Atlas / MCP servers / jasonjgardner / Blockbench

BlockbenchBLOCK

mcp/jasonjgardner/blockbench

Adds MCP server to Blockbench

Verdict
BLOCK
Grade
D
Trust score
62 /100
Exposed tools
49 36r · 12w · 1d
Transport
stdio · streamable-http
License
GPL-3.0
Stars
476
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Demo Reel

https://github.com/user-attachments/assets/c67d0dd8-ee50-40ba-b308-a84a21772901

All scenes, models, and textures created through Blockbench MCP plugin using agent skills. (Rendered in Blender)

[](https://skills.sh/jasonjgardner/blockbench-mcp-project)

Plugin Installation

Open the desktop version of Blockbench, go to File > Plugins and click the "Load Plugin from URL" and paste in this URL:

[https://jasonjgardner.github.io/blockbench-mcp-plugin/mcp.js](https://jasonjgardner.github.io/blockbench-mcp-plugin/mcp.js)

Model Context Protocol Servers

This repository contains two MCP server options.

Headless .bbmodel (stdio)

A separate stdio MCP server edits, validates, converts and renders .bbmodel files directly, without Blockbench running. Each agent can start its own process, so several can work in parallel while you keep using the editor. Run it straight from GitHub:

npx -y github:jasonjgardner/blockbench-mcp-plugin --root ./models

See headless/README.md for client configuration, the tool list and limits.

Blockbench Desktop Plugin (HTTP)

Configure the MCP server under Blockbench settings: Settings > General > MCP Server Port and MCP Server Endpoint.

The following installation settings examples use the default values of :3000/bb-mcp

Installation

The examples below configure the desktop plugin over HTTP and the headless server over stdio. You can use either server or both. HTTP requires Blockbench running with the plugin installed; stdio requires Node.js with npm and starts its own server process.

For headless examp

Read from source at commit 8b99cc7a4565OBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add blockbench-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "blockbench-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (49)

