Unitree Go2SAFE
The Unitree Go2 MCP Server is a server built on the MCP that enables users to control the Unitree Go2 robot using natural language commands interpreted by a LLM.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The Unitree Go2 MCP Server is a server built on the Model Context Protocol (MCP) that enables users to control the Unitree Go2 robot using natural language commands interpreted by a Large Language Model (LLM). These commands are translated into ROS2 instructions, allowing the robot to perform corresponding actions.
Requirements
MCP Functions
You can find the list of functions in the MCPFUNCTIONS.md.
Installation
1. Setup unitree_ros2 environment
https://github.com/unitreerobotics/unitree_ros2
- You need to complete the setup up to `Step 2: Connect and test` in the repository linked above.
2. Clone this repository
git clone https://github.com/lpigeon/unitree-go2-mcp-server.git cd unitree-go2-mcp-server
3. uv Installation
- To install
uv, you can use the following command:
curl -LsSf https://astral.sh/uv/install.sh | sh
or
pip install uv
- Create virtual environment and activate it (Optional)
uv venv source .venv/bin/activate
4. MCP Server Configuration
Set MCP setting to mcp.json.
Please keep in mind that the configuration must be done on the PC connected to the Go2.
{
"mcpServers": {
"unitree-go2-mcp-server": {
"command": "uv",
"args": [
"--directory",
"/ABSOLUTE/PATH/TO/PARENT/FOLDER/unitree-go2-mcp-server",
"run",
"server.py"
]
}
}
}If y
39b90c6ff99dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add unitree-go2-mcp-server -- uvx unitree-go2-mcp-server
{
"mcpServers": {
"unitree-go2-mcp-server": {
"command": "uvx",
"args": [
"unitree-go2-mcp-server"
]
}
}
}Exposed tools (12)
11 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
dance | read | _, msg = wirelesscontroller.dance() |
get_topics | read | if use_rosbridge: |
greet | read | _, msg = wirelesscontroller.greet() |
jump_forward | read | _, msg = wirelesscontroller.jump_forward() |
love | read | _, msg = wirelesscontroller.love() |
pounce | read | _, msg = wirelesscontroller.pounce() |
pub_wirelesscontroller | read | lx = convert_velocity_to_wirelesscontroller(linear_y) |
shake_hands | read | _, msg = wirelesscontroller.shake_hands() |
sit_down | read | _, msg = wirelesscontroller.sit_down() |
stand_up_from_a_fall | read | _, msg = wirelesscontroller.stand_up_from_a_fall() |
stop | write | _, msg = wirelesscontroller.stop() |
stretch | read | _, msg = wirelesscontroller.stretch() |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
img/contextual_understanding.gif
img/how_to_use_2.gif
img/task_test.gif
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
39b90c6ff99dfull audit observations/trust-audit/mcp-server/lpigeon__unitree-go2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 39b90c6ff99d | SAFE | B | 89 | first audit |
Questions
What is the Unitree Go2 MCP server?
The Unitree Go2 MCP Server is a server built on the MCP that enables users to control the Unitree Go2 robot using natural language commands interpreted by a LLM.
What tools does Unitree Go2 expose?
12 in total: 11 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Unitree Go2 safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Unitree Go2 need?
No credential environment variables were found in its source, so it appears to need none.
How does Unitree Go2 run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as unitree-go2-mcp-server.
How current is this page?
The grade is for one exact copy of the source (39b90c6ff99d), read on 2026-10-07. The repository is watched and re-audited when it changes.