UnrealBLOCK
MCP server for Unreal Engine that uses Unreal Python Remote Execution
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP server for Unreal Engine that uses Unreal Python Remote Execution
Twitter · Discord
⚡ Differences
This server does not require installing a new UE plugin as it uses the built-in Python remote execution protocol.
Adding new tools/features is much faster to develop since it does not require any C++ code.
It can support the full Unreal Engine Python API
⚠️ Note
- This is not an official Unreal Engine project.
- Your AI agents or tools will have full access to your Editor.
- Review any changes your Client suggests before you approve them.
📦 Installation
📋 Requirements
- 🔧 Unreal Engine 5.4+ (verified, may work with earlier versions)
- 🟢 Node.js with npx
- 🤖 MCP Client (Claude, Cursor, etc.)
- Setting up your Editor:
- Open your Unreal Engine project
- Go to
Edit->Plugins - Search for "Python Editor Script Plugin" and enable it
- Restart the editor if prompted
- Go to
Edit->Project Settings - Search for "Python" and enable the "Enable Remote Execution" option
- Set up your Client:
- Edit your Claude (or Cursor) config
{
"mcpServers": {
"unreal": {
"command": "npx",
"args": [
"-y",
"@runreal/unreal-mcp"
]
}
}
}🔧 Troubleshooting
If you get an error similar to `MCP Unreal: U
ea676b9c8badOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add unreal-mcp -- npx -y @runreal/[email protected]
{
"mcpServers": {
"unreal-mcp": {
"command": "npx",
"args": [
"-y",
"@runreal/[email protected]"
]
}
}
}Exposed tools (21)
13 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
UnrealMCP | read | Unreal Engine mcp - use the documentation resource before using tools. Some tools run in the editor |
editor_console_command | write | Run a console command in Unreal\n\nExample output: (No output for most commands, executed silently)\n\nExecutes the console command without returning output. |
editor_create_object | write | Create a new object/actor in the world\n\nExample output: { |
editor_delete_object | destructive | Delete an object/actor from the world\n\nExample output: { |
editor_export_asset | read | Export an Unreal asset to text\n\nExample output: Binary data of the exported asset file\n\nReturns the raw binary content of the exported asset. |
editor_get_asset_info | read | Get information about an asset, including LOD levels for StaticMesh and SkeletalMesh assets\n\nExample output: [{ |
editor_get_asset_references | read | Get references for an asset\n\nExample output: [{ |
editor_get_map_info | read | Get detailed information about the current map/level\n\nExample output: { |
editor_get_world_outliner | read | Get all actors in the current world with their properties\n\nExample output: { |
editor_list_assets | read | List all Unreal assets\n\nExample output: [ |
editor_move_camera | write | Move the viewport camera to a specific location and rotation for positioning screenshots |
editor_project_info | read | Get detailed information about the current project\n\nExample output: { |
editor_run_python | write | Execute any python within the Unreal Editor. All python must have |
editor_search_assets | read | Search for assets by name or path with optional class filter\n\nExample output: { |
editor_take_screenshot | read | Take a screenshot of the Unreal Editor\n\nExample output: data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAA...\n\nReturns a base64-encoded PNG image of the current editor view. IF THIS ERRORS OUT MAKE SURE THE UNREAL ENGINE WINDOW IS FOCUSED |
editor_update_object | write | Update an existing object/actor in the world\n\nExample output: { |
editor_validate_assets | read | Validate assets in the project to check for errors\n\nExample output: { |
get_unreal_engine_path | read | Get the current Unreal Engine path |
get_unreal_project_path | read | Get the current Unreal Project path |
set_unreal_engine_path | write | Set the Unreal Engine path |
set_unreal_project_path | write | Set the Project path |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
return new Function(...Object.keys(vars), `return \`${tmpl}\`;`)(...Object.values(vars))editor_delete_object
const readmePath = path.join(__dirname, "../../README.md")
@modelcontextprotocol/sdk, unreal-remote-execution, zod, @biomejs/biome, @types/node, typescript
mcp.gif
- Your AI agents or tools will have full access to your Editor.
Gates applied: no_behavioural_pass.
ea676b9c8badfull audit observations/trust-audit/mcp-server/runreal__unreal-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ea676b9c8bad | BLOCK | D | 69 | first audit |
Questions
What is the Unreal MCP server?
MCP server for Unreal Engine that uses Unreal Python Remote Execution
What tools does Unreal expose?
21 in total: 13 read-only, 7 that write, and 1 that can delete or overwrite (editor_delete_object). Every one is listed on this page with its risk.
Is Unreal safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Unreal need?
No credential environment variables were found in its source, so it appears to need none.
How does Unreal run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @runreal/unreal-mcp at 0.1.4.
How current is this page?
The grade is for one exact copy of the source (ea676b9c8bad), read on 2026-10-07. The repository is watched and re-audited when it changes.