Atlas / MCP servers / github-samples / Turn-Based Games

Turn-Based GamesSAFE

mcp/github-samples/turn-based-games

A turn-based games app built with Next.js and TypeScript that features Tic-Tac-Toe and Rock Paper Scissors games with AI opponents powered by the Model Context Protocol (MCP), offering three difficulty levels.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
13 10r · 3w · 0d
Transport
stdio
License
MIT
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This app is intended as a demo to showcase an example of MCP visually. It is not intended to be a production-ready application, but a learning tool for developers interested in building with the Model Context Protocol (MCP).

It is a modern turn-based games platform featuring a Next.js 15 frontend (and API), as well as an MCP (Model Context Protocol) server that can interact with the API and act as an AI opponent.

Features

  • Next.js Web Application: Modern, responsive UI built with TailwindCSS 4
  • MCP Server: AI opponent powered by Model Context Protocol
  • Shared Logic: Common game logic and types across all packages
  • Multiple Games: Tic-Tac-Toe and Rock Paper Scissors (extensible for more)
  • AI Difficulty Levels: Easy, Medium, and Hard AI opponents
  • Real-time Gameplay: Smooth, interactive game experience
  • Comprehensive Testing: Hundreds of test cases across all workspaces with high coverage on core logic
  • Professional Documentation: Full TSDoc documentation and testing guidelines
  • Component Architecture: Reusable UI patterns and shared components

Project Structure

turn-based-mcp/
├── shared/                       # Shared types, utilities, and game logic
├── web/                         # Next.js frontend application  
│   ├── src/components/
│   │   ├── games/              # Game-specific components
│   │   ├── ui/                 # Reusable UI components
│   │   └── shared/             # MCP and game-related shared components
│   └── src/app/
│       ├── api/games/          # API routes for game management
│       └── games/              # Game-specific pages
├── mcp-server/                  # MCP server for AI opponent
├── docs/                        # Documentation and guidelines  
├── package.json                 # Root package.json with workspaces
└── README.md

Games

Tic-Tac-Toe

  • Classic 3x3 grid game
  • AI difficulty levels: Easy (random), Medium
Read from source at commit aba5cb59d821OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add web -- npx -y @turn-based-mcp/[email protected]
claude-desktop
{
  "mcpServers": {
    "web": {
      "command": "npx",
      "args": [
        "-y",
        "@turn-based-mcp/[email protected]"
      ]
    }
  }
}
03

Exposed tools (13)

10 read · 3 write · 0 destructive.

ToolRiskDescription
analyze_gamereadAnalyze the current game state and provide insights
beating_hard_aireadAdvanced strategies for challenging the hardest AI opponents
difficultyreadAI difficulty level (${DIFFICULTIES?.join(
difficulty_strategy_guidereadLearn strategies for playing against different AI difficulty levels
gameTypereadGame type (${GAME_TYPES?.join(
getting_startedreadComplete guide to getting started with turn-based games via MCP
make_player_movewriteMake a move on behalf of the human player. Use this when the player tells you their move in chat instead of using the web UI. IMPORTANT: When you later call play_game for the AI move, do NOT consider what move the player made - the AI should calculate its own optimal move independently.
mcp_game_workflowreadUnderstanding the Model Context Protocol game workflow and architecture
play_gamewriteMake an AI move in a game. IMPORTANT: After calling this tool when the game is still playing, you MUST call wait_for_player_move to continue the game flow.
rock_paper_scissors_rulesreadLearn how to play Rock Paper Scissors and understand the rules
tic_tac_toe_rulesreadLearn how to play Tic-Tac-Toe and understand the rules
troubleshootingreadCommon issues and solutions for turn-based games MCP
wait_for_player_movewriteWait for human player to make their move via the web UI. If timeout occurs, you can call this again to continue waiting, or ask the player if they want to make their move in chat instead.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/app/api/games/rock-paper-scissors/[id]/move/route.test.ts:23
vi.mock('../../../../../../lib/game-storage', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/app/api/games/rock-paper-scissors/[id]/move/route.test.ts:30
import { getRPSGame, setRPSGame } from '../../../../../../lib/game-storage';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/app/api/games/rock-paper-scissors/[id]/move/route.ts:5
import { getRPSGame, setRPSGame } from '../../../../../../lib/game-storage'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/app/api/games/rock-paper-scissors/mcp/route.test.ts:3
import { getAllRPSGames } from '../../../../../lib/game-storage'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/app/api/games/rock-paper-scissors/mcp/route.test.ts:8
vi.mock('../../../../../lib/game-storage')
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, @eslint/js, @vitest/ui, typescript, typescript-eslint, vitest
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@eslint/js, @testing-library/jest-dom, @testing-library/react, @testing-library/user-event, @vitest/ui, eslint, typescript, typescript-eslint
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
shared/package.json
better-sqlite3, @eslint/js, @types/better-sqlite3, @types/jest, @vitest/coverage-v8, @vitest/ui, eslint, fix-esm-import-path
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
web/package.json
@react-three/cannon, @react-three/drei, @react-three/fiber, clsx, next, react, react-dom, better-sqlite3
Why it matters. 30 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha aba5cb59d821full audit observations/trust-audit/mcp-server/github-samples__turn-based-games.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08aba5cb59d821SAFEB89first audit
06

Questions

What is the Turn-Based Games MCP server?

A turn-based games app built with Next.js and TypeScript that features Tic-Tac-Toe and Rock Paper Scissors games with AI opponents powered by the Model Context Protocol (MCP), offering three difficulty levels.

What tools does Turn-Based Games expose?

13 in total: 10 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Turn-Based Games safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Turn-Based Games need?

No credential environment variables were found in its source, so it appears to need none.

How does Turn-Based Games run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @turn-based-mcp/web at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (aba5cb59d821), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement