Atlas / MCP servers / lmwilki / Civ6

Civ6CAUTION

mcp/lmwilki/civ6

An MCP server that lets LLM agents play Civilization VI.

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
76 61r · 13w · 2d
Transport
stdio
License
MIT
Stars
208
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server that lets LLM agents play full games of Civilization VI.

Connect any MCP-compatible client — Claude Code, Codex, Gemini CLI, or your own — to a running Civ 6 game. The agent reads game state, moves units, manages cities, conducts diplomacy, and ends turns, all through the game's own rule-enforcing APIs. No cheats, no vision model required.

Capabilities

76 tools covering the full gameplay loop:

  • Units — list, move, attack, fortify, found cities, build improvements, promote, upgrade
  • Cities — inspect, set production, purchase units/buildings with gold, manage focus
  • Map — explore terrain, resources, fog of war; get settle and district placement advice
  • Research — browse tech and civic trees, set research targets
  • Diplomacy — relationships, modifiers, delegations, embassies, alliances, peace deals
  • Trade — propose and respond to deals, manage trade routes and destinations
  • Government — swap policy cards, change governments, choose era dedications
  • Governors — appoint, assign to cities, promote
  • Religion — found pantheons and religions, select beliefs, track spread
  • Great People — recruit, patronize, reject
  • World Congress — vote on resolutions, manage diplomatic favor
  • Victory — track progress across all victory conditions
  • Game lifecycle — save, load, launch, restart, kill

Every turn, end_turn takes before/after snapshots and reports what happened: units damaged, cities grew, production completed, threats spotted near your cities.

Quick start

1. Configure Civ 6

Enable the FireTuner debug interface and configure recommended settings:

Read from source at commit 1126821f1d7cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add web --env AZURE_SAS_TOKEN=${AZURE_SAS_TOKEN} --env AZURE_STORAGE_ACCOUNT_KEY=${AZURE_STORAGE_ACCOUNT_KEY} --env CONVEX_DEPLOY_KEY=${CONVEX_DEPLOY_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "web": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AZURE_SAS_TOKEN": "${AZURE_SAS_TOKEN}",
        "AZURE_STORAGE_ACCOUNT_KEY": "${AZURE_STORAGE_ACCOUNT_KEY}",
        "CONVEX_DEPLOY_KEY": "${CONVEX_DEPLOY_KEY}"
      }
    }
  }
}
03

Exposed tools (76)

61 read · 13 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
appoint_governorreadAppoint a new governor.
assign_governorreadAssign an appointed governor to a city.
change_governmentreadSwitch to a different government type.
choose_dedicationreadChoose a dedication/commemoration for the current era.
choose_pantheonreadFound a pantheon with the specified belief.
city_actionreadIssue a command to a city.
dismiss_popupreadDismiss any blocking popup in the game UI.
end_turnreadEnd the current turn.
form_alliancereadForm an alliance with another civilization.
found_religionreadFound a religion with a chosen name, follower belief, and founder belief.
get_builder_tasksreadGet a prioritized task board for all your builders.
get_citiesreadList all your cities with yields, population, production, growth, and loyalty.
get_city_productionreadList what a city can produce right now.
get_city_statesreadList known city-states with envoy counts and types.
get_dedicationsreadGet current era age, available dedications, and active ones.
get_diaryreadRead diary entries for game memory.
get_diplomacyreadGet diplomatic status with all known civilizations.
get_district_advisorreadShow best tiles to place a district with adjacency bonuses.
get_empire_resourcesreadGet a summary of all resources in and near your empire.
get_game_overviewreadGet a high-level summary of the current game state.
get_global_settle_advisorreadFind the best settle locations across the entire revealed map.
get_governorsreadGet governor status, appointed governors, and available types.
get_gp_advisorreadShow best cities to activate a Great Person, ranked by suitability.
get_great_peoplereadSee available Great People and recruitment progress.
get_map_areareadGet terrain info for tiles around a point.
get_notificationsreadGet all active game notifications.
get_pantheon_beliefsreadGet pantheon status and available beliefs for selection.
get_pathing_estimatereadEstimate how many turns a unit needs to reach a destination.
get_pending_diplomacyreadCheck for pending diplomacy encounters (e.g. first meeting with a civ).
get_pending_tradesreadCheck for pending trade deal offers from other civilizations.
get_policiesreadGet current government, policy slots, and available policies.
get_purchasable_tilesreadList tiles a city can purchase with gold.
get_religion_beliefsreadGet religion founding status, available religions, and available beliefs.
get_religion_spreadreadGet per-city religion breakdown across all visible cities.
get_settle_advisorreadList best settle locations near a settler unit.
get_spiesreadList all your spy units with position, rank, city, and available missions.
get_strategic_mapreadGet fog-of-war boundaries and unclaimed resources across the map.
get_tech_civicsreadGet technology and civic research status.
get_trade_destinationsreadList valid trade route destinations for a trader unit.
get_trade_optionsreadSee what both sides can trade — like opening the trade screen.
get_trade_routesreadGet trade route capacity, active routes, and trader status.
get_unit_promotionsreadList available promotions for a unit.
get_unitsreadList all your units with position, type, movement, and health.
get_victory_progressreadGet victory condition progress for all civilizations.
get_wonder_advisorreadShow best tiles to place a wonder with displacement cost analysis.
get_world_congressreadGet World Congress status, active resolutions, and voting options.
kill_gamedestructiveKill the Civ 6 game process and wait for Steam to deregister.
launch_gamereadLaunch Civ 6 via Steam.
list_saveswriteList available save files (normal, autosave).
load_game_savewriteLoad a save file by name. No need to call list_saves first.
load_savewriteLoad a save file by index from the most recent list_saves() result.
load_save_from_menuwriteNavigate the main menu to load a save via OCR-guided clicking.
patronize_great_personreadBuy a Great Person instantly with gold or faith.
promote_governorreadPromote a governor with a new ability.
promote_unitwriteApply a promotion to a unit.
propose_peacereadPropose white peace to a civilization you
propose_tradereadPropose a trade deal to another civilization.
purchase_itemreadPurchase a unit or building instantly with gold or faith.
purchase_tilereadBuy a tile for a city with gold.
queue_wc_votesreadPre-configure World Congress votes for the upcoming session.
recruit_great_personreadRecruit a Great Person using accumulated GP points.
reject_great_personreadPass on a Great Person (skip to the next one in that class).
respond_to_diplomacyreadRespond to a pending diplomacy encounter.
respond_to_tradereadAccept or reject a pending trade deal.
restart_and_loaddestructiveFull game recovery: kill, relaunch, and load a save.
run_luawriteRun arbitrary Lua code in the game. Advanced escape hatch — prefer built-in tools.
send_diplomatic_actionwriteSend a proactive diplomatic action to another civilization.
send_envoywriteSend an envoy to a city-state.
set_city_focuswriteSet a city
set_city_productionwriteSet what a city should produce.
set_policieswriteSet policy cards in government slots.
set_researchwriteChoose a technology or civic to research.
skip_remaining_unitsreadSkip all units that still have moves remaining.
spy_actionwriteSend a spy to a city or launch a spy mission.
unit_actionreadIssue a command to a unit.
upgrade_unitreadUpgrade a unit to its next type (e.g. Slinger -> Archer).
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (7 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

MEDIUMInventory / provenance · inv.binary · CWE-1104
evals/saves/0A_GROUND_CONTROL.Civ6Save
0A_GROUND_CONTROL.Civ6Save
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
evals/saves/0B_SNOWFLAKE.Civ6Save
0B_SNOWFLAKE.Civ6Save
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
evals/saves/0C_CRY_HAVOC.Civ6Save
0C_CRY_HAVOC.Civ6Save
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/civ_mcp/run_id.py:165
"beacon",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/civ_mcp/server.py:338
log.info("Web API starting on http://0.0.0.0:8000")
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
kill_game, restart_and_load
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
GEMINI.md
GEMINI.md
Why it matters. link not followed
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/convex_sync.py:186
return hashlib.md5("".join(lines).encode()).hexdigest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/components/strategic-map.tsx:5
import { api } from "../../convex/_generated/api";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/lib/use-diary-convex.ts:5
import { api } from "../../convex/_generated/api";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/lib/use-diary-convex.ts:6
import type { Doc } from "../../convex/_generated/dataModel";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/lib/use-elo-convex.ts:4
import { api } from "../../convex/_generated/api";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
web/package.json
class-variance-authority, clsx, convex, fumadocs-core, fumadocs-mdx, fumadocs-ui, lucide-react, modern-gif
Why it matters. 25 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
docs/architecture-diagrams.md:252
**GameCore (state 8)** is direct access to the simulation. You can read anything — unit positions, city yields, map terrain, tech progress — and you can write some things directly (kill a unit, set a
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 1126821f1d7cfull audit observations/trust-audit/mcp-server/lmwilki__civ6.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-071126821f1d7cCAUTIONB84first audit
06

Questions

What is the Civ6 MCP server?

An MCP server that lets LLM agents play Civilization VI.

What tools does Civ6 expose?

76 in total: 61 read-only, 13 that write, and 2 that can delete or overwrite (kill_game, restart_and_load). Every one is listed on this page with its risk.

Is Civ6 safe to connect to an agent?

With care. The audit graded it B (84/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Civ6 need?

It reads AZURE_SAS_TOKEN, AZURE_STORAGE_ACCOUNT_KEY and CONVEX_DEPLOY_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Civ6 run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as web at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (1126821f1d7c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement