by playcanvas
MCP Server for AI automation of the PlayCanvas Editor
# Add to your Claude Code skills
git clone https://github.com/playcanvas/editor-mcp-serverGuides for using mcp servers skills like editor-mcp-server.
Last scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@modelcontextprotocol/sdk: @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser is vulnerable to denial of service when url encoding is used",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion Regular Expression Denial of Service vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks \"alg\" (untrusted header.alg fallback)",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: js-yaml has prototype pollution in merge (<<)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-30T16:34:37.473Z",
"npmAuditRan": true,
"pipAuditRan": true
}See how editor-mcp-server compares with popular alternatives.
editor-mcp-server is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by playcanvas. MCP Server for AI automation of the PlayCanvas Editor. It has 137 GitHub stars.
editor-mcp-server returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/playcanvas/editor-mcp-server" and add it to your Claude Code skills directory (see the Installation section above).
editor-mcp-server is primarily written in TypeScript. It is open-source under playcanvas on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh editor-mcp-server against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
| User Manual | API Reference | Blog | Forum |
An MCP server for automating the PlayCanvas Editor with an LLM. The MCP client is built into the Editor — no browser extension needed. Install the server into your MCP client of choice (Claude Code, Codex, Claude Desktop, Cursor, …) and connect the Editor to it.
Requires Node.js 22.18+. The server is published to npm as @playcanvas/editor-mcp-server — a self-contained, zero-dependency bundle — so every client below runs it with npx. Nothing to clone or build.
claude mcp add playcanvas -- npx -y @playcanvas/editor-mcp-server
To share the server with everyone working on a repo, commit a .mcp.json to the project root instead:
{
"mcpServers": {
"playcanvas": {
"command": "npx",
"args": ["-y", "@playcanvas/editor-mcp-server"]
}
}
}
The Codex CLI and the Codex app share ~/.codex/config.toml, so one command covers both:
codex mcp add playcanvas -- npx -y @playcanvas/editor-mcp-server
[!NOTE] On Windows, use
codex mcp add playcanvas -- cmd /c npx -y @playcanvas/editor-mcp-server. If the server times out on first run (whilenpxdownloads the package), raisestartup_timeout_secunder[mcp_servers.playcanvas]in~/.codex/config.toml. ChatGPT itself only supports remote MCP connectors, so Codex is the OpenAI surface to use.
Go to Claude > Settings > Developer > Edit Config and add to claude_desktop_config.json:
{
"mcpServers": {
"playcanvas": {
"command": "npx",
"args": ["-y", "@playcanvas/editor-mcp-server"]
}
}
}
[!NOTE] On Windows, use
"command": "cmd"and"args": ["/c", "npx", "-y", "@playcanvas/editor-mcp-server"].
Select File > Preferences > Cursor Settings > MCP > Add new global MCP server and add the same JSON as for Claude Desktop.
The server listens for the Editor on WebSocket port 52000 by default. To change it, append --port <number> to the npx args and set the same port in the Editor's MCP popover.
52000) and click CONNECT.You can now issue commands from your MCP client.
[!NOTE] Only one Editor instance can be connected to the MCP server at a time.
[!IMPORTANT] Chromium gates a public page's connection to
127.0.0.1behind a local access permission (Chrome 142+, extended to WebSockets in Chrome 147) granted per origin, so allow it when prompted. In Chrome's site settings it isApps on device(loopback) —Local networkcovers LAN addresses and is not required. Only the Editor needs it: the launch page is bridged through the Editor rather than opening a socket of its own. If the Editor sits onConnecting, open its site settings and allow it — a blocked connection fails silently and looks exactly like a server that isn't running.
All tools act on the project open in the connected Editor. The server does not discover, select, create, delete, transfer, or administer projects, and project IDs are not tool inputs.
| Category | Driver coverage | Tools |
|---|---|---|
| Entity | Exact reads, filtered lists, resolution, search, script lookup, creation, schema-safe batch edits, duplication, hierarchy changes, deletion and component lifecycle | list_entities, get_entity, resolve_entities, search_entities, find_entities_by_script, create_entities, modify_entities, duplicate_entities, reparent_entity, delete_entities, add_components, remove_components |
| Scripts | Asset text reads and writes, parsing, attachment, attributes, ordering and removal | get_asset_text, set_asset_text, set_script_text, script_parse, add_script_component_script, attach_script, add_entity_scripts, remove_entity_scripts, move_entity_script |
| Assets | Exact reads, reference graphs, native creation, streamed upload and atomic download up to 512 MiB, schema-safe edits, moves, duplication, source replacement, reimport, deletion and materials | list_assets, get_asset, get_asset_references, create_assets, upload_assets, modify_assets, move_assets, duplicate_assets, replace_asset, reimport_assets, download_asset, delete_assets, set_material_diffuse, set_material_properties |
| Templates | Instantiation and instance override inspection, application, reversion and unlinking | instantiate_template_assets, get_template_overrides, apply_template_overrides, revert_template_overrides, unlink_template_instances |
| Animation | Animation state graph reads and edits, mapping-safe state renames and animation events | get_anim_state_graph, modify_anim_state_graph, get_animation_events, modify_animation_events |
| Processing | Lightmaps, model unwrap and cancellation, texture conversion, atlases, cubemaps, fonts, metadata, compressed variants, prefiltering, sprites and bundles | bake_lightmaps, unwrap_model_asset, cancel_model_unwrap, convert_texture_asset, create_texture_atlas, create_cubemap_from_texture, process_font_asset, generate_texture_metadata, process_texture_variants, prefilter_cubemap, clear_cubemap_prefilter, modify_sprite_asset, modify_bundle_asset |
| Scene | Exact reads, listing, loading, creation, duplication, rename, deletion and scene settings | list_scenes, get_scene, load_scene, create_scene, duplicate_scene, rename_scene, delete_scene, query_scene_settings, modify_scene_settings |
| Settings | Scoped project, private, user, session and scene settings reads and edits | query_settings, modify_settings, query_project_settings, modify_project_settings |
| Viewport | Camera and viewport state, visibility, capture and focus | query_viewport_state, set_viewport_state, query_viewport_visibility, set_viewport_visibility, capture_viewport, focus_viewport, focus_camera |
| Editor | Selection, edit-time logs, transform gizmo state, undo and redo | get_selection, set_selection, clear_selection, read_editor_logs, set_transform_gizmo, undo, redo |
| Builds | Listing, exact reads, creation options, streamed downloads, primary build selection and deletion | list_builds, get_build, create_build, download_build, set_primary_build, delete_build |
| Store | PlayCanvas Store search and import, licenses, Sketchfab search and import, and My Assets search and import | store_search, store_get, store_download, list_store_licenses, sketchfab_search, sketchfab_get, sketchfab_import, my_assets_search, my_assets_import |
| Runtime | Launch lifecycle and options, engine version discovery, screenshots, logs, live state inspection and keyboard, mouse and touch input | launch_start, launch_stop, list_engine_versions, capture_runtime, read_runtime_logs, query_runtime_state, inject_input |
| VCS | Branches, checkpoints, restore and hard reset, merges, conflict resolution and checkpoint diffs | vcs_status, list_branches, create_branch, switch_branch, close_branch, open_branch, delete_branch, list_checkpoints, create_checkpoint, get_checkpoint, restore_checkpoint, hard_reset_checkpoint, start_merge, get_merge, resolve_conflicts, get_conflict_file, apply_merge, cancel_merge, diff_checkpoints |
Asset transfers over 20 MiB use 1 MiB chunks. The server reads and writes local files incrementally, while the Editor spools uploads to browser storage and consumes downloads as streams instead of buffering the entire transfer in memory.
The Runtime tools drive a real Launch instance (the Editor's Launch button) so an agent can verify that a scene actually runs: screenshot the running app, read its console output, query live entity state, and inject keyboard/mouse/touch input. Allow pop-ups for the editor origin so launch_start can open the launch window — it reuses your existing PlayCanvas login session. The Editor relays runtime:* calls to that window, so it needs no local access permission of its own. Calling launch_start with no options adopts an app that is already running (adopted: true in the response) instead of restarting it; pass any option to force a fresh launch. It also reports the engine and graphics backend it ran with (engineVersion, deviceType) and a sessionId that changes on every launch;