PosecodeCAUTION
An open-source text language, parser, validator and Three.js renderer for inspectable 3D human movement.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Posecode
Kinematic motion as text.
An inspectable, editable movement format for animation tools, LLMs, and web products.
Like Mermaid for movement: small text documents for describing, validating, and rendering
deterministic human motion without hiding the source inside a black box.
Live Playground · Movement Library · Language Specification (SPEC.md) · LLM Authoring Guide · Examples · MCP Server
Why Posecode?
Animation clips and generated trajectories can show movement, but they often hide the semantic decisions that produced it.
Posecode keeps those decisions in readable source. A human can write the document, an animation tool can emit it, or an LLM can draft it. Parsing, validation, editing, and rendering do not require an AI model.
b8bce7d3820bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add posecode-mcp -- npx -y [email protected]
Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
posecode_authoring_guide | read | |
render_posecode | read | |
validate_posecode | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
jumping-jacks.fbx
const origin = `http://127.0.0.1:${port}`;const origin = `http://127.0.0.1:${port}`;const examplesDir = resolve(here, "../../../spec/examples");
const xbotAsset = new URL("../../../playground/public/models/xbot.glb", import.meta.url);"../../../spec/examples",
"../../../spec/examples",
"../../../playground/public/models/xbot.glb",
vscode-languageclient, @types/node, @types/vscode, esbuild, typescript
@changesets/cli, @vitest/coverage-v8, gifenc, playwright-core, tsx, typescript, vitest
esbuild
three, @types/node, @types/three
vscode-languageserver, vscode-languageserver-textdocument, @types/node, esbuild, tsx
docs/launch-media/dead-bug.gif
docs/launch-media/posecode-cut2-builder-16x9.mp4
docs/launch-media/posecode-cut2-builder-9x16.mp4
docs/launch-media/wall-sit.gif
docs/media/deadlift.gif
Gates applied: no_behavioural_pass.
b8bce7d3820bfull audit observations/trust-audit/mcp-server/posecode-dev__posecode.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b8bce7d3820b | CAUTION | B | 89 | first audit |
Questions
What is the Posecode MCP server?
An open-source text language, parser, validator and Three.js renderer for inspectable 3D human movement.
What tools does Posecode expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Posecode safe to connect to an agent?
With care. The audit graded it B (89/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Posecode need?
It reads POSECODE_TELEGRAM_BOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Posecode run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as posecode-playground at 0.2.2.
How current is this page?
The grade is for one exact copy of the source (b8bce7d3820b), read on 2026-10-07. The repository is watched and re-audited when it changes.