Atlas / MCP servers / gennadiyev / STS2

STS2CAUTION

mcp/gennadiyev/sts2-1

Full agentic runs for Slay the Spire 2. A mod that exposes in-game state, and the MCP server for the mod.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
64 58r · 5w · 1d
Transport
stdio
License
MIT
Stars
509
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An Experimental Research Project to Fully-Automate your Slay the Spire 2 Runs

A mod for **Slay the Spire 2** that lets AI agents play the game. Exposes game state and actions via a localhost REST API, with an optional MCP server for Claude Desktop / Claude Code integration.

Singleplayer and multiplayer (co-op) supported, plus full menu and lobby control: profile switching, character select (SP and MP host/client) with optional seed, multiplayer host / Steam-friend join / FastMP localhost join, multiplayer load lobby for resuming saved co-op runs, game-over dismissal, FTUE/tutorial popup handling, and Timeline visibility. Tested against STS2 v0.103.2.

[!warning] This mod allows external programs to read and control your game via a localhost API. Use at your own risk with runs you care less about.
[!caution] Multiplayer support is in beta — expect bugs. Any multiplayer issues encountered with this mod installed are very likely caused by the mod, not the game. Please disable the mod and verify the issue persists before reporting bugs to the STS2 developers.

For Players

1. Install the Mod

Grab the latest release and follow the instructions:

  1. Copy STS2_MCP.dll and STS2_MCP.json to /mods/
  2. Launch the game and enable mods in settings (a consent dialog appears on first launch)
  3. The mod starts an HTTP server on localhost:15526 automatically
[!note] The release DLL is a platform-agnostic .NET assembly — the same STS2_MCP.dll and STS2_MCP.json work on Windows, Linux, and macOS. No separate builds are needed.

macOS install

On macOS, the mods directory lives inside the app bundle. The default Steam install path is:

~/Library/Application Support/Steam/steamapps/common/Sla
Read from source at commit 16da865bda04OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add sts2-mcp -- uvx sts2-mcp
claude-desktop
{
  "mcpServers": {
    "sts2-mcp": {
      "command": "uvx",
      "args": [
        "sts2-mcp"
      ]
    }
  }
}
03

Exposed tools (64)

