Atlas / MCP servers / adambdooley / Foundry VTT Bridge

Foundry VTT BridgeCAUTION

mcp/adambdooley/foundry-vtt-bridge

An MCP (Model Context Protocol) server that bridges Foundry VTT data with Claude Desktop, enabling users to chat with their game world data using their own Claude subscription.

Verdict
CAUTION
Grade
C
Trust score
80 /100
Exposed tools
45 23r · 16w · 6d
Transport
stdio
License
NOASSERTION
Stars
72
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Connect Foundry VTT to Claude Desktop for AI-powered campaign management through the Model Context Protocol (MCP). It currently supports Dungeons and Dragons Fifth Edition, Pathfinder Second Edition, Das Schwarze Augen Fifth Edition, Cosmere RPG System, Warhammer Fantasy Roleplay 4th Edition, & Mongoose Traveller 2nd Edition. The majority of MCP tools are system agnostic or have features that are aware of the system it is working with, excluding some DSA 5 specific tools.

Overview

The Foundry MCP Bridge enables natural AI conversations with your Foundry VTT game data:

  • Quest Creation: Create quests from prompts that incorporate what exists in your world and journals
  • Character Management: Query character stats, abilities, and information
  • Compendium Search: Find items, spells, and creatures using natural language
  • Content Creation: Generate actors, NPCs, and quest journals from simple prompts
  • Scene Information: Access current scene data and world details
  • Dice Coordination: Interactive roll requests with player targeting
  • Campaign Management: Multi-part quest and campaign tracking
  • Map Generation: Create maps from prompts and automatically upload them into scenes in Foundry VTT using the optional ComfyUI component

Installation

Prerequisites

  • Foundry VTT v13 or v14
  • Claude Desktop with MCP support
  • Windows (for automated installer) or Node.js 18+ for manual installation

Option 1: Windows Installer

Video guide for Windows Installer

  1. Download the latest FoundryMCPServer-Setup-vx.x.x.exe from Releases
  2. Run the installer - it will:
  3. Install the MCP server with bundled Node.js runtime
  4. Configure the Claude Desktop MCP server settings
  5. Optionally install the Foundry module and ComfyUI Map Generation to your VTT i
Read from source at commit 09c9c8d1f759OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add shared --env FOUNDRY_REJECT_UNAUTHORIZED=${FOUNDRY_REJECT_UNAUTHORIZED} -- npx -y @foundry-mcp/[email protected]
claude-desktop
{
  "mcpServers": {
    "shared": {
      "command": "npx",
      "args": [
        "-y",
        "@foundry-mcp/[email protected]"
      ],
      "env": {
        "FOUNDRY_REJECT_UNAUTHORIZED": "${FOUNDRY_REJECT_UNAUTHORIZED}"
      }
    }
  }
}
03

Exposed tools (45)

23 read · 16 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
assign-actor-ownershipreadAssign ownership permissions for actors to players. Supports individual assignments like
cancel-map-jobreadCancel a running map generation job
check-mac-setup-statusreadCheck if ComfyUI and AI models are installed on Mac (Apple Silicon only). Returns installation status and whether system can run AI map generation.
check-map-statusreadCheck status of map generation job. Progress updates appear automatically in Foundry VTT. DO NOT check frequently - this wastes tokens. Only check if user explicitly asks for status.
control-playlistwritePlayback control for playlists and their sounds: play (playAll), stop (stopAll), cycle-mode (sequential -> shuffle -> soundboard), play-sound, stop-sound. Playlist and sound accept ids or unique names.
create-actor-from-compendiumwriteCreate one or more actors from a specific compendium entry with custom names. Use search-compendium first to find the exact creature you want, then use this tool with the packId and itemId from the search results.
create-campaign-dashboardwriteCreate a comprehensive campaign dashboard journal with navigation, progress tracking, and part management
create-dsa5-character-from-archetypewriteCreate a DSA5 character from an archetype (e.g., Allacaya, Wulfgrimm). Allows customization of name, age, biography, and other details. Use search-compendium first to find available archetypes in DSA5 character packs.
create-quest-journalwriteCreate a new quest journal entry with AI-generated content based on natural language description
delete-tokensdestructiveDelete one or more tokens from the current scene
dnd5e-add-featurewrite[D&D 5e only] Add a feature, attack, spellcasting setup, or spells to an existing actor.
dnd5e-add-features-from-compendiumwrite[D&D 5e only] Import class features and monster features from an official compendium
dnd5e-create-npcwrite[D&D 5e only] Create a new NPC actor from scratch with a full Level-2 stat block:
generate-mapwriteStart AI map generation using D&D Battlemaps SDXL (async)
get-available-conditionsreadGet a list of all available status effects/conditions that can be applied to tokens in the current game system
get-compendium-entry-fullreadRetrieve complete stat block data including items, spells, and abilities for actor creation
get-compendium-itemreadRetrieve detailed information about a specific compendium item. Use compact mode for UI performance when full details are not needed.
get-current-scenereadGet information about the currently active scene, including tokens, layout, and the music binding (playlist + playlistSound)
get-mac-setup-progresswriteGet current progress of Mac setup (if running). Shows download progress, installation stage, and any errors.
get-token-detailsreadGet detailed information about a specific token including all properties and linked actor data
get-world-inforeadGet basic information about the Foundry world and system
link-quest-to-npcreadLink an existing quest journal to an NPC in the world
list-actor-ownershipreadList current ownership permissions for actors, showing which players have what access levels.
list-charactersreadList all available characters with basic information
list-compendium-packsreadList all available compendium packs
list-dsa5-archetypesreadList available DSA5 character archetypes from compendium packs. Helps users discover available templates for character creation.
list-journalsreadList all journal entries, or read a specific journal/page. Without parameters: lists all journals with their pages (id, name, type). With journalId: reads the journal
list-scenesreadList all available Foundry VTT scenes with their details, including the music binding (playlist + playlistSound) for each scene
manage-actorsdestructiveCreate, update, or delete Actor documents in Foundry VTT. Works with any game system.\n
manage-effectsdestructiveCreate, update, or delete an ActiveEffect on an Actor or on an embedded Item owned by that Actor. Effect payloads are generic Foundry ActiveEffect document data. Use parentType
manage-world-itemsreadManage Item documents in Foundry VTT. Specify the operation with
move-tokenwriteMove a token to a new position on the current scene. Can optionally animate the movement.
remove-actor-ownershipdestructiveRemove ownership permissions (set to NONE) for specific actors and players. Equivalent to
replace-journal-pagedestructiveReplace the ENTIRE content of a specific journal page. Use this to overwrite/rewrite a page. For appending progress, use update-quest-journal instead.
request-player-rollsreadRequest dice rolls from players with interactive buttons. Creates roll buttons in Foundry chat that players can click. VISIBILITY WORKFLOW: Before calling this function, ensure the user has specified whether they want a public or private roll. If they have already specified
run-mac-setupwriteAuto-install ComfyUI Desktop and SDXL model on Mac (Apple Silicon only). Downloads ~2.7GB total. Use this when user wants to enable AI map generation on Mac.
search-character-itemsreadSearch within a character
search-journalsreadSearch through all pages of all journal entries for specific content or keywords. Returns which specific page matched, so you can read it with list-journals using journalId + pageId.
switch-scenereadSwitch to a different Foundry VTT scene by name or ID
toggle-token-conditionwriteToggle a status effect/condition on or off for a token. Use this to apply or remove conditions like Prone, Poisoned, Blinded, etc.
update-scene-musicdestructiveSet or clear the music binding of a scene. Pass playlist and optionally playlist_sound (ids or unique names, null to clear). Writes through the scene document API and syncs live to connected clients.
update-tokenwriteUpdate various properties of a token such as visibility, disposition, size, rotation, elevation, or name
use-itemreadUse an item on a character (cast spell, use ability, activate feature, consume item). Opens the item dialog in Foundry VTT for the GM to configure options and confirm. Optionally specify targets by name. Returns immediately with status
wfrp4e-add-itemswrite[WFRP4e only] Add skills, talents, traits, trappings, careers, weapons, spells and
wfrp4e-update-actorwrite[WFRP4e only] Update an existing actor
04

Trust audit

CAUTIONgrade C · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (20)

MEDIUMInventory / provenance · inv.binary · CWE-1104
installer/inetc_plugin/x64-ansi/INetC.dll
INetC.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
installer/inetc_plugin/x64-unicode/INetC.dll
INetC.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
installer/inetc_plugin/x86-ansi/INetC.dll
INetC.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
installer/inetc_plugin/x86-unicode/INetC.dll
INetC.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
installer/nsis/7zr.exe
7zr.exe
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-server/src/backend.ts:333
const response = await fetch('http://127.0.0.1:31411/system_stats', {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-server/src/backend.ts:511
const response = await fetch('http://127.0.0.1:31411/system_stats', {
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-tokens, manage-actors, manage-effects, remove-actor-ownership, replace-journal-page, update-scene-music
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/mcp-server/src/systems/dsa5/normalize-payload.test.ts
normalize-payload.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/build-complete-release.yml:411
zip -r ../../foundry-vtt-mcp.zip . -x ".*" -x "node_modules/*"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/foundry-module-release.yml:17
zip -r ../../foundry-vtt-mcp.zip . -x ".*" -x "node_modules/*"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/systems/dsa5/character-creator.ts:2
import { FoundryClient } from '../../foundry-client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/systems/dsa5/character-creator.ts:3
import { Logger } from '../../logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/systems/dsa5/character-creator.ts:4
import { ErrorHandler } from '../../utils/error-handler.js';
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
packages/foundry-module/src/queries.ts:1354
const byteCharacters = atob(data.imageData);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@primno/dpapi, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, esbuild-analyzer, eslint, eslint-config-prettier, eslint-plugin-prettier
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/foundry-module/package.json
socket.io-client, @types/node, typescript, @league-of-foundry-developers/foundry-vtt-types
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp-server/package.json
@foundry-mcp/shared, @modelcontextprotocol/sdk, axios, dotenv, ws, werift, winston, zod
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
shared/package.json
zod, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 09c9c8d1f759full audit observations/trust-audit/mcp-server/adambdooley__foundry-vtt-bridge.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0709c9c8d1f759CAUTIONC80first audit
06

Questions

What is the Foundry VTT Bridge MCP server?

An MCP (Model Context Protocol) server that bridges Foundry VTT data with Claude Desktop, enabling users to chat with their game world data using their own Claude subscription.

What tools does Foundry VTT Bridge expose?

45 in total: 23 read-only, 16 that write, and 6 that can delete or overwrite (delete-tokens, manage-actors, manage-effects, remove-actor-ownership, replace-journal-page). Every one is listed on this page with its risk.

Is Foundry VTT Bridge safe to connect to an agent?

With care. The audit graded it C (80/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Foundry VTT Bridge need?

It reads FOUNDRY_REJECT_UNAUTHORIZED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Foundry VTT Bridge run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @foundry-mcp/shared at 0.8.4.

How current is this page?

The grade is for one exact copy of the source (09c9c8d1f759), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement