Atlas / MCP servers / aigengame / godot-agent

godot-agentCAUTION

mcp/aigengame/godot-agent

Godot automation for AI agents to build and verify projects through a CLI, Agent Skill, or MCP server, with structured results, headless operations, and live runtime control.

Verdict
CAUTION
Grade
D
Trust score
68 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://aigengame.xyz/)

Read this in: 简体中文 · Español · 日本語

[](https://pypi.org/project/gda/) [](https://github.com/aigengame/godot-agent/actions/workflows/ci.yml?query=branch%3Amain+event%3Apush) [](https://www.python.org/) -478CBF) [](#how-it-works) [](https://modelcontextprotocol.io) [](LICENSE)

Build and verify Godot projects with AI coding agents, shell scripts, and CI. gda provides Godot automation with headless validation as well as live runtime inspection and control through a CLI, a bundled Agent Skill, or an MCP server, returning structured results agents can act on.

Two complementary modes cover this build-and-verify workflow:

  • Headless — create and edit project content, compile scripts, validate and boot

scenes, analyze project structure, and export builds without an editor plugin or daemon.

  • Live — inspect and drive the running game through a per-project daemon: runtime

tree and state, input simulation, frame capture, logs, errors, and performance.

Product overview · CLI, Agent Skill, or MCP? · Playable demos · PyPI

TL;DR

Just tel

Read from source at commit f2a216966cb3OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add gda --env GDA_BALANCING_ANCHOR_KEY=${GDA_BALANCING_ANCHOR_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} -- uvx gda
claude-desktop
{
  "mcpServers": {
    "gda": {
      "command": "uvx",
      "args": [
        "gda"
      ],
      "env": {
        "GDA_BALANCING_ANCHOR_KEY": "${GDA_BALANCING_ANCHOR_KEY}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
generate_imagereadNever returns in time — sleeps far past any reasonable acquire timeout.
04

Trust audit

CAUTIONgrade D · trust 68/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
src/gda/skill/SKILL.md
src/gda/skill/SKILL.md
Why it matters. link not followed
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
libs/gda-balancing/src/gda_balancing/interfaces/cli/serve.py:102
"base_url": "http://127.0.0.1:1",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/cli/test_dispatch.py:157
secret = "SECRET_MARKER_abcdefghijklmnopqrstuvwxyz0123456789_END"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/cli/test_dispatch.py:206
secret = "SECRET_MARKER_abcdefghijklmnopqrstuvwxyz0123456789_END"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
libs/gda-balancing/examples/schema2/playtest/docs/.gdignore
.gdignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
libs/gda-balancing/examples/schema2/playtest/tests/.gdignore
.gdignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
docs/adr/0043-headless-payload-splits-into-entry-groups-and-concept-modules.md
0043-headless-payload-splits-into-entry-groups-and-concept-modules.md
Why it matters. member named after an attack tool
Fix. remove or justify
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/cli/test_command_descriptor_registry.py:70
module = importlib.import_module(f"gda.commands.{info.name}")
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/cli/test_command_descriptor_registry.py:148
modules.append(importlib.import_module(f"gda.commands.{info.name}"))
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/gda/core/project/import_evidence.py:345
+ hashlib.md5(res_path.encode("utf-8")).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/gda/core/project/import_evidence.py:381
if hashlib.md5((project / rel).read_bytes()).hexdigest() != recorded_source:
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/gda/core/project/import_evidence.py:387
ctx = hashlib.md5()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/resource/import_artifacts.py:51
digest = hashlib.md5(f"res://{asset}".encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/resource/import_artifacts.py:57
digest = hashlib.md5((project / source_rel).read_bytes()).hexdigest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/export/test_export_smoke_operation.py:321
pytest.param("../../../../bin/echo", "a climbing path", id="dot-dot"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/project/test_e2e_project_walk.py:421
(deep / "c").symlink_to("../../.godot", target_is_directory=True)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/project/test_e2e_project_walk.py:422
(deep / "ci").symlink_to("../../.godot/imported", target_is_directory=True)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/project/test_e2e_project_walk.py:423
(deep / "f_alias.gd").symlink_to("../../.godot/root_cache.gd")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/project/test_project.py:434
("res://a/../../outside.gd", "../outside.gd"),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
libs/gda-balancing/examples/schema2/playtest/tests/test_gda_execution_client.gd:74
"base_url": "http://127.0.0.1:1",
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
libs/gda-balancing/src/gda_balancing/domain/publication.py:620
return bytes.fromhex(encoded)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
libs/gda-balancing/tests/test_schema2_model_cli.py:4347
bytes.fromhex(os.environ["GDA_BALANCING_ANCHOR_KEY"]),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
libs/gda-balancing/tests/test_schema2_model_cli.py:4390
bytes.fromhex(os.environ["GDA_BALANCING_ANCHOR_KEY"]),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/gda/commands/screen.py:799
raw = base64.b64decode(png_base64)

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f2a216966cb3full audit observations/trust-audit/mcp-server/aigengame__godot-agent.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f2a216966cb3CAUTIOND68first audit
06

Questions

What is the godot-agent MCP server?

Godot automation for AI agents to build and verify projects through a CLI, Agent Skill, or MCP server, with structured results, headless operations, and live runtime control.

What tools does godot-agent expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is godot-agent safe to connect to an agent?

With care. The audit graded it D (68/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does godot-agent need?

It reads GDA_BALANCING_ANCHOR_KEY and GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does godot-agent run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as gda.

How current is this page?

The grade is for one exact copy of the source (f2a216966cb3), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement