STS2CAUTION
Full agentic runs for Slay the Spire 2. A mod that exposes in-game state, and the MCP server for the mod.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An Experimental Research Project to Fully-Automate your Slay the Spire 2 Runs
A mod for **Slay the Spire 2** that lets AI agents play the game. Exposes game state and actions via a localhost REST API, with an optional MCP server for Claude Desktop / Claude Code integration.
Singleplayer and multiplayer (co-op) supported, plus full menu and lobby control: profile switching, character select (SP and MP host/client) with optional seed, multiplayer host / Steam-friend join / FastMP localhost join, multiplayer load lobby for resuming saved co-op runs, game-over dismissal, FTUE/tutorial popup handling, and Timeline visibility. Tested against STS2 v0.103.2.
[!warning] This mod allows external programs to read and control your game via a localhost API. Use at your own risk with runs you care less about.
[!caution] Multiplayer support is in beta — expect bugs. Any multiplayer issues encountered with this mod installed are very likely caused by the mod, not the game. Please disable the mod and verify the issue persists before reporting bugs to the STS2 developers.
For Players
1. Install the Mod
Grab the latest release and follow the instructions:
- Copy
STS2_MCP.dllandSTS2_MCP.jsonto/mods/ - Launch the game and enable mods in settings (a consent dialog appears on first launch)
- The mod starts an HTTP server on
localhost:15526automatically
[!note] The release DLL is a platform-agnostic .NET assembly — the sameSTS2_MCP.dllandSTS2_MCP.jsonwork on Windows, Linux, and macOS. No separate builds are needed.
macOS install
On macOS, the mods directory lives inside the app bundle. The default Steam install path is:
~/Library/Application Support/Steam/steamapps/common/Sla
16da865bda04OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add sts2-mcp -- uvx sts2-mcp
{
"mcpServers": {
"sts2-mcp": {
"command": "uvx",
"args": [
"sts2-mcp"
]
}
}
}Exposed tools (64)
58 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
bundle_cancel_selection | read | [Bundle Selection] Cancel the current bundle preview. |
bundle_confirm_selection | read | [Bundle Selection] Confirm the currently previewed bundle. |
bundle_select | read | [Bundle Selection] Open a bundle preview. |
combat_confirm_selection | read | [Combat Selection] Confirm the in-combat card selection. |
combat_end_turn | read | [Combat] End the player |
combat_play_card | read | [Combat] Play a card from the player |
combat_select_card | read | [Combat Selection] Select a card from hand during an in-combat card selection prompt. |
crystal_sphere_click_cell | read | [Crystal Sphere] Click a hidden cell on the Crystal Sphere grid. |
crystal_sphere_proceed | read | [Crystal Sphere] Continue after the Crystal Sphere minigame finishes. |
crystal_sphere_set_tool | write | [Crystal Sphere] Switch the active divination tool. |
deck_cancel_selection | read | [Card Selection] Cancel the current card selection. |
deck_confirm_selection | read | [Card Selection] Confirm the current card selection. |
deck_select_card | read | [Card Selection] Select or deselect a card in the card selection screen. |
delete_profile | destructive | Delete an inactive profile slot. |
discard_potion | read | Discard a potion from the player |
event_advance_dialogue | read | [Event] Advance ancient event dialogue. |
event_choose_option | read | [Event] Choose an event option. |
get_compendium | read | Get the active profile |
get_game_state | read | Get the current Slay the Spire 2 game state. |
get_profile | read | Get the current profile |
list_profiles | read | List the three profile slots and identify the active slot. |
map_choose_node | read | [Map] Choose a map node to travel to. |
menu_select | read | Select a visible menu option. |
mp_bundle_cancel_selection | read | [Multiplayer Bundle Selection] Cancel the current bundle preview. |
mp_bundle_confirm_selection | read | [Multiplayer Bundle Selection] Confirm the currently previewed bundle. |
mp_bundle_select | read | [Multiplayer Bundle Selection] Open a bundle preview. |
mp_combat_confirm_selection | read | [Multiplayer Combat Selection] Confirm the in-combat card selection. |
mp_combat_end_turn | write | [Multiplayer Combat] Submit end-turn vote. |
mp_combat_play_card | read | [Multiplayer Combat] Play a card from the local player |
mp_combat_select_card | read | [Multiplayer Combat Selection] Select a card from hand during in-combat card selection. |
mp_combat_undo_end_turn | read | [Multiplayer Combat] Retract end-turn vote. |
mp_crystal_sphere_click_cell | read | [Multiplayer Crystal Sphere] Click a hidden cell on the Crystal Sphere grid. |
mp_crystal_sphere_proceed | read | [Multiplayer Crystal Sphere] Continue after the Crystal Sphere minigame finishes. |
mp_crystal_sphere_set_tool | write | [Multiplayer Crystal Sphere] Switch the active divination tool. |
mp_deck_cancel_selection | read | [Multiplayer Card Selection] Cancel the current card selection. |
mp_deck_confirm_selection | read | [Multiplayer Card Selection] Confirm the current card selection. |
mp_deck_select_card | read | [Multiplayer Card Selection] Select or deselect a card in the card selection screen. |
mp_discard_potion | read | [Multiplayer] Discard a potion from the local player |
mp_event_advance_dialogue | read | [Multiplayer Event] Advance ancient event dialogue. |
mp_event_choose_option | read | [Multiplayer Event] Choose or vote for an event option. |
mp_get_game_state | read | [Multiplayer] Get the current multiplayer game state. |
mp_map_vote | read | [Multiplayer Map] Vote for a map node to travel to. |
mp_proceed_to_map | read | [Multiplayer] Proceed from the current screen to the map. |
mp_relic_select | read | [Multiplayer Relic Selection] Select a relic (boss relic rewards). |
mp_relic_skip | read | [Multiplayer Relic Selection] Skip the relic selection. |
mp_rest_choose_option | read | [Multiplayer Rest Site] Choose a rest site option (rest, smith, etc.). |
mp_rewards_claim | write | [Multiplayer Rewards] Claim a reward from the post-combat rewards screen. |
mp_rewards_pick_card | read | [Multiplayer Rewards] Select a card from the card reward screen. |
mp_rewards_skip_card | read | [Multiplayer Rewards] Skip the card reward. |
mp_shop_purchase | read | [Multiplayer Shop] Purchase an item from the shop. |
mp_treasure_claim_relic | read | [Multiplayer Treasure] Bid on / claim a relic from the treasure chest. |
mp_use_potion | read | [Multiplayer] Use a potion from the local player |
proceed_to_map | read | Proceed from the current screen to the map. |
relic_select | read | [Relic Selection] Select a relic from the relic selection screen. |
relic_skip | read | [Relic Selection] Skip the relic selection without choosing a relic. |
rest_choose_option | read | [Rest Site] Choose a rest site option (rest, smith, etc.). |
rewards_claim | write | [Rewards] Claim a reward from the post-combat rewards screen. |
rewards_pick_card | read | [Rewards] Select a card from the card reward selection screen. |
rewards_skip_card | read | [Rewards] Skip the card reward without selecting a card. |
search_wiki | read | Search discovered card and relic wiki entries for the active profile. |
shop_purchase | read | [Shop / Fake Merchant] Purchase an item from the shop. |
switch_profile | read | Switch to a profile slot through the game |
treasure_claim_relic | read | [Treasure] Claim a relic from the treasure chest. |
use_potion | read | Use a potion from the player |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
_listener.Prefixes.Add($"http://127.0.0.1:{port}/");delete_profile
Grab the [latest release](https://github.com/Gennadiyev/STS2MCP/releases/latest) and follow the instructions:
Gates applied: no_behavioural_pass.
16da865bda04full audit observations/trust-audit/mcp-server/gennadiyev__sts2-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 16da865bda04 | CAUTION | B | 89 | first audit |
Questions
What is the STS2 MCP server?
Full agentic runs for Slay the Spire 2. A mod that exposes in-game state, and the MCP server for the mod.
What tools does STS2 expose?
64 in total: 58 read-only, 5 that write, and 1 that can delete or overwrite (delete_profile). Every one is listed on this page with its risk.
Is STS2 safe to connect to an agent?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does STS2 need?
No credential environment variables were found in its source, so it appears to need none.
How does STS2 run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as sts2-mcp.
How current is this page?
The grade is for one exact copy of the source (16da865bda04), read on 2026-09-30. The repository is watched and re-audited when it changes.