OsrsSAFE
mcp server for AI to understand osrs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/jayarrowz-mcp-osrs)
OSRS MCP Server [](https://smithery.ai/server/@jayarrowz/mcp-osrs)
MCP Server for interacting with the Old School RuneScape (OSRS) Wiki API and data files. This server provides tools to search the OSRS Wiki and access game data definitions through the Model Context Protocol.
Tools
This server implements the following tools:
OSRS Wiki Methods
osrs_wiki_search- Search the OSRS Wiki for pages matching a search termosrs_wiki_get_page_info- Get information about specific pages on the OSRS Wikiosrs_wiki_parse_page- Get the parsed HTML content of a specific OSRS Wiki page
Game Data Search Methods
search_varptypes- Search the varptypes.txt file for player variables (varps) that store player state and progresssearch_varbittypes- Search the varbittypes.txt file for variable bits (varbits) that store individual bits from varpssearch_iftypes- Search the iftypes.txt file for interface definitions used in the game's UIsearch_invtypes- Search the invtypes.txt file for inventory type definitions in the gamesearch_loctypes- Search the loctypes.txt file for location/object type definitions in the game worldsearch_npctypes- Search the npctypes.txt file for NPC (non-player character) definitionssearch_objtypes- Search the objtypes.txt file for object/
d9a4fe82834eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-osrs -- npx -y @jayarrowz/[email protected]
{
"mcpServers": {
"mcp-osrs": {
"command": "npx",
"args": [
"-y",
"@jayarrowz/[email protected]"
]
}
}
}Exposed tools (23)
23 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_file_details | read | Get details about a file in the data directory. |
get_ge_latest | read | Get the latest Grand Exchange high and low prices for a specific item by its ID. |
get_ge_timeseries | read | Get historical time-series price data for an item at a given interval (5m, 1h, 6h, 24h). Returns up to 365 data points. |
list_data_files | read | List available data files in the data directory. |
lookup_player | read | Look up an OSRS player |
osrs_wiki_get_page_info | read | Get information about specific pages on the OSRS Wiki. |
osrs_wiki_parse_page | read | Get the parsed HTML content of a specific OSRS Wiki page. |
osrs_wiki_search | read | Search the OSRS Wiki for pages matching a search term. |
search_data_file | read | Search any file in the data directory for matching entries. |
search_ge_items | read | Search for Grand Exchange tradeable items by name. Uses an exact/prefix/substring match. Returns item IDs, names, buy limits, and alch values. |
search_iftypes | read | Search the iftypes.txt file for interface definitions used in the game |
search_invtypes | read | Search the invtypes.txt file for inventory type definitions in the game. |
search_loctypes | read | Search the loctypes.txt file for location/object type definitions in the game world. |
search_npctypes | read | Search the npctypes.txt file for NPC (non-player character) definitions. |
search_objtypes | read | Search the objtypes.txt file for object/item definitions in the game. |
search_rowtypes | read | Search the rowtypes.txt file for row definitions used in various interfaces. |
search_seqtypes | read | Search the seqtypes.txt file for animation sequence definitions. |
search_soundtypes | read | Search the soundtypes.txt file for sound effect definitions in the game. |
search_spottypes | read | Search the spottypes.txt file for spot animation (graphical effect) definitions. |
search_spritetypes | read | Search the spritetypes.txt file for sprite image definitions used in the interface. |
search_tabletypes | read | Search the tabletypes.txt file for interface tab definitions. |
search_varbittypes | read | Search the varbittypes.txt file for variable bits (varbits) that store individual bits from varps. |
search_varptypes | read | Search the varptypes.txt file for player variables (varps) that store player state and progress. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
@modelcontextprotocol/sdk, axios, axios-retry, osrs-json-hiscores, zod, zod-to-json-schema, @types/jest, @types/node
data/loctypes.txt
data/objtypes.txt
Gates applied: no_behavioural_pass.
d9a4fe82834efull audit observations/trust-audit/mcp-server/jayarrowz__osrs.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d9a4fe82834e | SAFE | B | 89 | first audit |
Questions
What is the Osrs MCP server?
mcp server for AI to understand osrs
What tools does Osrs expose?
23 in total: 23 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Osrs safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Osrs need?
No credential environment variables were found in its source, so it appears to need none.
How does Osrs run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @jayarrowz/mcp-osrs at 0.7.2.
How current is this page?
The grade is for one exact copy of the source (d9a4fe82834e), read on 2026-10-08. The repository is watched and re-audited when it changes.