VibeCraftBLOCK
AI-driven vibe based Minecraft building via MCP. Describe a build, watch your agent construct it in Minecraft.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AI-Powered Minecraft Building — Build structures through natural-language conversations with Claude.
[](LICENSE) [](https://www.python.org/downloads/) [](https://www.minecraft.net/) [](https://discord.gg/uJ8DQBgcHF)
How It Works
┌─────────────┐ MCP ┌─────────────┐ WebSocket ┌─────────────┐ │ Claude │◄────────────►│ VibeCraft │◄─────────────►│ Minecraft │ │ (AI Chat) │ Protocol │ MCP Server │ Bridge │ Client Mod │ └─────────────┘ └─────────────┘ └─────────────┘ │ ▼ ┌─────────────┐ │ Minecraft │ │ Server │ └─────────────┘
- You chat with Claude asking it to build something
- Claude sends commands to the VibeCraft MCP server
- The server forwards commands to the Fabric client mod via WebSocket
- The client mod executes commands in Minecraft as your player
Works with any Minecraft server — vanilla, Paper, Spigot, or modded. WorldEdit optional.
Quick Start
Prerequisites
- Python 3.10+ with uv package manager
- Java 21 (for Minecraft 1.21.x) or Java 17 (for 1.20.x)
- jq for build script:
brew install jq - Minecraft Java Edition with a launcher like [Prism](h
c397d9245345OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add vibecraft-mcp --env RCON_PASSWORD=${RCON_PASSWORD} -- uvx vibecraft-mcp{
"mcpServers": {
"vibecraft-mcp": {
"command": "uvx",
"args": [
"vibecraft-mcp"
],
"env": {
"RCON_PASSWORD": "${RCON_PASSWORD}"
}
}
}
}Exposed tools (45)
45 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_palette | read | |
analyze_palette_region | read | |
build | read | |
build_schematic | read | |
building_pattern_lookup | read | |
building_template | read | |
calculate_shape | read | |
capture_screenshot | read | |
furniture_lookup | read | |
generate_terrain | read | |
get_heightmap | read | |
get_nearby_entities | read | |
get_player_context | read | |
get_player_position | read | |
get_server_info | read | |
get_surface_level | read | |
place_building_pattern | read | |
place_furniture | read | |
scan_region | read | |
search_minecraft_item | read | |
smooth_terrain | read | |
spatial_awareness_scan | read | |
terrain_pattern_lookup | read | |
texture_terrain | read | |
validate_mask | read | |
worldedit_analysis | read | |
worldedit_biome | read | |
worldedit_brush | read | |
worldedit_chunk | read | |
worldedit_clipboard | read | |
worldedit_deform | read | |
worldedit_general | read | |
worldedit_generation | read | |
worldedit_history | read | |
worldedit_navigation | read | |
worldedit_reference | read | |
worldedit_region | read | |
worldedit_schematic | read | |
worldedit_scripting | read | |
worldedit_selection | read | |
worldedit_snapshot | read | |
worldedit_terrain_advanced | read | |
worldedit_tools | read | |
worldedit_utility | read | |
worldedit_vegetation | read |
Trust audit
BLOCKgrade F · trust 57/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (15)
"eval(","exec(",exec(code, safe_namespace)
("eval() call", "commands = []\neval('1+1')"),("exec() call", "commands = []\nexec('pass')"),gradle-wrapper.jar
modern_villa_1.schem
modern_villa_2.schem
("open() call", "commands = []\nopen('/etc/passwd')"),"beacon",
"url": "http://127.0.0.1:8765/sse"
"url": "http://127.0.0.1:8765/sse"
Configure your AI client to connect to `http://127.0.0.1:8765/sse`
url = "http://127.0.0.1:8765/sse"
post_url = f"http://127.0.0.1:8765/messages/?session_id={session_id}"Gates applied: no_behavioural_pass.
c397d9245345full audit observations/trust-audit/mcp-server/amenti-labs__vibecraft.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c397d9245345 | BLOCK | F | 57 | first audit |
Questions
What is the VibeCraft MCP server?
AI-driven vibe based Minecraft building via MCP. Describe a build, watch your agent construct it in Minecraft.
What tools does VibeCraft expose?
45 in total: 45 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is VibeCraft safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (57/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does VibeCraft need?
It reads RCON_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does VibeCraft run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as vibecraft-mcp.
How current is this page?
The grade is for one exact copy of the source (c397d9245345), read on 2026-10-07. The repository is watched and re-audited when it changes.