36 read · 12 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
DemoreadRuns the demo.
TurntablereadReference model
add_locatorwriteAdds a locator: a named point on a bone where particle effects (and sounds) spawn and which they follow as the bone animates. Exported as a Bedrock bone locator. Requires a format with locators (Bedrock Entity, GeckoLib, Generic Model). One undo step.
bbmodel_convert_legacyreadWrites a copy of a .bbmodel in the 4.10 layout that Blockbench 4.x can open (a 5.0 file opens there as an empty scene). Mirrors Blockbench
bbmodel_createwriteCreates a new, empty .bbmodel file (format 5.0). Build it up with bbmodel_edit. Refuses to replace an existing file unless overwrite is true.
bbmodel_export_bedrock_geometryreadCompiles a .bbmodel to Minecraft Bedrock geometry (.geo.json) using the same conventions as Blockbench
bbmodel_export_java_blockreadCompiles a .bbmodel to a Minecraft Java Edition block/item model .json the way Blockbench
bbmodel_export_modded_entityreadCompiles a .bbmodel to a Java entity model class with the same templates and code generation as Blockbench
bbmodel_find_elementsreadFinds elements in a .bbmodel file by name, type, containing group or texture. Returns world-space bounds for each match.
bbmodel_get_nodereadReturns the saved data of one group or element (by UUID or exact name), its parent, and its world-space bounds. Group results list their children.
bbmodel_import_java_blockwriteConverts a Minecraft Java Edition block/item model .json into a new java_block .bbmodel, porting Blockbench
bbmodel_inforeadSummarizes a .bbmodel file: format, version, resolution, node counts, world-space bounds and the current revision. Start here before editing.
bbmodel_list_animationsreadLists animation clips with length, loop mode and, per animated bone, how many keyframes each channel has.
bbmodel_list_texturesreadLists the textures of a .bbmodel file with their index, size, and whether the image is embedded. Image data is not returned.
bbmodel_outlinewriteReturns the group/element tree of a .bbmodel file. Set transforms to include origins, rotations and cube from/to.
bbmodel_particle_packreadDelivers the particle effects a .bbmodel
bbmodel_renderreadRenders a .bbmodel file to a PNG with bb-render (headless three.js WebGPU), without Blockbench. Returns the image and its path. Optionally poses the model at a time in an animation clip. Views are relative to the model
bbmodel_sample_posereadEvaluates an animation at a time and returns each animated bone
bbmodel_web_urlreadMakes a link that opens a .bbmodel (or a Bedrock/Java .json model) in the Blockbench web app, with the file carried in the URL
blockbench_code_eval_safetyreadCritical safety guide for agents using code evaluation/execution tools with Blockbench v5.0+. Contains breaking changes, quick reference, common mistakes, and safe code patterns for native module usage.
blockbench_native_apisreadEssential information about Blockbench v5.0 native API security model and requireNativeModule() usage. Use this when working with Node.js modules, file system access, or native APIs in Blockbench plugins.
create_brush_presetwriteCreates a custom brush preset with specified settings. Omitted settings are stored as unset so loading the preset keeps the current value.
create_offscreen_viewwriteCreates a private offscreen viewport that renders the current project without moving the user
create_particle_effectwriteCreates a Bedrock particle effect (the Snowstorm format Blockbench, Minecraft Bedrock and GeckoLib use) from a preset plus design knobs, or from raw JSON. Writes <pack_root>/particles/<name>.json (and an optional custom texture to textures/particle/), validates it, and loads it into Blockbench
create_projectwriteCreates a project with the given name and format, and returns a resource link to its live .bbmodel file.
delete_offscreen_viewdestructiveDisposes an offscreen view and releases its WebGL context. The user
export_modelreadCompiles the current project through a codec whose native export action is available. Returns JSON metadata and a live .bbmodel resource link; result_format=
export_particle_packreadDelivers particle effects to a Bedrock resource pack: writes particles/<name>.json and copies custom textures to textures/particle/, then returns the particle_effects map to paste into the client entity so animation keyframe names resolve. Defaults to every effect the project
foreign_schemareadUses a foreign schema.
geckolib_list_easingsreadLists every easing name GeckoLib accepts on keyframes, which of them read easingArgs, and each argument
get_average_fpsreadMeasures the average frames per second of Blockbench
get_capabilitiesreadDiscover Blockbench/plugin versions, desktop or web environment, active project summary, and registered model formats. Returns detailed boolean format features (null means unknown; includes molang and java_cube_shade_direction_override) plus the format
get_project_inforead
hytale_animation_workflowreadGuide for creating animations for Hytale models. Covers 60 FPS timing, quaternion rotations, visibility keyframes, loop modes, and common animation patterns.
hytale_attachmentsreadGuide for creating and managing attachments in Hytale models. Covers attachment collections, piece bones, modular equipment, and best practices.
hytale_model_creationreadComprehensive guide for creating Hytale character and prop models. Covers format selection, node limits, shading modes, stretch, quads, and best practices.
list_export_formatsreadLists registered export codecs, file extensions, compile/export support, and availability under the native export action
list_modesreadLists Blockbench editor tabs/modes with IDs, names, native availability, and the current mode. Includes plugin-added modes. Use before set_mode to discover whether Edit, Paint, Animate, or Display is available for the current project. Camera angles are controlled separately by set_camera_angle.
list_particle_effectsreadLists particle effects loaded in Blockbench with their file, summary, texture status and validation warnings, every particle keyframe that uses them, keyframes that have no preview file or point at missing locators, and the client-entity particle_effects map a Bedrock pack needs.
list_particle_presetsreadLists particle effect presets (smoke, fire, sparks, magic, glow, snow, drip, ...), built-in sprites and textures, materials and facing modes. Every preset uses a texture that ships with Minecraft and Blockbench, so it previews and runs with no image file. Read this before create_particle_effect.
list_viewsreadLists render targets: the user
manage_particle_keyframesreadAdds, removes or lists particle keyframes on an animation
model_creation_strategyreadA strategy for creating a new 3D model in Blockbench.
no_descriptionread
no_executewriteFine.
resize_offscreen_viewreadChanges the pixel size of an offscreen view. The user
set_modewriteSwitches Blockbench
trigger_actionwriteTriggers an available Blockbench Action and respects its condition. The native action owns Undo; only a newly opened dialog may be auto-confirmed.
update_particle_effectwriteChanges an existing particle effect file with design knobs (only the components each knob owns are rewritten) or replaces it with raw JSON, validates it, saves it and refreshes the preview. Also loads an effect file from disk that Blockbench has not seen yet. Blockbench desktop only.
04