58 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
bundle_cancel_selectionread[Bundle Selection] Cancel the current bundle preview.
bundle_confirm_selectionread[Bundle Selection] Confirm the currently previewed bundle.
bundle_selectread[Bundle Selection] Open a bundle preview.
combat_confirm_selectionread[Combat Selection] Confirm the in-combat card selection.
combat_end_turnread[Combat] End the player
combat_play_cardread[Combat] Play a card from the player
combat_select_cardread[Combat Selection] Select a card from hand during an in-combat card selection prompt.
crystal_sphere_click_cellread[Crystal Sphere] Click a hidden cell on the Crystal Sphere grid.
crystal_sphere_proceedread[Crystal Sphere] Continue after the Crystal Sphere minigame finishes.
crystal_sphere_set_toolwrite[Crystal Sphere] Switch the active divination tool.
deck_cancel_selectionread[Card Selection] Cancel the current card selection.
deck_confirm_selectionread[Card Selection] Confirm the current card selection.
deck_select_cardread[Card Selection] Select or deselect a card in the card selection screen.
delete_profiledestructiveDelete an inactive profile slot.
discard_potionreadDiscard a potion from the player
event_advance_dialogueread[Event] Advance ancient event dialogue.
event_choose_optionread[Event] Choose an event option.
get_compendiumreadGet the active profile
get_game_statereadGet the current Slay the Spire 2 game state.
get_profilereadGet the current profile
list_profilesreadList the three profile slots and identify the active slot.
map_choose_noderead[Map] Choose a map node to travel to.
menu_selectreadSelect a visible menu option.
mp_bundle_cancel_selectionread[Multiplayer Bundle Selection] Cancel the current bundle preview.
mp_bundle_confirm_selectionread[Multiplayer Bundle Selection] Confirm the currently previewed bundle.
mp_bundle_selectread[Multiplayer Bundle Selection] Open a bundle preview.
mp_combat_confirm_selectionread[Multiplayer Combat Selection] Confirm the in-combat card selection.
mp_combat_end_turnwrite[Multiplayer Combat] Submit end-turn vote.
mp_combat_play_cardread[Multiplayer Combat] Play a card from the local player
mp_combat_select_cardread[Multiplayer Combat Selection] Select a card from hand during in-combat card selection.
mp_combat_undo_end_turnread[Multiplayer Combat] Retract end-turn vote.
mp_crystal_sphere_click_cellread[Multiplayer Crystal Sphere] Click a hidden cell on the Crystal Sphere grid.
mp_crystal_sphere_proceedread[Multiplayer Crystal Sphere] Continue after the Crystal Sphere minigame finishes.
mp_crystal_sphere_set_toolwrite[Multiplayer Crystal Sphere] Switch the active divination tool.
mp_deck_cancel_selectionread[Multiplayer Card Selection] Cancel the current card selection.
mp_deck_confirm_selectionread[Multiplayer Card Selection] Confirm the current card selection.
mp_deck_select_cardread[Multiplayer Card Selection] Select or deselect a card in the card selection screen.
mp_discard_potionread[Multiplayer] Discard a potion from the local player
mp_event_advance_dialogueread[Multiplayer Event] Advance ancient event dialogue.
mp_event_choose_optionread[Multiplayer Event] Choose or vote for an event option.
mp_get_game_stateread[Multiplayer] Get the current multiplayer game state.
mp_map_voteread[Multiplayer Map] Vote for a map node to travel to.
mp_proceed_to_mapread[Multiplayer] Proceed from the current screen to the map.
mp_relic_selectread[Multiplayer Relic Selection] Select a relic (boss relic rewards).
mp_relic_skipread[Multiplayer Relic Selection] Skip the relic selection.
mp_rest_choose_optionread[Multiplayer Rest Site] Choose a rest site option (rest, smith, etc.).
mp_rewards_claimwrite[Multiplayer Rewards] Claim a reward from the post-combat rewards screen.
mp_rewards_pick_cardread[Multiplayer Rewards] Select a card from the card reward screen.
mp_rewards_skip_cardread[Multiplayer Rewards] Skip the card reward.
mp_shop_purchaseread[Multiplayer Shop] Purchase an item from the shop.
mp_treasure_claim_relicread[Multiplayer Treasure] Bid on / claim a relic from the treasure chest.
mp_use_potionread[Multiplayer] Use a potion from the local player
proceed_to_mapreadProceed from the current screen to the map.
relic_selectread[Relic Selection] Select a relic from the relic selection screen.
relic_skipread[Relic Selection] Skip the relic selection without choosing a relic.
rest_choose_optionread[Rest Site] Choose a rest site option (rest, smith, etc.).
rewards_claimwrite[Rewards] Claim a reward from the post-combat rewards screen.
rewards_pick_cardread[Rewards] Select a card from the card reward selection screen.
rewards_skip_cardread[Rewards] Skip the card reward without selecting a card.
search_wikireadSearch discovered card and relic wiki entries for the active profile.
shop_purchaseread[Shop / Fake Merchant] Purchase an item from the shop.
switch_profilereadSwitch to a profile slot through the game
treasure_claim_relicread[Treasure] Claim a relic from the treasure chest.
use_potionreadUse a potion from the player
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
McpMod.cs:96
_listener.Prefixes.Add($"http://127.0.0.1:{port}/");
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_profile
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:21
Grab the [latest release](https://github.com/Gennadiyev/STS2MCP/releases/latest) and follow the instructions:
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 16da865bda04full audit observations/trust-audit/mcp-server/gennadiyev__sts2-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-3016da865bda04CAUTIONB89first audit
06

Questions

What is the STS2 MCP server?

Full agentic runs for Slay the Spire 2. A mod that exposes in-game state, and the MCP server for the mod.

What tools does STS2 expose?

64 in total: 58 read-only, 5 that write, and 1 that can delete or overwrite (delete_profile). Every one is listed on this page with its risk.

Is STS2 safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does STS2 need?

No credential environment variables were found in its source, so it appears to need none.

How does STS2 run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as sts2-mcp.

How current is this page?

The grade is for one exact copy of the source (16da865bda04), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement