration could be missed or mis-attributed, so tool-derived findings are capped below “confirmed”. To grade the real runtime surface, scan the running server: --command "npx -y <package>".
Capability — what it could do if the model were manipulated
Tags derived from each tool’s schema and the implementation, not from what the tool calls itself. moderate is the level these add up to.
| Tool | Capability tags | Why the tag was assigned |
|---|---|---|
| list_mockups | no tags | |
| get_mockup_details | no tags | |
| update_mockup | no tags | |
| delete_mockup | no tags | |
| render_mockup | no tags | |
| remove_background | no tags | |
| create_2d_mockup | no tags | |
| render_2d_surface | no tags | |
| render_2d_print_area | no tags | |
| list_2d_mockups | no tags | |
| get_2d_mockup | no tags | |
| update_2d_print_areas | no tags | |
| delete_2d_mockup | no tags | |
| upload_psd | no tags | |
| get_job | no tags | |
| list_jobs | untrusted-input | |
| wait_for_job | no tags | |
| render_video | no tags | |
| get_account | no tags | |
| create_webhook_endpoint | external-sink | |
| list_webhook_endpoints | no tags | |
| update_webhook_endpoint | external-sink | |
| delete_webhook_endpoint | external-sink | |
| rotate_webhook_secret | external-sink | |
| test_webhook_endpoint | external-sink | |
| list_webhook_deliveries | no tags | |
| replay_webhook_delivery | external-sink | |
| upload_local_file | no tags |
Toxic-flow graph
The lethal trifecta, checked as a graph rather than as a checklist: untrusted input, a sensitive source and an external sink have to meet before there is a path worth worrying about.
Supply chain and provenance
This is the first scan of this surface here, so there is nothing yet to compare it against.
Every result on this tab comes from one deterministic pass over the published package — offline, rule by rule, and auditable line by line above. Same methodology version, same bytes, same score.
Release history
Pinned to 2.7.0 — the install command below asks for that release. A pin is part of an install, so it is kept for this visit and written down when you install.
No release note was published with this version.
Only accounts with at least 50 real tool calls against this server in the last 90 days can post. Ratings are weighted by how much the reviewer actually uses it, and publishers can reply once per review.
Writing one takes an account with at least 50 real tool calls against Sudomock in the last 90 days. That is the whole gate — there is no other way to post, which is why the counts beside each review are worth reading.
Nobody has reviewed this listing. The rating on the card is the mean of the reviews written here and nothing else, so there is no rating until somebody writes the first — which takes an account with 50 real tool calls against it.