Trust audit

BLOCKgrade D · trust 62/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/tools/ui.ts:218
result = await eval(code.trim());
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.agents/skills/bun-development/SKILL.md:240
// Access environment variables
Why it matters. asks the agent to read credentials
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
headless/mesh/draft.ts:26
return Array.from({ length }, () => KEY_CHARS[Math.floor(Math.random() * KEY_CHARS.length)] ?? "a").join("");
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
server/tools/texture/texture-set-import.ts:32
const LEADING_BYTE_ORDER_MARK = /^/;
MEDIUMSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
.agents/skills/bun-development/SKILL.md:28
curl -fsSL https://bun.sh/install | bash
MEDIUMSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
.agents/skills/bun-development/SKILL.md:586
curl -fsSL https://bun.sh/install | bash
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_offscreen_view
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
lib/ai-disclosure.test.ts
ai-disclosure.test.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coderabbit.yaml
.coderabbit.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/harness.test.ts:394
'{"action":"read_context","path":"../../.env"}',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
headless/render/input.test.ts:35
texture("embedded", { source: embedded, path: secret, relative_path: "../../secret.png" }),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
headless/server.test.ts:141
const outside = await session.call("bbmodel_info", { file: "../../etc/model.bbmodel" });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
headless/server.test.ts:311
const outside = await session.call("blockbench_launch", { file: "../../elsewhere/model.bbmodel" });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
lib/particles/particles.test.ts:257
["../../outside/pwn", "/abs/tex", "C:/tex", "textures\\particle\\x", "textures//x"].forEach((texture) => {
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
server/net-security.test.ts:127
"127.0.0.1", "0.0.0.0", "10.1.2.3", "100.64.0.1", "169.254.169.254", "172.16.0.1", "172.31.255.255",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
server/tools/import.test.ts:148
"http://169.254.169.254/latest/meta-data",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/cli-track.test.ts:178
proxyUrl: "http://127.0.0.1:1234/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/cli-track.test.ts:198
mcpServers: { bench: { type: "http", url: "http://127.0.0.1:1234/mcp" } },
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/cli-track.test.ts:315
expect(settings.mcpServers.bench.httpUrl).toBe("http://127.0.0.1:1234/mcp");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/harness.test.ts:485
const client = await connect(`http://127.0.0.1:${http.port}/mcp`, id);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/proxy.ts:85
return `http://127.0.0.1:${this.http.port}/mcp`;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
headless/particle.test.ts:18
const PNG_2X4 = Uint8Array.from(atob("iVBORw0KGgoAAAANSUhEUgAAAAIAAAAECAYAAACk7+45AAAAFklEQVR4nGP838Dwn4GBgYEJRGBnAABUcQKGuqbVnwAAAABJRU5ErkJggg=="), (c) => c.charCodeAt(0));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
server/tools/camera.test.ts:73
return { frame: atob(item.data), structured: result.structuredContent };
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
server/tools/particle/host.ts:250
return Uint8Array.from(atob(base64), (character) => character.charCodeAt(0));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/particle-tools.test.ts:13
const PNG_2X4 = Uint8Array.from(atob("iVBORw0KGgoAAAANSUhEUgAAAAIAAAAECAYAAACk7+45AAAAFklEQVR4nGP838Dwn4GBgYEJRGBnAABUcQKGuqbVnwAAAABJRU5ErkJggg=="), (c) => c.charCodeAt(0));

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha 8b99cc7a4565full audit observations/trust-audit/mcp-server/jasonjgardner__blockbench.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-038b99cc7a4565BLOCKD62first audit
06

Questions

What is the Blockbench MCP server?

Adds MCP server to Blockbench

What tools does Blockbench expose?

49 in total: 36 read-only, 12 that write, and 1 that can delete or overwrite (delete_offscreen_view). Every one is listed on this page with its risk.

Is Blockbench safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (62/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Blockbench need?

No credential environment variables were found in its source, so it appears to need none.

How does Blockbench run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as blockbench-mcp at 1.10.0.

How current is this page?

The grade is for one exact copy of the source (8b99cc7a4565), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement