Atlas / MCP servers / ozankasikci / Unity Editor

Unity EditorSAFE

mcp/ozankasikci/unity-editor

An MCP server and client for LLMs to interact with Unity Projects

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
11 9r · 2w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
3
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/ozankasikci/unity-editor-mcp/actions/workflows/test-coverage.yml) [](https://codecov.io/gh/ozankasikci/unity-mcp) [](https://opensource.org/licenses/MIT) [](https://www.npmjs.com/package/unity-editor-mcp)

⚠️ This project is in beta and under heavy development. Features and APIs may change. Use at your own discretion.

Unity Editor MCP (Model Context Protocol) enables AI assistants like Claude and Cursor to interact directly with the Unity Editor, allowing for AI-assisted game development and automation.

🚀 Key Features

  • 🎮 GameObject Management: Create primitives, modify transforms, manage hierarchy, and delete objects
  • 🔧 Component System: Add, remove, modify, and list components on GameObjects with full property control
  • 🎭 Prefab Workflow: Complete prefab mode editing - open, modify, save, and exit with override management
  • 🔍 Smart Search: Find GameObjects by name, tag, layer, or component type with exact/partial matching
  • 📊 Scene Analysis: Analyze scene composition, component statistics, and prefab connections
  • 🎯 Component Inspection: Get component values, find objects by component, trace references between objects
  • 🎬 Scene Control: Create, load, save scenes, manage build settings, and work with multiple scenes
  • 🏃 Play Mode Testing: Start, pause, and stop play mode, check editor state and compilation status
  • 🖼️ Screenshot Capture: Take screenshots of Game View or Scene View with analysis capabilities
  • 🎨 Asset Management: Create and modify prefabs, materials, scripts with comprehensive property control
  • 🖱️ UI Automation: Interact with Unity UI ele
Read from source at commit 2188e3088a98OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add com.unity.editor-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "com.unity.editor-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (11)

9 read · 2 write · 0 destructive.

ToolRiskDescription
analyze_scene_contentsreadAnalyze and get statistics about the current scene
create_scenewriteCreate a new scene in Unity
find_by_componentreadFind all GameObjects that have a specific component type
get_component_valuesreadGet all properties and values of a specific component
get_gameobject_detailsreadGet detailed information about a specific GameObject
get_object_referencesreadFind all references to and from a GameObject
get_scene_inforeadGet detailed information about a scene
list_scenesreadList all scenes in the Unity project
load_scenereadLoad a scene in Unity
pingreadTest connection to Unity Editor
save_scenewriteSave the current scene in Unity
04

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/src/core/daemonServer.js:444
`http://127.0.0.1:${port}`,
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcp-server/.c8rc.json
.c8rc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/src/core/serverMetadata.js:6
const packageJsonPath = fileURLToPath(new URL('../../package.json', import.meta.url));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/src/handlers/analysis/AnalyzeSceneContentsToolHandler.js:2
import { analyzeSceneContentsToolDefinition } from '../../tools/analysis/analyzeSceneContents.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/src/handlers/analysis/FindByComponentToolHandler.js:2
import { findByComponentToolDefinition } from '../../tools/analysis/findByComponent.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/src/handlers/analysis/GetComponentValuesToolHandler.js:2
import { getComponentValuesToolDefinition } from '../../tools/analysis/getComponentValues.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/src/handlers/analysis/GetGameObjectDetailsToolHandler.js:2
import { getGameObjectDetailsToolDefinition } from '../../tools/analysis/getGameObjectDetails.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/tests/unit/core/daemonRegistry.test.js:38
url: 'http://127.0.0.1:49152/mcp',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/tests/unit/core/daemonRegistry.test.js:54
assert.equal(registry.url, 'http://127.0.0.1:49152/mcp');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/tests/unit/core/daemonServer.test.js:44
const response = await fetch(`http://127.0.0.1:${daemon.port}/health`);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/tests/unit/core/daemonServer.test.js:53
assert.equal(registry.url, `http://127.0.0.1:${daemon.port}/mcp`);
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
mcp-server/tests/security/menu-security-patch.test.js:47
{ input: 'Fіle/Quit', description: 'Cyrillic і instead of i' },
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
mcp-server/tests/security/menu-security-patch.test.js:48
{ input: 'Fіlе/Quit', description: 'Cyrillic і and е' },
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
mcp-server/tests/security/menu-security-patch.test.js:49
{ input: 'Filе/Quit', description: 'Cyrillic е instead of e' },
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
mcp-server/tests/security/menu-security-patch.test.js:57
{ input: 'Filε/Quit', description: 'Greek epsilon' },
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
mcp-server/tests/security/menu-security-patch.test.js:58
{ input: 'Fiλe/Quit', description: 'Greek lambda' },
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, ajv, c8, nodemon
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 2188e3088a98full audit observations/trust-audit/mcp-server/ozankasikci__unity-editor.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082188e3088a98SAFEB88first audit
06

Questions

What is the Unity Editor MCP server?

An MCP server and client for LLMs to interact with Unity Projects

What tools does Unity Editor expose?

11 in total: 9 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Unity Editor safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Unity Editor need?

No credential environment variables were found in its source, so it appears to need none.

How does Unity Editor run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as com.unity.editor-mcp at 0.16.0.

How current is this page?

The grade is for one exact copy of the source (2188e3088a98), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement