Atlas / MCP servers / lpigeon / Unitree Go2

Unitree Go2SAFE

mcp/lpigeon/unitree-go2

The Unitree Go2 MCP Server is a server built on the MCP that enables users to control the Unitree Go2 robot using natural language commands interpreted by a LLM.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 11r · 1w · 0d
Transport
stdio
License
Apache-2.0
Stars
87
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The Unitree Go2 MCP Server is a server built on the Model Context Protocol (MCP) that enables users to control the Unitree Go2 robot using natural language commands interpreted by a Large Language Model (LLM). These commands are translated into ROS2 instructions, allowing the robot to perform corresponding actions.

Requirements

  • Unitree Go2 robot
  • Ubuntu 20.04 or 22.04
  • ROS2 environment : Humble(recommended) or Foxy

MCP Functions

You can find the list of functions in the MCPFUNCTIONS.md.

Installation

1. Setup unitree_ros2 environment

https://github.com/unitreerobotics/unitree_ros2

  • You need to complete the setup up to `Step 2: Connect and test` in the repository linked above.

2. Clone this repository

git clone https://github.com/lpigeon/unitree-go2-mcp-server.git
cd unitree-go2-mcp-server

3. uv Installation

  • To install uv, you can use the following command:
curl -LsSf https://astral.sh/uv/install.sh | sh

or

pip install uv
  • Create virtual environment and activate it (Optional)
uv venv
source .venv/bin/activate

4. MCP Server Configuration

Set MCP setting to mcp.json.

Please keep in mind that the configuration must be done on the PC connected to the Go2.

{
"mcpServers": {
"unitree-go2-mcp-server": {
"command": "uv",
"args": [
"--directory",
"/ABSOLUTE/PATH/TO/PARENT/FOLDER/unitree-go2-mcp-server",
"run",
"server.py"
]
}
}
}

If y

Read from source at commit 39b90c6ff99dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add unitree-go2-mcp-server -- uvx unitree-go2-mcp-server
claude-desktop
{
  "mcpServers": {
    "unitree-go2-mcp-server": {
      "command": "uvx",
      "args": [
        "unitree-go2-mcp-server"
      ]
    }
  }
}
03

Exposed tools (12)

11 read · 1 write · 0 destructive.

ToolRiskDescription
danceread_, msg = wirelesscontroller.dance()
get_topicsreadif use_rosbridge:
greetread_, msg = wirelesscontroller.greet()
jump_forwardread_, msg = wirelesscontroller.jump_forward()
loveread_, msg = wirelesscontroller.love()
pounceread_, msg = wirelesscontroller.pounce()
pub_wirelesscontrollerreadlx = convert_velocity_to_wirelesscontroller(linear_y)
shake_handsread_, msg = wirelesscontroller.shake_hands()
sit_downread_, msg = wirelesscontroller.sit_down()
stand_up_from_a_fallread_, msg = wirelesscontroller.stand_up_from_a_fall()
stopwrite_, msg = wirelesscontroller.stop()
stretchread_, msg = wirelesscontroller.stretch()
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (4)

INFOInventory / provenance · inv.oversize · CWE-1104
img/contextual_understanding.gif
img/contextual_understanding.gif
Why it matters. 23072708 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
img/how_to_use_2.gif
img/how_to_use_2.gif
Why it matters. 26549102 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
img/task_test.gif
img/task_test.gif
Why it matters. 38671529 bytes not read
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:37
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 39b90c6ff99dfull audit observations/trust-audit/mcp-server/lpigeon__unitree-go2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0739b90c6ff99dSAFEB89first audit
06

Questions

What is the Unitree Go2 MCP server?

The Unitree Go2 MCP Server is a server built on the MCP that enables users to control the Unitree Go2 robot using natural language commands interpreted by a LLM.

What tools does Unitree Go2 expose?

12 in total: 11 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Unitree Go2 safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Unitree Go2 need?

No credential environment variables were found in its source, so it appears to need none.

How does Unitree Go2 run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as unitree-go2-mcp-server.

How current is this page?

The grade is for one exact copy of the source (39b90c6ff99d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement