Unity IntegrationSAFE
Enable AI Agents to Control Unity
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://modelcontextprotocol.io/introduction) [](https://smithery.ai/server/@quazaai/unitymcpintegration) [](https://unity.com) [](https://nodejs.org) [](https://www.typescriptlang.org) [](https://developer.mozilla.org/en-US/docs/Web/API/WebSockets_API)
[](https://github.com/quazaai/UnityMCPIntegration/stargazers) [](https://github.com/quazaai/UnityMCPIntegration/network/members) [](https://github.com/quazaai/UnityMCPIntegration/blob/main/LICENSE)
This package provides a seamless integration between Model Context Protocol (MCP) and Unity Editor, allowing AI assistants to understand and interact with your Unity projects in real-time. With this integration, AI assistants can access information about your scene hierarchy, project settings, and execute code directly in the Unity Editor context.
📚 Features
- Browse and manipulate project files directly
- Access real-time information about your Unity project
- Understand your scene hierarchy and game objects
- Execute C# code directly in the Unity Editor
- Monitor logs and errors
- Control the Editor's play mode
- Wait Fo
6759c910d6e7OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add com.quaza.unitymcp -- npx -y [email protected]
{
"mcpServers": {
"com.quaza.unitymcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (15)
12 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
directory_tree | read | Get a recursive tree view of files and directories in the Unity project as a JSON structure. |
edit_file | write | Make precise edits to a text file in the Unity project. Returns a git-style diff showing changes. |
execute_editor_command | write | Execute C# code directly in the Unity Editor - allows full flexibility including custom namespaces and multiple classes |
find_assets_by_type | read | Find all Unity assets of a specified type (e.g., Material, Prefab, Scene, Script) in the project. Set searchPath to an empty string to search the entire Assets folder. |
get_current_scene_info | read | Retrieve information about the current scene in Unity Editor with configurable detail level |
get_editor_state | read | Get the current Unity Editor state including project information |
get_file_info | read | Retrieve detailed metadata about a file or directory in the Unity project. |
get_game_objects_info | read | Retrieve detailed information about specific GameObjects in the current scene |
get_logs | read | Retrieve Unity Editor logs with filtering options |
list_directory | read | Get a listing of all files and directories in a specified path in the Unity project. Paths are relative to the Assets folder unless absolute. For example, use |
read_file | read | Read the contents of a file from the Unity project. Paths are relative to the project |
read_multiple_files | read | Read the contents of multiple files from the Unity project simultaneously. |
search_files | read | Recursively search for files and directories matching a pattern in the Unity project. |
verify_connection | read | Verify that the MCP server has an active connection to Unity Editor |
write_file | destructive | Create a new file or completely overwrite an existing file in the Unity project. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
write_file
ws, diff, minimatch, zod, zod-to-json-schema, @types/node, @types/ws, @types/diff
Gates applied: no_behavioural_pass.
6759c910d6e7full audit observations/trust-audit/mcp-server/quazaai__unity-integration-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6759c910d6e7 | SAFE | B | 89 | first audit |
Questions
What is the Unity Integration MCP server?
Enable AI Agents to Control Unity
What tools does Unity Integration expose?
15 in total: 12 read-only, 2 that write, and 1 that can delete or overwrite (write_file). Every one is listed on this page with its risk.
Is Unity Integration safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Unity Integration need?
No credential environment variables were found in its source, so it appears to need none.
How does Unity Integration run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as com.quaza.unitymcp at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (6759c910d6e7), read on 2026-10-07. The repository is watched and re-audited when it changes.