Funplay GodotSAFE
The Most Advanced MCP Server for Godot Editor with execute_code, prompts/resources, project maps, runtime inspection, asset workflows, and safe AI automation.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Funplay MCP for Godot
The Most Advanced MCP Server for Godot Editor
Godot Asset Store · 中文 | English
💖 If you find this project useful, please consider giving it a Star. It helps more Godot developers discover it and supports ongoing development.
Funplay MCP for Godot is an MIT-licensed Godot Editor MCP server that lets AI assistants like Claude Code, Cursor, Windsurf, Codex, and VS Code Copilot operate directly inside your running Godot project.
The addon works in standard Godot 4.2+ projects and is also usable in Godot .NET projects. The current implementation is GDScript-based, and the exported script tools are language-aware: GDScript projects see GDScript workflows, .NET projects see C#/.NET workflows, and mixed projects expose both where useful.
Describe your game or tool in one sentence — your AI assistant builds it in Godot through Funplay MCP for Godot’s built-in tools for scene creation, script generation, UI authoring, play-mode validation, input simulation, animation setup, camera control, performance inspection, and editor automation.
"Build a top-down shooter HUD with health, ammo, pause menu, and hit flash feedback" Your AI assistant handles it through Funplay MCP for Godot: creates the scene structure, generates scripts, builds the Control tree
bc1638f75919OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add funplay-godot-mcp --env FUNPLAY_GODOT_MCP_TOKEN=${FUNPLAY_GODOT_MCP_TOKEN} --env GODOT_MCP_TOKEN=${GODOT_MCP_TOKEN} -- npx -y [email protected]Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
.gdignore
4. Start the server and confirm it is reachable at `http://127.0.0.1:8765/`
The server starts on `http://127.0.0.1:8765/` by default.
"FUNPLAY_GODOT_MCP_URL": "http://127.0.0.1:8765/",
"FUNPLAY_GODOT_MCP_URL": "http://127.0.0.1:8765/",
"FUNPLAY_GODOT_MCP_URL": "http://127.0.0.1:8765/",
Gates applied: no_behavioural_pass.
bc1638f75919full audit observations/trust-audit/mcp-server/funplayai__funplay-godot.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | bc1638f75919 | SAFE | B | 89 | first audit |
Questions
What is the Funplay Godot MCP server?
The Most Advanced MCP Server for Godot Editor with execute_code, prompts/resources, project maps, runtime inspection, asset workflows, and safe AI automation.
Is Funplay Godot safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Funplay Godot need?
It reads FUNPLAY_GODOT_MCP_TOKEN and GODOT_MCP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Funplay Godot run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as funplay-godot-mcp at 0.10.0.
How current is this page?
The grade is for one exact copy of the source (bc1638f75919), read on 2026-10-08. The repository is watched and re-audited when it changes.