MCPMCSAFE
Model Context Protocol Minecraft Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://badge.fury.io/js/@gerred%2Fmcpmc) [](https://www.npmjs.com/package/@gerred/mcpmc) [](https://github.com/gerred/mcpmc/actions?query=workflow%3ACI) [](https://opensource.org/licenses/MIT)
A Model Context Protocol (MCP) server for interacting with Minecraft via Mineflayer. This package enables AI agents to control Minecraft bots through a standardized JSON-RPC interface.
Features
- Full MCP compatibility for AI agent integration
- Built on Mineflayer for reliable Minecraft interaction
- Supports navigation, block manipulation, inventory management, and more
- Real-time game state monitoring
- Type-safe API with TypeScript support
Installation
# Using npm npm install @gerred/mcpmc # Using yarn yarn add @gerred/mcpmc # Using bun bun add @gerred/mcpmc
Usage
# Start the MCP server mcpmc
The server communicates via stdin/stdout using the Model Context Protocol. For detailed API documentation, use the MCP inspector:
bun run inspector
Development
# Install dependencies bun install # Run tests bun test # Build the project bun run build # Watch mode during development bun run watch # Run MCP inspector bun run inspector
Contributing
Contributions are welcome! Please follow these steps:
- Fork the repository
- Create a new branch for your feature
- Write tests for your changes
- Make your changes
- Run tests and ensure they pass
- Submit a pull request
Please make sure to update tests as appropriate and adhere to the existing coding style.
License
MIT License
Copyright (c) 2024 Gerred Dillon
Permission is hereby granted, free of charge, to any person obtaining a copy of this softwa
cc162cd4ad91OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcpmc -- npx -y @gerred/[email protected]
{
"mcpServers": {
"mcpmc": {
"command": "npx",
"args": [
"-y",
"@gerred/[email protected]"
]
}
}
}Exposed tools (10)
9 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
attack_entity | read | Attack a specific entity near the bot |
chat | write | Send a chat message to the server |
craft_item | read | Craft items using materials in inventory. Can use a crafting table if specified. |
dig_area_relative | read | Dig multiple blocks in an area relative to the bot |
dig_block_relative | read | Dig a single block relative to the bot |
find_blocks | read | Find nearby blocks of specific types. Use this to locate building materials or identify terrain. |
follow_player | read | Make the bot follow a specific player |
inspect_inventory | read | Check the contents of the bot |
navigate_relative | read | Make the bot walk relative to its current position. dx moves right(+)/left(-), dy moves up(+)/down(-), dz moves forward(+)/back(-) relative to bot |
place_block | read | Place a block from the bot |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
bun.lockb
import type { MinecraftBot } from "../../types/minecraft";} from "../../types/minecraft";
@modelcontextprotocol/inspector, bunx, mineflayer, mineflayer-pathfinder, vec3, zod-to-json-schema, @types/bun, @types/jest
Gates applied: no_behavioural_pass.
cc162cd4ad91full audit observations/trust-audit/mcp-server/gerred__mcpmc.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | cc162cd4ad91 | SAFE | B | 89 | first audit |
Questions
What is the MCPMC MCP server?
Model Context Protocol Minecraft Server
What tools does MCPMC expose?
10 in total: 9 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MCPMC safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does MCPMC need?
No credential environment variables were found in its source, so it appears to need none.
How does MCPMC run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @gerred/mcpmc at 0.0.9.
How current is this page?
The grade is for one exact copy of the source (cc162cd4ad91), read on 2026-10-08. The repository is watched and re-audited when it changes.