Atlas / MCP servers / playcanvas / PlayCanvas Editor AI Automation

PlayCanvas Editor AI AutomationSAFE

mcp/playcanvas/playcanvas-editor-ai-automation

MCP Server for AI automation of the PlayCanvas Editor

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
125 73r · 42w · 10d
Transport
stdio
License
MIT
Stars
137
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/playcanvas/editor-mcp-server/actions/workflows/ci.yml) [](https://www.npmjs.com/package/@playcanvas/editor-mcp-server) [](https://github.com/playcanvas/editor-mcp-server/blob/main/LICENSE) [](https://discord.gg/RSaMRzg) [](https://www.reddit.com/r/PlayCanvas) [](https://x.com/intent/follow?screen_name=playcanvas)

An MCP server for automating the PlayCanvas Editor with an LLM. The MCP client is built into the Editor — no browser extension needed. Install the server into your MCP client of choice (Claude Code, Codex, Claude Desktop, Cursor, ...) and connect the Editor to it.

Installation

Requires Node.js 22.18+. The server is published to npm as `@playcanvas/editor-mcp-server` — a self-contained, zero-dependency bundle — so every client below runs it with npx. Nothing to clone or build.

Claude Code

claude mcp add playcanvas -- npx -y @playcanvas/edit
Read from source at commit 21f985f97a3eOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add editor-mcp-server -- npx -y @playcanvas/[email protected]
claude-desktop
{
  "mcpServers": {
    "editor-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@playcanvas/[email protected]"
      ]
    }
  }
}
03

Exposed tools (125)

73 read · 42 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_componentswrite
add_entity_scriptswrite
add_script_component_scriptwrite
apply_mergewrite
apply_template_overrideswrite
attach_scriptread
bake_lightmapsread
cancel_mergewrite
cancel_model_unwrapread
capture_runtimeread
capture_viewportread
clear_cubemap_prefilterdestructive
clear_selectiondestructive
close_branchread
convert_texture_assetread
create_assetswrite
create_branchwrite
create_buildwrite
create_checkpointwrite
create_cubemap_from_texturewrite
create_entitieswrite
create_scenewrite
create_texture_atlaswrite
delete_assetsdestructive
delete_branchdestructive
delete_builddestructive
delete_entitiesdestructive
delete_scenedestructive
diff_checkpointsread
download_assetread
download_buildread
duplicate_assetsread
duplicate_entitiesread
duplicate_sceneread
find_entities_by_scriptread
focus_cameraread
focus_viewportread
generate_texture_metadataread
get_anim_state_graphread
get_animation_eventsread
get_assetread
get_asset_referencesread
get_asset_textread
get_buildread
get_checkpointread
get_conflict_fileread
get_entityread
get_mergewrite
get_sceneread
get_selectionread
get_template_overridesread
hard_reset_checkpointdestructive
inject_inputread
instantiate_template_assetsread
launch_startwrite
launch_stopwrite
list_assetsread
list_branchesread
list_buildsread
list_checkpointsread
list_engine_versionsread
list_entitiesread
list_scenesread
list_store_licensesread
load_sceneread
modify_anim_state_graphwrite
modify_animation_eventswrite
modify_assetswrite
modify_bundle_assetwrite
modify_entitieswrite
modify_project_settingswrite
modify_scene_settingswrite
modify_settingswrite
modify_sprite_assetwrite
move_assetswrite
move_entity_scriptwrite
my_assets_importwrite
my_assets_searchread
open_branchread
prefilter_cubemapread
process_font_assetread
process_texture_variantsread
query_project_settingsread
query_runtime_stateread
query_scene_settingsread
query_settingsread
query_viewport_stateread
query_viewport_visibilityread
read_editor_logsread
read_runtime_logsread
redoread
reimport_assetsread
remove_componentsdestructive
remove_entity_scriptsdestructive
rename_scenewrite
reparent_entityread
replace_assetread
resolve_conflictsread
resolve_entitiesread
restore_checkpointread
revert_template_overridesread
script_parseread
search_entitiesread
set_asset_textwrite
set_material_diffusewrite
set_material_propertieswrite
set_primary_buildwrite
set_script_textwrite
set_selectionwrite
set_transform_gizmowrite
set_viewport_statewrite
set_viewport_visibilitywrite
sketchfab_getread
sketchfab_importwrite
sketchfab_searchread
start_mergewrite
store_downloadread
store_getread
store_searchread
switch_branchread
undoread
unlink_template_instancesread
unwrap_model_assetread
upload_assetswrite
vcs_statusread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (5 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_cubemap_prefilter, clear_selection, delete_assets, delete_branch, delete_build, delete_entities, delete_scene, hard_reset_checkpoint, remove_components, remove_entity_scripts
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/assets/material.ts:3
import type { WSS } from '../../wss.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/assets/script.ts:4
import type { WSS } from '../../wss.ts';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/wss.test.ts:51
assert.equal(await attempt('http://127.0.0.1:8080'), true, '127.0.0.1 dev origin should be allowed');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/wss.test.ts:62
assert.equal(await attempt('http://192.168.1.10:3000'), false, 'LAN origin must be rejected');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/inspector, @types/node, @types/ws, esbuild, eslint, publint, typescript, ws
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 21f985f97a3efull audit observations/trust-audit/mcp-server/playcanvas__playcanvas-editor-ai-automation.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0721f985f97a3eSAFEB89first audit
06

Questions

What is the PlayCanvas Editor AI Automation MCP server?

MCP Server for AI automation of the PlayCanvas Editor

What tools does PlayCanvas Editor AI Automation expose?

125 in total: 73 read-only, 42 that write, and 10 that can delete or overwrite (clear_cubemap_prefilter, clear_selection, delete_assets, delete_branch, delete_build). Every one is listed on this page with its risk.

Is PlayCanvas Editor AI Automation safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does PlayCanvas Editor AI Automation need?

No credential environment variables were found in its source, so it appears to need none.

How does PlayCanvas Editor AI Automation run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @playcanvas/editor-mcp-server at 0.7.1.

How current is this page?

The grade is for one exact copy of the source (21f985f97a3e), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement