Atlas / MCP servers / satelliteoflove / Godot

GodotBLOCK

mcp/satelliteoflove/godot-13

Give your AI assistant eyes and hands in the Godot editor: scene editing, input injection, deterministic playtesting, and live game state for agents

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
13 12r · 1w · 0d
Transport
stdio
License
MIT
Stars
172
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@satelliteoflove/godot-mcp) [](https://github.com/satelliteoflove/godot-mcp/actions/workflows/ci.yml) [](https://godotengine.org) [](https://nodejs.org) [](https://github.com/satelliteoflove/godot-mcp/blob/main/LICENSE)

Give your AI assistant eyes and hands in the Godot editor — and a running game it can actually playtest.

Why this one?

There are a few Godot MCP servers out there, and most can open a scene and poke at nodes. This one is built around a harder problem: letting an agent verify its own work. Run the game, drive it like a player, observe what actually happened, and prove the change did what it claimed — without you ferrying screenshots and error logs back and forth.

The pieces that make that possible, and that you won't find elsewhere:

  • Deterministic playtesting. Freeze the game clock, step exact slices of game time (or step until a condition holds), with inputs riding inside the window. Observation never races the game.
  • Cheap observation. Live entity state — positions, velocities, animation state, your own custom data — as structured JSON. Most "what's happening on screen?" questions get answered without spending vision tokens on a screenshot.
  • Real input. Named actions with analog strength, joypad buttons and stick vectors, raw keys with modifier combos, relative mouse-loo
Read from source at commit 3aca43b11262OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add godot-mcp -- npx -y @satelliteoflove/[email protected]
03

Exposed tools (13)

12 read · 1 write · 0 destructive.

ToolRiskDescription
animationreadAnimation query, playback, and editing tools
docsreadFetch Godot Engine documentation with smart extraction
editorreadEditor control, debugging, and screenshot tools
execwriteRun GDScript inside the running game for test scenario setup: one-shot state mutations plus persistent holder-managed nodes, behind a denylist accident guard.
game-timereadDeterministic game-clock control: freeze the running game, step a bounded slice of game time (or step until a condition holds) with inputs riding inside the window, then thaw — so observation is not racing ahead between tool calls.
inputreadInput injection for testing running games: named actions, joypad buttons, analog axes and stick vectors, raw keyboard keys with modifier combos, relative mouse-look, and text typing (no absolute cursor positioning)
nodereadNode manipulation and script attachment tools
profilerreadPerformance profiling: snapshots, per-frame time series with spike detection, active process inspection, signal connections
projectreadProject information tools
resourcereadResource inspection tools for SpriteFrames, TileSet, Materials, etc.
scenereadScene management tools
scene3dread3D spatial information and bounding box tools
tilemapreadTileMapLayer and GridMap editing tools (uses Godot 4.3+ TileMapLayer, not deprecated TileMap)
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (1 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/src/tools/profiler.ts:232
'Profile a running game; every action errors if no game is playing. Use snapshot for one-shot engine metrics, or start → get_data for a per-frame time series with percentile stats, frame-budget usage,
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
server/scripts/generate-docs.ts:310
node_path: '/root/Main/Player',
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
server/scripts/generate-docs.ts:311
parent_path: '/root/Main',
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
server/scripts/generate-docs.ts:312
new_parent_path: '/root/UI',
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
server/scripts/generate-docs.ts:321
root_path: '/root/Main',
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
server/src/utils/build-info.ts:48
out[rel] = createHash('sha1').update(readFileSync(f)).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
server/src/utils/build-info.ts:55
const h = createHash('sha1');
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
server/src/__tests__/core/doc-examples.test.ts:144
expect(val).toEqual({ path: '/root/Main/Player' });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:113
zip -r ../../godot-mcp-addon-${{ needs.release-please.outputs.version }}.zip godot_mcp
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/scripts/generate-docs.ts:32
const DOCS_DIR = join(__dirname, '../../docs');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/scripts/generate-docs.ts:34
const ROOT_README = join(__dirname, '../../README.md');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/src/__tests__/connection/timeouts.test.ts:12
} from '../../connection/timeouts.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/src/__tests__/connection/websocket.test.ts:5
import { GodotConnection } from '../../connection/websocket.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
server/package.json
@modelcontextprotocol/sdk, ws, zod, @types/node, @types/ws, @vitest/coverage-v8, nodemon, tsx
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 3aca43b11262full audit observations/trust-audit/mcp-server/satelliteoflove__godot-13.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-073aca43b11262BLOCKD69first audit
06

Questions

What is the Godot MCP server?

Give your AI assistant eyes and hands in the Godot editor: scene editing, input injection, deterministic playtesting, and live game state for agents

What tools does Godot expose?

13 in total: 12 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Godot safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Godot need?

No credential environment variables were found in its source, so it appears to need none.

How does Godot run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @satelliteoflove/godot-mcp at 4.1.11.

How current is this page?

The grade is for one exact copy of the source (3aca43b11262), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement