Unity EditorSAFE
An MCP server and client for LLMs to interact with Unity Projects
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/ozankasikci/unity-editor-mcp/actions/workflows/test-coverage.yml) [](https://codecov.io/gh/ozankasikci/unity-mcp) [](https://opensource.org/licenses/MIT) [](https://www.npmjs.com/package/unity-editor-mcp)
⚠️ This project is in beta and under heavy development. Features and APIs may change. Use at your own discretion.
Unity Editor MCP (Model Context Protocol) enables AI assistants like Claude and Cursor to interact directly with the Unity Editor, allowing for AI-assisted game development and automation.
🚀 Key Features
- 🎮 GameObject Management: Create primitives, modify transforms, manage hierarchy, and delete objects
- 🔧 Component System: Add, remove, modify, and list components on GameObjects with full property control
- 🎭 Prefab Workflow: Complete prefab mode editing - open, modify, save, and exit with override management
- 🔍 Smart Search: Find GameObjects by name, tag, layer, or component type with exact/partial matching
- 📊 Scene Analysis: Analyze scene composition, component statistics, and prefab connections
- 🎯 Component Inspection: Get component values, find objects by component, trace references between objects
- 🎬 Scene Control: Create, load, save scenes, manage build settings, and work with multiple scenes
- 🏃 Play Mode Testing: Start, pause, and stop play mode, check editor state and compilation status
- 🖼️ Screenshot Capture: Take screenshots of Game View or Scene View with analysis capabilities
- 🎨 Asset Management: Create and modify prefabs, materials, scripts with comprehensive property control
- 🖱️ UI Automation: Interact with Unity UI ele
2188e3088a98OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add com.unity.editor-mcp -- npx -y [email protected]
{
"mcpServers": {
"com.unity.editor-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (11)
9 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_scene_contents | read | Analyze and get statistics about the current scene |
create_scene | write | Create a new scene in Unity |
find_by_component | read | Find all GameObjects that have a specific component type |
get_component_values | read | Get all properties and values of a specific component |
get_gameobject_details | read | Get detailed information about a specific GameObject |
get_object_references | read | Find all references to and from a GameObject |
get_scene_info | read | Get detailed information about a scene |
list_scenes | read | List all scenes in the Unity project |
load_scene | read | Load a scene in Unity |
ping | read | Test connection to Unity Editor |
save_scene | write | Save the current scene in Unity |
Trust audit
SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
`http://127.0.0.1:${port}`,.c8rc.json
const packageJsonPath = fileURLToPath(new URL('../../package.json', import.meta.url));import { analyzeSceneContentsToolDefinition } from '../../tools/analysis/analyzeSceneContents.js';import { findByComponentToolDefinition } from '../../tools/analysis/findByComponent.js';import { getComponentValuesToolDefinition } from '../../tools/analysis/getComponentValues.js';import { getGameObjectDetailsToolDefinition } from '../../tools/analysis/getGameObjectDetails.js';url: 'http://127.0.0.1:49152/mcp',
assert.equal(registry.url, 'http://127.0.0.1:49152/mcp');
const response = await fetch(`http://127.0.0.1:${daemon.port}/health`);assert.equal(registry.url, `http://127.0.0.1:${daemon.port}/mcp`);{ input: 'Fіle/Quit', description: 'Cyrillic і instead of i' },{ input: 'Fіlе/Quit', description: 'Cyrillic і and е' },{ input: 'Filе/Quit', description: 'Cyrillic е instead of e' },{ input: 'Filε/Quit', description: 'Greek epsilon' },{ input: 'Fiλe/Quit', description: 'Greek lambda' },@modelcontextprotocol/sdk, ajv, c8, nodemon
Gates applied: no_behavioural_pass.
2188e3088a98full audit observations/trust-audit/mcp-server/ozankasikci__unity-editor.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2188e3088a98 | SAFE | B | 88 | first audit |
Questions
What is the Unity Editor MCP server?
An MCP server and client for LLMs to interact with Unity Projects
What tools does Unity Editor expose?
11 in total: 9 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Unity Editor safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Unity Editor need?
No credential environment variables were found in its source, so it appears to need none.
How does Unity Editor run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as com.unity.editor-mcp at 0.16.0.
How current is this page?
The grade is for one exact copy of the source (2188e3088a98), read on 2026-10-08. The repository is watched and re-audited when it changes.