Turn-Based GamesSAFE
A turn-based games app built with Next.js and TypeScript that features Tic-Tac-Toe and Rock Paper Scissors games with AI opponents powered by the Model Context Protocol (MCP), offering three difficulty levels.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This app is intended as a demo to showcase an example of MCP visually. It is not intended to be a production-ready application, but a learning tool for developers interested in building with the Model Context Protocol (MCP).
It is a modern turn-based games platform featuring a Next.js 15 frontend (and API), as well as an MCP (Model Context Protocol) server that can interact with the API and act as an AI opponent.
Features
- Next.js Web Application: Modern, responsive UI built with TailwindCSS 4
- MCP Server: AI opponent powered by Model Context Protocol
- Shared Logic: Common game logic and types across all packages
- Multiple Games: Tic-Tac-Toe and Rock Paper Scissors (extensible for more)
- AI Difficulty Levels: Easy, Medium, and Hard AI opponents
- Real-time Gameplay: Smooth, interactive game experience
- Comprehensive Testing: Hundreds of test cases across all workspaces with high coverage on core logic
- Professional Documentation: Full TSDoc documentation and testing guidelines
- Component Architecture: Reusable UI patterns and shared components
Project Structure
turn-based-mcp/ ├── shared/ # Shared types, utilities, and game logic ├── web/ # Next.js frontend application │ ├── src/components/ │ │ ├── games/ # Game-specific components │ │ ├── ui/ # Reusable UI components │ │ └── shared/ # MCP and game-related shared components │ └── src/app/ │ ├── api/games/ # API routes for game management │ └── games/ # Game-specific pages ├── mcp-server/ # MCP server for AI opponent ├── docs/ # Documentation and guidelines ├── package.json # Root package.json with workspaces └── README.md
Games
Tic-Tac-Toe
- Classic 3x3 grid game
- AI difficulty levels: Easy (random), Medium
aba5cb59d821OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add web -- npx -y @turn-based-mcp/[email protected]
{
"mcpServers": {
"web": {
"command": "npx",
"args": [
"-y",
"@turn-based-mcp/[email protected]"
]
}
}
}Exposed tools (13)
10 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_game | read | Analyze the current game state and provide insights |
beating_hard_ai | read | Advanced strategies for challenging the hardest AI opponents |
difficulty | read | AI difficulty level (${DIFFICULTIES?.join( |
difficulty_strategy_guide | read | Learn strategies for playing against different AI difficulty levels |
gameType | read | Game type (${GAME_TYPES?.join( |
getting_started | read | Complete guide to getting started with turn-based games via MCP |
make_player_move | write | Make a move on behalf of the human player. Use this when the player tells you their move in chat instead of using the web UI. IMPORTANT: When you later call play_game for the AI move, do NOT consider what move the player made - the AI should calculate its own optimal move independently. |
mcp_game_workflow | read | Understanding the Model Context Protocol game workflow and architecture |
play_game | write | Make an AI move in a game. IMPORTANT: After calling this tool when the game is still playing, you MUST call wait_for_player_move to continue the game flow. |
rock_paper_scissors_rules | read | Learn how to play Rock Paper Scissors and understand the rules |
tic_tac_toe_rules | read | Learn how to play Tic-Tac-Toe and understand the rules |
troubleshooting | read | Common issues and solutions for turn-based games MCP |
wait_for_player_move | write | Wait for human player to make their move via the web UI. If timeout occurs, you can call this again to continue waiting, or ask the player if they want to make their move in chat instead. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
vi.mock('../../../../../../lib/game-storage', () => ({import { getRPSGame, setRPSGame } from '../../../../../../lib/game-storage';import { getRPSGame, setRPSGame } from '../../../../../../lib/game-storage'import { getAllRPSGames } from '../../../../../lib/game-storage'vi.mock('../../../../../lib/game-storage')@modelcontextprotocol/sdk, @eslint/js, @vitest/ui, typescript, typescript-eslint, vitest
@eslint/js, @testing-library/jest-dom, @testing-library/react, @testing-library/user-event, @vitest/ui, eslint, typescript, typescript-eslint
better-sqlite3, @eslint/js, @types/better-sqlite3, @types/jest, @vitest/coverage-v8, @vitest/ui, eslint, fix-esm-import-path
@react-three/cannon, @react-three/drei, @react-three/fiber, clsx, next, react, react-dom, better-sqlite3
Gates applied: no_behavioural_pass.
aba5cb59d821full audit observations/trust-audit/mcp-server/github-samples__turn-based-games.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | aba5cb59d821 | SAFE | B | 89 | first audit |
Questions
What is the Turn-Based Games MCP server?
A turn-based games app built with Next.js and TypeScript that features Tic-Tac-Toe and Rock Paper Scissors games with AI opponents powered by the Model Context Protocol (MCP), offering three difficulty levels.
What tools does Turn-Based Games expose?
13 in total: 10 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Turn-Based Games safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Turn-Based Games need?
No credential environment variables were found in its source, so it appears to need none.
How does Turn-Based Games run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @turn-based-mcp/web at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (aba5cb59d821), read on 2026-10-08. The repository is watched and re-audited when it changes.