AshfoxCAUTION
Assets as Code for voxel games. Define models, textures, and sounds in code. Version them in Git. Build them with Ashfox.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Assets as Code. Built for voxel games.
Write the source. Build the world.
Griffin guardian · 6 motions · Build replay reconstructed from the finished model.
Models. Textures. Sound. All from code. Ashfox compiles native .ashfox files into game assets you can version, review and rebuild alongside your game.
**Explore the live examples →** · Read the DSL · Griffin source
Game assets, with a source of truth
A creature's proportions, its pixels, its rig and its motions can live in source files. So can the sound it makes. Ashfox turns those definitions into assets for voxel games and Minecraft.
That is Assets as Code: the editable asset lives in your repository. Your coding agent can work on it, your team can review the change, and your build can produce the deliverables.
What this makes possible
Resize a creature through shared dimensions. Keep its eyes one pixel wide. Reuse its rig across motions. Review the result and commit the source alongside the game that uses it.
Start with a sword. Build a creature.
Expl
3ed650a5d589OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add render-core --env GH_TOKEN=${GH_TOKEN} -- npx -y @ashfox/[email protected]{
"mcpServers": {
"render-core": {
"command": "npx",
"args": [
"-y",
"@ashfox/[email protected]"
],
"env": {
"GH_TOKEN": "${GH_TOKEN}"
}
}
}
}Exposed tools (26)
10 read · 11 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_bone | write | Adds a bone to the current Blockbench compatibility session; not a canonical Ashfox authoring path. |
add_cube | write | Adds a cube to the current Blockbench compatibility session; not a canonical Ashfox authoring path. |
add_mesh | write | Adds a mesh to the current Blockbench compatibility session; not a canonical Ashfox authoring path. |
assign_texture | read | Binds a texture to cubes/faces (no UV edits). |
create_animation_clip | write | Creates an animation clip (low-level). |
delete_animation_clip | destructive | Deletes an animation clip by id/name (or ids/names for bulk removal). |
delete_bone | destructive | Deletes a bone from the current Blockbench compatibility session; not canonical Ashfox source. |
delete_cube | destructive | Deletes a cube from the current Blockbench compatibility session; not canonical Ashfox source. |
delete_mesh | destructive | Deletes a mesh from the current Blockbench compatibility session; not canonical Ashfox source. |
delete_texture | destructive | Deletes a texture by id or name. |
demo_tool | read | demo |
ensure_project | write | Ensures a usable project. Reuses the active project by default and can create a new one when missing or on mismatch (per options). Use match/onMismatch/onMissing to control behavior. action= |
export_trace_log | read | Flushes the trace log to disk (writeFile/export) and returns the resource URI for the in-memory log. |
get_project_state | read | Returns the current project state (summary by default). Summary includes texture metadata and textureResolution. Full detail includes textureUsage (per-face mappings) when available. |
list_capabilities | read | Returns plugin capabilities and limits. Tool schemas are strict (extra fields are rejected). |
paint_faces | read | Paints one cube face with one drawing op (UV handled internally). Default coordSpace=face; use coordSpace=texture with width/height for texture-space coordinates. |
paint_mesh_face | read | Paints mesh face UV regions with one drawing op. Use scope=single_face (target.faceId required) or scope=all_faces. Default coordSpace=face; use coordSpace=texture with width/height for texture-space coordinates. |
read_texture | read | Reads a texture image (dataUri + metadata) or saves a snapshot to .ashfox/tmp. |
reload_plugins | read | Reloads Blockbench plugins (confirm required). |
set_frame_pose | write | Sets a pose frame for multiple bones at a single frame (rot/pos/scale). |
set_trigger_keyframes | write | Sets trigger keyframes (sound/particle/timeline), one key per call. |
update_animation_clip | write | Updates an animation clip by id/name. |
update_bone | write | Updates a bone in the current Blockbench compatibility session; not canonical Ashfox source. |
update_cube | write | Updates a cube in the current Blockbench compatibility session; not canonical Ashfox source. |
update_mesh | write | Updates mesh geometry in the current Blockbench compatibility session; not canonical Ashfox source. |
validate | read | Validates the current project. |
Trust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
fox.glb
goblin.glb
griffin.glb
const url = `http://127.0.0.1:${server.address().port}`;return server.listen(port, '127.0.0.1', () => console.log(`Audio harness: http://127.0.0.1:${server.address().port}/`));server.listen(Number(process.env.ASHFOX_ITEMS_PORT || 4318), '127.0.0.1', () => console.log(`Item studio: http://127.0.0.1:${server.address().port}`));'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAAa6SURBVFhH7ZV7UJNXGsbjTukWqlITgVxMICTkzl0EQZSLWClFZAULDZcSuXhBn
delete_animation_clip, delete_bone, delete_cube, delete_mesh, delete_texture
claw.wav
.ashfoxworkspace
.ashfoxworkspace
.ashfoxworkspace
.ashfoxworkspace
.ashfoxworkspace
payload.test.ts
payload.test.ts
logger.warn('warn', { token: 'secret' });const root = process.env.ASHFOX_AUDIO_STORE || path.resolve(__dirname, '../../.ashfox/audio-native');
const root = process.env.ASHFOX_AUDIO_STORE || path.resolve(__dirname, '../../.ashfox/audio-native');
const bootstrap = () => Object.fromEntries(fs.readdirSync(path.join(__dirname, '../../examples/sounds/src'))
.filter((n) => n.endsWith('.ashfox')).sort().map((n) => [`sounds/${n}`, fs.readFileSync(path.join(__dirname, '../../examples/sounds/src', n), 'utf8')]));}, sourceGuide: fs.readFileSync(path.join(__dirname, '../../docs/guides/sounds.md'), 'utf8'), examples: Object.fromEntries(Object.entries(bootstrap()).filter(([n]) => n.startsWith('sounds/'))),The server opens at `http://127.0.0.1:3134`. The English viewer offers sound
<header class="app-header"><a class="brand" href="http://127.0.0.1:3123/">ashfox<span class="brand-dot"></span></a><span class="app-name">Sound Viewer</span><span class="local-badge">Local viewer</spa
@ashfox/audio-core, ts-node, @ashfox/asset-build
Gates applied: no_behavioural_pass.
3ed650a5d589full audit observations/trust-audit/mcp-server/sigee-min__ashfox.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 3ed650a5d589 | CAUTION | C | 75 | first audit |
Questions
What is the Ashfox MCP server?
Assets as Code for voxel games. Define models, textures, and sounds in code. Version them in Git. Build them with Ashfox.
What tools does Ashfox expose?
26 in total: 10 read-only, 11 that write, and 5 that can delete or overwrite (delete_animation_clip, delete_bone, delete_cube, delete_mesh, delete_texture). Every one is listed on this page with its risk.
Is Ashfox safe to connect to an agent?
With care. The audit graded it C (75/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Ashfox need?
It reads GH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (3ed650a5d589), read on 2026-10-09. The repository is watched and re-audited when it changes.