No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by tomyud1 · MCP Server · ★ 411
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is godot-mcp safe to install? View the security audit →
Godot MCP Give your AI assistant full access to the Godot editor. Build games faster with Claude, Cursor, or any MCP-compatible AI — no copy-pasting, no context switching. AI reads, writes, and manipulates your scenes, scripts, nodes, and project settings directly. Godot 4.x · 42 tools · Interactive project visualizer · MIT license Quick Start Install Node.js (one-time setup) Download and run the installer from nodejs.org (LTS version). It's a standard installer — no terminal needed. Install the Godot plugin Inside the Godot editor, click the AssetLib tab at the top → search "mcp" → find "Godot AI Assistant tools MCP" → Install. Then go to Project → Project Settings → Plugins and enable the Godot MCP plugin. Add the server config to your AI client Claude Desktop — Settings → Developer → Edit Config → open the config file and paste: Mac / Linux: Windows: Cursor — Settings → MCP → Add Server: Mac / Linux: Windows: json { "mcpServers": { "godot": { "command": "cmd",
| Stars | 411 |
| Forks | 45 |
| Language | GDScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 66.9906389143017/100 |
| Open Issues | 14 |
| Last Updated | 2026-08-24 |
| Created | 2026-01-29 |
| Platforms | mcp |
| Est. Tokens | ~17k |
Explore other popular mcp server tools:
godot-mcp is MCP Server and Godot Plugin for AI-assisted game development. It is categorized as a MCP Server with 411 GitHub stars.
godot-mcp is primarily written in GDScript.
You can find installation instructions and usage details in the godot-mcp GitHub repository at github.com/tomyud1/godot-mcp. The project has 411 stars and 45 forks, indicating an active community.
godot-mcp is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: