GodotSAFE
An MCP for Godot that lets you create and edit games in the Godot game engine with tools like Claude
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A comprehensive integration between Godot Engine and AI assistants using the Model Context Protocol (MCP). This plugin allows AI assistants to interact with your Godot projects, providing powerful capabilities for code assistance, scene manipulation, and project management.
Features
- Full Godot Project Access: AI assistants can access and modify scripts, scenes, nodes, and project resources
- Two-way Communication: Send project data to AI and apply suggested changes directly in the editor
- Command Categories:
- Node Commands: Create, modify, and manage nodes in your scenes
- Script Commands: Edit, analyze, and create GDScript files
- Scene Commands: Manipulate scenes and their structure
- Project Commands: Access project settings and resources
- Editor Commands: Control various editor functionality
Quick Setup
1. Clone the Repository
git clone https://github.com/ee0pdt/godot-mcp.git cd godot-mcp
2. Set Up the MCP Server
cd server npm install npm run build # Return to project root cd ..
3. Set Up Claude Desktop
- Edit or create the Claude Desktop config file:
# For macOS nano ~/Library/Application\ Support/Claude/claude_desktop_config.json
- Add the following configuration (or use the included
claude_desktop_config.jsonas a reference):
{
"mcpServers": {
"godot-mcp": {
"command": "node",
"args": [
"PATH_TO_YOUR_PROJECT/server/dist/index.js"
],
"env": {
"MCP_TRANSPORT": "stdio"
}
}
}
}Note: Replace PATH_TO_YOUR_PROJECT with the absolute path to where you have this repository stored.- Restart Claude Desktop
4. Open the Example Project in Godot
- Open Godot Engine
- Select "Import" and navigate to the cloned repository
- Open the
project.godotfile - The MCP plugin is already enabled in this example project
Using MCP wit
07cc239013d9OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add godot-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"godot-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (16)
6 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_node | write | Create a new node in the Godot scene tree |
create_resource | write | Create a new resource in the project |
create_scene | write | Create a new empty scene with optional root node type |
create_script | write | Create a new GDScript file in the project |
create_script_template | write | Generate a GDScript template with common boilerplate |
delete_node | destructive | Delete a node from the Godot scene tree |
edit_script | write | Edit an existing GDScript file |
execute_editor_script | write | Executes arbitrary GDScript code in the Godot editor |
get_current_scene | read | Get information about the currently open scene |
get_node_properties | read | Get all properties of a node in the Godot scene tree |
get_project_info | read | Get information about the current Godot project |
get_script | read | Get the content of a GDScript file |
list_nodes | read | List all child nodes under a parent node in the Godot scene tree |
open_scene | read | Open a scene in the editor |
save_scene | write | Save the current scene to disk |
update_node_property | write | Update a property of a node in the Godot scene tree |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
delete_node
fastmcp, websocket, ws, zod, @types/node, @types/ws, nodemon, typescript
Gates applied: no_behavioural_pass.
07cc239013d9full audit observations/trust-audit/mcp-server/ee0pdt__godot-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 07cc239013d9 | SAFE | B | 89 | first audit |
Questions
What is the Godot MCP server?
An MCP for Godot that lets you create and edit games in the Godot game engine with tools like Claude
What tools does Godot expose?
16 in total: 6 read-only, 9 that write, and 1 that can delete or overwrite (delete_node). Every one is listed on this page with its risk.
Is Godot safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Godot need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (07cc239013d9), read on 2026-09-29. The repository is watched and re-audited when it changes.