Atlas / MCP servers / arjunkmrm / Minecraft Integration

Minecraft IntegrationSAFE

mcp/arjunkmrm/minecraft-integration
Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
21 16r · 5w · 0d
Transport
stdio
License
MIT
Stars
100
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) integration for Minecraft that enables AI assistants to interact with a Minecraft server. This integration allows AI models to observe and interact with the Minecraft world through a bot.

Prerequisites

  1. Minecraft Launcher
  2. Node.js 18 or higher
  3. Claude Desktop App
  4. Java 21.0.5 (recommended)
⚠️ Note: Currently only tested on macOS/Linux. Windows compatibility is not guaranteed.

Important Note

  1. Use the F3+P Shortcut:

Press F3 + P together. This toggles the "Pause on Lost Focus" feature. Once turned off, you can switch to claude desktop and Minecraft will continue running without pausing.

  1. Connection Issues on Claude Restart:

If you restart Claude while the Minecraft server is running, you may experience MCP connection issues on the next claude launch due to lingering java process. See Troubleshooting: MCP Connection Failed for resolution steps.

Installation Steps

  1. Download and Setup Minecraft Server
  2. Download Minecraft server v1.21 from mcversions.net/1.21
  3. Install Java 21.0.5 if not already installed (other versions are untested)
  4. Create a dedicated directory (e.g., ~/minecraft-server/)
  5. Place the downloaded server.jar file in this directory
  6. Note down the absolute path to your server.jar file
  1. Install and Configure MCP Integration

Quick Install (Recommended):

npx -y @smithery/cli install mcp-minecraft --client claude

Follow the CLI prompts to complete the setup.

Or Manual Setup:

  • Navigate to ~/Library/Application Support/Claude/claude_desktop_config.json
  • Add the MCP server configuration:
{
"mcpServers": {
"mcp-minecraft": {
"command": "npx",
"args": [
"-y",
"mcp-minecraft
Read from source at commit 165b8ef13a0aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-minecraft -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-minecraft": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (21)

16 read · 5 write · 0 destructive.

ToolRiskDescription
attackreadAttack a nearby entity by name
chatwriteSend a chat message
digBlockreadBreak a block at specified coordinates
equipItemreadEquip an item by name
followPlayerreadFollow a specific player
getBlockInforeadGet information about a block at specified coordinates
getInventoryreadGet contents of bot
getNearbyEntitiesreadGet list of nearby entities within specified range
getStatusreadGet bot
goToPositionreadNavigate to specific coordinates
jumpreadMake the bot jump
lookAtreadMake the bot look at specific coordinates
moveBackwriteMake the bot move backward
moveForwardwriteMake the bot move forward
placeBlockreadPlace a block at specified coordinates
selectSlotreadSelect a hotbar slot (0-8)
stopFollowingwriteStop following current target
stopUsingItemwriteStop using/deactivate the current item
turnLeftreadMake the bot turn left
turnRightreadMake the bot turn right
useItemreadUse/activate the currently held item
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/node, minecraft-protocol, mineflayer, mineflayer-pathfinder, ts-node, typescript, yargs
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
public/screenshot.png
public/screenshot.png
Why it matters. 3949429 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 165b8ef13a0afull audit observations/trust-audit/mcp-server/arjunkmrm__minecraft-integration.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07165b8ef13a0aSAFEB89first audit
06

Questions

What tools does Minecraft Integration expose?

21 in total: 16 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Minecraft Integration safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Minecraft Integration need?

No credential environment variables were found in its source, so it appears to need none.

How does Minecraft Integration run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-minecraft at 1.0.34.

How current is this page?

The grade is for one exact copy of the source (165b8ef13a0a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement