Atlas / MCP servers / funplayai / Funplay Godot

Funplay GodotSAFE

mcp/funplayai/funplay-godot

The Most Advanced MCP Server for Godot Editor with execute_code, prompts/resources, project maps, runtime inspection, asset workflows, and safe AI automation.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
41
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Funplay MCP for Godot

The Most Advanced MCP Server for Godot Editor

Godot Asset Store · 中文 | English

💖 If you find this project useful, please consider giving it a Star. It helps more Godot developers discover it and supports ongoing development.

Funplay MCP for Godot is an MIT-licensed Godot Editor MCP server that lets AI assistants like Claude Code, Cursor, Windsurf, Codex, and VS Code Copilot operate directly inside your running Godot project.

The addon works in standard Godot 4.2+ projects and is also usable in Godot .NET projects. The current implementation is GDScript-based, and the exported script tools are language-aware: GDScript projects see GDScript workflows, .NET projects see C#/.NET workflows, and mixed projects expose both where useful.

Describe your game or tool in one sentence — your AI assistant builds it in Godot through Funplay MCP for Godot’s built-in tools for scene creation, script generation, UI authoring, play-mode validation, input simulation, animation setup, camera control, performance inspection, and editor automation.

"Build a top-down shooter HUD with health, ammo, pause menu, and hit flash feedback" Your AI assistant handles it through Funplay MCP for Godot: creates the scene structure, generates scripts, builds the Control tree
Read from source at commit bc1638f75919OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add funplay-godot-mcp --env FUNPLAY_GODOT_MCP_TOKEN=${FUNPLAY_GODOT_MCP_TOKEN} --env GODOT_MCP_TOKEN=${GODOT_MCP_TOKEN} -- npx -y [email protected]
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (7)

LOWInventory / provenance · inv.hidden_file · CWE-1104
tests/fixtures/gdscript_diagnostics/.gdignore
.gdignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:10
4. Start the server and confirm it is reachable at `http://127.0.0.1:8765/`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:59
The server starts on `http://127.0.0.1:8765/` by default.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:87
"FUNPLAY_GODOT_MCP_URL": "http://127.0.0.1:8765/",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:107
"FUNPLAY_GODOT_MCP_URL": "http://127.0.0.1:8765/",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:128
"FUNPLAY_GODOT_MCP_URL": "http://127.0.0.1:8765/",
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha bc1638f75919full audit observations/trust-audit/mcp-server/funplayai__funplay-godot.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08bc1638f75919SAFEB89first audit
05

Questions

What is the Funplay Godot MCP server?

The Most Advanced MCP Server for Godot Editor with execute_code, prompts/resources, project maps, runtime inspection, asset workflows, and safe AI automation.

Is Funplay Godot safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Funplay Godot need?

It reads FUNPLAY_GODOT_MCP_TOKEN and GODOT_MCP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Funplay Godot run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as funplay-godot-mcp at 0.10.0.

How current is this page?

The grade is for one exact copy of the source (bc1638f75919), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement