Atlas / MCP servers / sigee-min / Ashfox

AshfoxCAUTION

mcp/sigee-min/ashfox

Assets as Code for voxel games. Define models, textures, and sounds in code. Version them in Git. Build them with Ashfox.

Verdict
CAUTION
Grade
C
Trust score
75 /100
Exposed tools
26 10r · 11w · 5d
Transport
—
License
MIT
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Assets as Code. Built for voxel games.

Write the source. Build the world.

Griffin guardian · 6 motions · Build replay reconstructed from the finished model.

Models. Textures. Sound. All from code. Ashfox compiles native .ashfox files into game assets you can version, review and rebuild alongside your game.

**Explore the live examples →** · Read the DSL · Griffin source

Game assets, with a source of truth

A creature's proportions, its pixels, its rig and its motions can live in source files. So can the sound it makes. Ashfox turns those definitions into assets for voxel games and Minecraft.

That is Assets as Code: the editable asset lives in your repository. Your coding agent can work on it, your team can review the change, and your build can produce the deliverables.

What this makes possible

Resize a creature through shared dimensions. Keep its eyes one pixel wide. Reuse its rig across motions. Review the result and commit the source alongside the game that uses it.

Start with a sword. Build a creature.

Expl

Read from source at commit 3ed650a5d589OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add render-core --env GH_TOKEN=${GH_TOKEN} -- npx -y @ashfox/[email protected]
claude-desktop
{
  "mcpServers": {
    "render-core": {
      "command": "npx",
      "args": [
        "-y",
        "@ashfox/[email protected]"
      ],
      "env": {
        "GH_TOKEN": "${GH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (26)

10 read · 11 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_bonewriteAdds a bone to the current Blockbench compatibility session; not a canonical Ashfox authoring path.
add_cubewriteAdds a cube to the current Blockbench compatibility session; not a canonical Ashfox authoring path.
add_meshwriteAdds a mesh to the current Blockbench compatibility session; not a canonical Ashfox authoring path.
assign_texturereadBinds a texture to cubes/faces (no UV edits).
create_animation_clipwriteCreates an animation clip (low-level).
delete_animation_clipdestructiveDeletes an animation clip by id/name (or ids/names for bulk removal).
delete_bonedestructiveDeletes a bone from the current Blockbench compatibility session; not canonical Ashfox source.
delete_cubedestructiveDeletes a cube from the current Blockbench compatibility session; not canonical Ashfox source.
delete_meshdestructiveDeletes a mesh from the current Blockbench compatibility session; not canonical Ashfox source.
delete_texturedestructiveDeletes a texture by id or name.
demo_toolreaddemo
ensure_projectwriteEnsures a usable project. Reuses the active project by default and can create a new one when missing or on mismatch (per options). Use match/onMismatch/onMissing to control behavior. action=
export_trace_logreadFlushes the trace log to disk (writeFile/export) and returns the resource URI for the in-memory log.
get_project_statereadReturns the current project state (summary by default). Summary includes texture metadata and textureResolution. Full detail includes textureUsage (per-face mappings) when available.
list_capabilitiesreadReturns plugin capabilities and limits. Tool schemas are strict (extra fields are rejected).
paint_facesreadPaints one cube face with one drawing op (UV handled internally). Default coordSpace=face; use coordSpace=texture with width/height for texture-space coordinates.
paint_mesh_facereadPaints mesh face UV regions with one drawing op. Use scope=single_face (target.faceId required) or scope=all_faces. Default coordSpace=face; use coordSpace=texture with width/height for texture-space coordinates.
read_texturereadReads a texture image (dataUri + metadata) or saves a snapshot to .ashfox/tmp.
reload_pluginsreadReloads Blockbench plugins (confirm required).
set_frame_posewriteSets a pose frame for multiple bones at a single frame (rot/pos/scale).
set_trigger_keyframeswriteSets trigger keyframes (sound/particle/timeline), one key per call.
update_animation_clipwriteUpdates an animation clip by id/name.
update_bonewriteUpdates a bone in the current Blockbench compatibility session; not canonical Ashfox source.
update_cubewriteUpdates a cube in the current Blockbench compatibility session; not canonical Ashfox source.
update_meshwriteUpdates mesh geometry in the current Blockbench compatibility session; not canonical Ashfox source.
validatereadValidates the current project.
04

Trust audit

CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (8 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
assets/exports/fox/fox.glb
fox.glb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
assets/exports/goblin/goblin.glb
goblin.glb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
assets/exports/griffin/griffin.glb
griffin.glb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/audio-study/integration.js:13
const url = `http://127.0.0.1:${server.address().port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/audio-study/serve.js:72
return server.listen(port, '127.0.0.1', () => console.log(`Audio harness: http://127.0.0.1:${server.address().port}/`));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/item-study/serve.js:20
server.listen(Number(process.env.ASHFOX_ITEMS_PORT || 4318), '127.0.0.1', () => console.log(`Item studio: http://127.0.0.1:${server.address().port}`));
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/blockbench-runtime/src/plugin/pluginIcon.ts:2
'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAAa6SURBVFhH7ZV7UJNXGsbjTukWqlITgVxMICTkzl0EQZSLWClFZAULDZcSuXhBn
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_animation_clip, delete_bone, delete_cube, delete_mesh, delete_texture
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
assets/docs/claw.wav
claw.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/game-assets/.ashfoxworkspace
.ashfoxworkspace
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/items/.ashfoxworkspace
.ashfoxworkspace
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/minecraft/.ashfoxworkspace
.ashfoxworkspace
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/pipeline/.ashfoxworkspace
.ashfoxworkspace
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/resource-pack/.ashfoxworkspace
.ashfoxworkspace
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/blockbench-runtime/tests/domain/payload.test.ts
payload.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/blockbench-runtime/tests/usecases/texture-tools/faces/payload.test.ts
payload.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/blockbench-runtime/tests/runtime/logging.test.ts:73
logger.warn('warn', { token: 'secret' });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/audio-study/build.js:5
const root = process.env.ASHFOX_AUDIO_STORE || path.resolve(__dirname, '../../.ashfox/audio-native');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/audio-study/cli.js:4
const root = process.env.ASHFOX_AUDIO_STORE || path.resolve(__dirname, '../../.ashfox/audio-native');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/audio-study/harness.js:7
const bootstrap = () => Object.fromEntries(fs.readdirSync(path.join(__dirname, '../../examples/sounds/src'))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/audio-study/harness.js:8
.filter((n) => n.endsWith('.ashfox')).sort().map((n) => [`sounds/${n}`, fs.readFileSync(path.join(__dirname, '../../examples/sounds/src', n), 'utf8')]));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/audio-study/harness.js:47
}, sourceGuide: fs.readFileSync(path.join(__dirname, '../../docs/guides/sounds.md'), 'utf8'), examples: Object.fromEntries(Object.entries(bootstrap()).filter(([n]) => n.startsWith('sounds/'))),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/audio-study/README.md:19
The server opens at `http://127.0.0.1:3134`. The English viewer offers sound
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/audio-study/index.html:9
<header class="app-header"><a class="brand" href="http://127.0.0.1:3123/">ashfox<span class="brand-dot"></span></a><span class="app-name">Sound Viewer</span><span class="local-badge">Local viewer</spa
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/audio-study/package.json
@ashfox/audio-core, ts-node, @ashfox/asset-build
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 3ed650a5d589full audit observations/trust-audit/mcp-server/sigee-min__ashfox.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-093ed650a5d589CAUTIONC75first audit
06

Questions

What is the Ashfox MCP server?

Assets as Code for voxel games. Define models, textures, and sounds in code. Version them in Git. Build them with Ashfox.

What tools does Ashfox expose?

26 in total: 10 read-only, 11 that write, and 5 that can delete or overwrite (delete_animation_clip, delete_bone, delete_cube, delete_mesh, delete_texture). Every one is listed on this page with its risk.

Is Ashfox safe to connect to an agent?

With care. The audit graded it C (75/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Ashfox need?

It reads GH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (3ed650a5d589), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement