BlockbenchBLOCK
Adds MCP server to Blockbench
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Demo Reel
https://github.com/user-attachments/assets/c67d0dd8-ee50-40ba-b308-a84a21772901
All scenes, models, and textures created through Blockbench MCP plugin using agent skills. (Rendered in Blender)
[](https://skills.sh/jasonjgardner/blockbench-mcp-project)
Plugin Installation
Open the desktop version of Blockbench, go to File > Plugins and click the "Load Plugin from URL" and paste in this URL:
[https://jasonjgardner.github.io/blockbench-mcp-plugin/mcp.js](https://jasonjgardner.github.io/blockbench-mcp-plugin/mcp.js)
Model Context Protocol Servers
This repository contains two MCP server options.
Headless .bbmodel (stdio)
A separate stdio MCP server edits, validates, converts and renders .bbmodel files directly, without Blockbench running. Each agent can start its own process, so several can work in parallel while you keep using the editor. Run it straight from GitHub:
npx -y github:jasonjgardner/blockbench-mcp-plugin --root ./models
See headless/README.md for client configuration, the tool list and limits.
Blockbench Desktop Plugin (HTTP)
Configure the MCP server under Blockbench settings: Settings > General > MCP Server Port and MCP Server Endpoint.
The following installation settings examples use the default values of :3000/bb-mcpInstallation
The examples below configure the desktop plugin over HTTP and the headless server over stdio. You can use either server or both. HTTP requires Blockbench running with the plugin installed; stdio requires Node.js with npm and starts its own server process.
For headless examp
8b99cc7a4565OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add blockbench-mcp -- npx -y [email protected]
{
"mcpServers": {
"blockbench-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (49)
36 read · 12 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Demo | read | Runs the demo. |
Turntable | read | Reference model |
add_locator | write | Adds a locator: a named point on a bone where particle effects (and sounds) spawn and which they follow as the bone animates. Exported as a Bedrock bone locator. Requires a format with locators (Bedrock Entity, GeckoLib, Generic Model). One undo step. |
bbmodel_convert_legacy | read | Writes a copy of a .bbmodel in the 4.10 layout that Blockbench 4.x can open (a 5.0 file opens there as an empty scene). Mirrors Blockbench |
bbmodel_create | write | Creates a new, empty .bbmodel file (format 5.0). Build it up with bbmodel_edit. Refuses to replace an existing file unless overwrite is true. |
bbmodel_export_bedrock_geometry | read | Compiles a .bbmodel to Minecraft Bedrock geometry (.geo.json) using the same conventions as Blockbench |
bbmodel_export_java_block | read | Compiles a .bbmodel to a Minecraft Java Edition block/item model .json the way Blockbench |
bbmodel_export_modded_entity | read | Compiles a .bbmodel to a Java entity model class with the same templates and code generation as Blockbench |
bbmodel_find_elements | read | Finds elements in a .bbmodel file by name, type, containing group or texture. Returns world-space bounds for each match. |
bbmodel_get_node | read | Returns the saved data of one group or element (by UUID or exact name), its parent, and its world-space bounds. Group results list their children. |
bbmodel_import_java_block | write | Converts a Minecraft Java Edition block/item model .json into a new java_block .bbmodel, porting Blockbench |
bbmodel_info | read | Summarizes a .bbmodel file: format, version, resolution, node counts, world-space bounds and the current revision. Start here before editing. |
bbmodel_list_animations | read | Lists animation clips with length, loop mode and, per animated bone, how many keyframes each channel has. |
bbmodel_list_textures | read | Lists the textures of a .bbmodel file with their index, size, and whether the image is embedded. Image data is not returned. |
bbmodel_outline | write | Returns the group/element tree of a .bbmodel file. Set transforms to include origins, rotations and cube from/to. |
bbmodel_particle_pack | read | Delivers the particle effects a .bbmodel |
bbmodel_render | read | Renders a .bbmodel file to a PNG with bb-render (headless three.js WebGPU), without Blockbench. Returns the image and its path. Optionally poses the model at a time in an animation clip. Views are relative to the model |
bbmodel_sample_pose | read | Evaluates an animation at a time and returns each animated bone |
bbmodel_web_url | read | Makes a link that opens a .bbmodel (or a Bedrock/Java .json model) in the Blockbench web app, with the file carried in the URL |
blockbench_code_eval_safety | read | Critical safety guide for agents using code evaluation/execution tools with Blockbench v5.0+. Contains breaking changes, quick reference, common mistakes, and safe code patterns for native module usage. |
blockbench_native_apis | read | Essential information about Blockbench v5.0 native API security model and requireNativeModule() usage. Use this when working with Node.js modules, file system access, or native APIs in Blockbench plugins. |
create_brush_preset | write | Creates a custom brush preset with specified settings. Omitted settings are stored as unset so loading the preset keeps the current value. |
create_offscreen_view | write | Creates a private offscreen viewport that renders the current project without moving the user |
create_particle_effect | write | Creates a Bedrock particle effect (the Snowstorm format Blockbench, Minecraft Bedrock and GeckoLib use) from a preset plus design knobs, or from raw JSON. Writes <pack_root>/particles/<name>.json (and an optional custom texture to textures/particle/), validates it, and loads it into Blockbench |
create_project | write | Creates a project with the given name and format, and returns a resource link to its live .bbmodel file. |
delete_offscreen_view | destructive | Disposes an offscreen view and releases its WebGL context. The user |
export_model | read | Compiles the current project through a codec whose native export action is available. Returns JSON metadata and a live .bbmodel resource link; result_format= |
export_particle_pack | read | Delivers particle effects to a Bedrock resource pack: writes particles/<name>.json and copies custom textures to textures/particle/, then returns the particle_effects map to paste into the client entity so animation keyframe names resolve. Defaults to every effect the project |
foreign_schema | read | Uses a foreign schema. |
geckolib_list_easings | read | Lists every easing name GeckoLib accepts on keyframes, which of them read easingArgs, and each argument |
get_average_fps | read | Measures the average frames per second of Blockbench |
get_capabilities | read | Discover Blockbench/plugin versions, desktop or web environment, active project summary, and registered model formats. Returns detailed boolean format features (null means unknown; includes molang and java_cube_shade_direction_override) plus the format |
get_project_info | read | |
hytale_animation_workflow | read | Guide for creating animations for Hytale models. Covers 60 FPS timing, quaternion rotations, visibility keyframes, loop modes, and common animation patterns. |
hytale_attachments | read | Guide for creating and managing attachments in Hytale models. Covers attachment collections, piece bones, modular equipment, and best practices. |
hytale_model_creation | read | Comprehensive guide for creating Hytale character and prop models. Covers format selection, node limits, shading modes, stretch, quads, and best practices. |
list_export_formats | read | Lists registered export codecs, file extensions, compile/export support, and availability under the native export action |
list_modes | read | Lists Blockbench editor tabs/modes with IDs, names, native availability, and the current mode. Includes plugin-added modes. Use before set_mode to discover whether Edit, Paint, Animate, or Display is available for the current project. Camera angles are controlled separately by set_camera_angle. |
list_particle_effects | read | Lists particle effects loaded in Blockbench with their file, summary, texture status and validation warnings, every particle keyframe that uses them, keyframes that have no preview file or point at missing locators, and the client-entity particle_effects map a Bedrock pack needs. |
list_particle_presets | read | Lists particle effect presets (smoke, fire, sparks, magic, glow, snow, drip, ...), built-in sprites and textures, materials and facing modes. Every preset uses a texture that ships with Minecraft and Blockbench, so it previews and runs with no image file. Read this before create_particle_effect. |
list_views | read | Lists render targets: the user |
manage_particle_keyframes | read | Adds, removes or lists particle keyframes on an animation |
model_creation_strategy | read | A strategy for creating a new 3D model in Blockbench. |
no_description | read | |
no_execute | write | Fine. |
resize_offscreen_view | read | Changes the pixel size of an offscreen view. The user |
set_mode | write | Switches Blockbench |
trigger_action | write | Triggers an available Blockbench Action and respects its condition. The native action owns Undo; only a newly opened dialog may be auto-confirmed. |
update_particle_effect | write | Changes an existing particle effect file with design knobs (only the components each knob owns are rewritten) or replaces it with raw JSON, validates it, saves it and refreshes the preview. Also loads an effect file from disk that Blockbench has not seen yet. Blockbench desktop only. |
Trust audit
BLOCKgrade D · trust 62/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
result = await eval(code.trim());
// Access environment variables
return Array.from({ length }, () => KEY_CHARS[Math.floor(Math.random() * KEY_CHARS.length)] ?? "a").join("");const LEADING_BYTE_ORDER_MARK = /^/;
curl -fsSL https://bun.sh/install | bash
curl -fsSL https://bun.sh/install | bash
delete_offscreen_view
ai-disclosure.test.ts
.coderabbit.yaml
'{"action":"read_context","path":"../../.env"}',texture("embedded", { source: embedded, path: secret, relative_path: "../../secret.png" }),const outside = await session.call("bbmodel_info", { file: "../../etc/model.bbmodel" });const outside = await session.call("blockbench_launch", { file: "../../elsewhere/model.bbmodel" });["../../outside/pwn", "/abs/tex", "C:/tex", "textures\\particle\\x", "textures//x"].forEach((texture) => {"127.0.0.1", "0.0.0.0", "10.1.2.3", "100.64.0.1", "169.254.169.254", "172.16.0.1", "172.31.255.255",
"http://169.254.169.254/latest/meta-data",
proxyUrl: "http://127.0.0.1:1234/mcp",
mcpServers: { bench: { type: "http", url: "http://127.0.0.1:1234/mcp" } },expect(settings.mcpServers.bench.httpUrl).toBe("http://127.0.0.1:1234/mcp");const client = await connect(`http://127.0.0.1:${http.port}/mcp`, id);return `http://127.0.0.1:${this.http.port}/mcp`;const PNG_2X4 = Uint8Array.from(atob("iVBORw0KGgoAAAANSUhEUgAAAAIAAAAECAYAAACk7+45AAAAFklEQVR4nGP838Dwn4GBgYEJRGBnAABUcQKGuqbVnwAAAABJRU5ErkJggg=="), (c) => c.charCodeAt(0));return { frame: atob(item.data), structured: result.structuredContent };return Uint8Array.from(atob(base64), (character) => character.charCodeAt(0));
const PNG_2X4 = Uint8Array.from(atob("iVBORw0KGgoAAAANSUhEUgAAAAIAAAAECAYAAACk7+45AAAAFklEQVR4nGP838Dwn4GBgYEJRGBnAABUcQKGuqbVnwAAAABJRU5ErkJggg=="), (c) => c.charCodeAt(0));Gates applied: no_behavioural_pass.
8b99cc7a4565full audit observations/trust-audit/mcp-server/jasonjgardner__blockbench.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 8b99cc7a4565 | BLOCK | D | 62 | first audit |
Questions
What is the Blockbench MCP server?
Adds MCP server to Blockbench
What tools does Blockbench expose?
49 in total: 36 read-only, 12 that write, and 1 that can delete or overwrite (delete_offscreen_view). Every one is listed on this page with its risk.
Is Blockbench safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (62/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Blockbench need?
No credential environment variables were found in its source, so it appears to need none.
How does Blockbench run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as blockbench-mcp at 1.10.0.
How current is this page?
The grade is for one exact copy of the source (8b99cc7a4565), read on 2026-10-03. The repository is watched and re-audited when it changes.