godot-agentCAUTION
Godot automation for AI agents to build and verify projects through a CLI, Agent Skill, or MCP server, with structured results, headless operations, and live runtime control.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://aigengame.xyz/)
Read this in: 简体中文 · Español · 日本語
[](https://pypi.org/project/gda/) [](https://github.com/aigengame/godot-agent/actions/workflows/ci.yml?query=branch%3Amain+event%3Apush) [](https://www.python.org/) -478CBF) [](#how-it-works) [](https://modelcontextprotocol.io) [](LICENSE)
Build and verify Godot projects with AI coding agents, shell scripts, and CI. gda provides Godot automation with headless validation as well as live runtime inspection and control through a CLI, a bundled Agent Skill, or an MCP server, returning structured results agents can act on.
Two complementary modes cover this build-and-verify workflow:
- Headless — create and edit project content, compile scripts, validate and boot
scenes, analyze project structure, and export builds without an editor plugin or daemon.
- Live — inspect and drive the running game through a per-project daemon: runtime
tree and state, input simulation, frame capture, logs, errors, and performance.
Product overview · CLI, Agent Skill, or MCP? · Playable demos · PyPI
TL;DR
Just tel
f2a216966cb3OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add gda --env GDA_BALANCING_ANCHOR_KEY=${GDA_BALANCING_ANCHOR_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} -- uvx gda{
"mcpServers": {
"gda": {
"command": "uvx",
"args": [
"gda"
],
"env": {
"GDA_BALANCING_ANCHOR_KEY": "${GDA_BALANCING_ANCHOR_KEY}",
"GEMINI_API_KEY": "${GEMINI_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
generate_image | read | Never returns in time — sleeps far past any reasonable acquire timeout. |
Trust audit
CAUTIONgrade D · trust 68/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
src/gda/skill/SKILL.md
"base_url": "http://127.0.0.1:1",
secret = "SECRET_MARKER_abcdefghijklmnopqrstuvwxyz0123456789_END"
secret = "SECRET_MARKER_abcdefghijklmnopqrstuvwxyz0123456789_END"
.release-please-manifest.json
.gdignore
.gdignore
0043-headless-payload-splits-into-entry-groups-and-concept-modules.md
module = importlib.import_module(f"gda.commands.{info.name}")modules.append(importlib.import_module(f"gda.commands.{info.name}"))+ hashlib.md5(res_path.encode("utf-8")).hexdigest()if hashlib.md5((project / rel).read_bytes()).hexdigest() != recorded_source:
ctx = hashlib.md5()
digest = hashlib.md5(f"res://{asset}".encode()).hexdigest()digest = hashlib.md5((project / source_rel).read_bytes()).hexdigest()
pytest.param("../../../../bin/echo", "a climbing path", id="dot-dot"),(deep / "c").symlink_to("../../.godot", target_is_directory=True)(deep / "ci").symlink_to("../../.godot/imported", target_is_directory=True)(deep / "f_alias.gd").symlink_to("../../.godot/root_cache.gd")("res://a/../../outside.gd", "../outside.gd"),"base_url": "http://127.0.0.1:1",
return bytes.fromhex(encoded)
bytes.fromhex(os.environ["GDA_BALANCING_ANCHOR_KEY"]),
bytes.fromhex(os.environ["GDA_BALANCING_ANCHOR_KEY"]),
raw = base64.b64decode(png_base64)
Gates applied: no_behavioural_pass.
f2a216966cb3full audit observations/trust-audit/mcp-server/aigengame__godot-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f2a216966cb3 | CAUTION | D | 68 | first audit |
Questions
What is the godot-agent MCP server?
Godot automation for AI agents to build and verify projects through a CLI, Agent Skill, or MCP server, with structured results, headless operations, and live runtime control.
What tools does godot-agent expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is godot-agent safe to connect to an agent?
With care. The audit graded it D (68/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does godot-agent need?
It reads GDA_BALANCING_ANCHOR_KEY and GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does godot-agent run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as gda.
How current is this page?
The grade is for one exact copy of the source (f2a216966cb3), read on 2026-10-08. The repository is watched and re-audited when it changes.