by playcanvas
MCP Server for AI automation of the PlayCanvas Editor
# Add to your Claude Code skills
git clone https://github.com/playcanvas/editor-mcp-serverGuides for using mcp servers skills like editor-mcp-server.
Last scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@modelcontextprotocol/sdk: @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser is vulnerable to denial of service when url encoding is used",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion Regular Expression Denial of Service vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks \"alg\" (untrusted header.alg fallback)",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: js-yaml has prototype pollution in merge (<<)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-30T16:34:37.473Z",
"npmAuditRan": true,
"pipAuditRan": true
}editor-mcp-server is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by playcanvas. MCP Server for AI automation of the PlayCanvas Editor. It has 131 GitHub stars.
editor-mcp-server returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/playcanvas/editor-mcp-server" and add it to your Claude Code skills directory (see the Installation section above).
editor-mcp-server is primarily written in TypeScript. It is open-source under playcanvas on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh editor-mcp-server against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
| User Manual | API Reference | Blog | Forum |
An MCP server for automating the PlayCanvas Editor with an LLM. The MCP client is built into the Editor — no browser extension needed. Install the server into your MCP client of choice (Claude Code, Codex, Claude Desktop, Cursor, …) and connect the Editor to it.
Requires Node.js 22.18+. The server is published to npm as @playcanvas/editor-mcp-server — a self-contained, zero-dependency bundle — so every client below runs it with npx. Nothing to clone or build.
claude mcp add playcanvas -- npx -y @playcanvas/editor-mcp-server
To share the server with everyone working on a repo, commit a .mcp.json to the project root instead:
{
"mcpServers": {
"playcanvas": {
"command": "npx",
"args": ["-y", "@playcanvas/editor-mcp-server"]
}
}
}
The Codex CLI and the Codex app share ~/.codex/config.toml, so one command covers both:
codex mcp add playcanvas -- npx -y @playcanvas/editor-mcp-server
[!NOTE] On Windows, use
codex mcp add playcanvas -- cmd /c npx -y @playcanvas/editor-mcp-server. If the server times out on first run (whilenpxdownloads the package), raisestartup_timeout_secunder[mcp_servers.playcanvas]in~/.codex/config.toml. ChatGPT itself only supports remote MCP connectors, so Codex is the OpenAI surface to use.
Go to Claude > Settings > Developer > Edit Config and add to claude_desktop_config.json:
{
"mcpServers": {
"playcanvas": {
"command": "npx",
"args": ["-y", "@playcanvas/editor-mcp-server"]
}
}
}
[!NOTE] On Windows, use
"command": "cmd"and"args": ["/c", "npx", "-y", "@playcanvas/editor-mcp-server"].
Select File > Preferences > Cursor Settings > MCP > Add new global MCP server and add the same JSON as for Claude Desktop.
The server listens for the Editor on WebSocket port 52000 by default. To change it, append --port <number> to the npx args and set the same port in the Editor's MCP popover.
52000) and click CONNECT.You can now issue commands from your MCP client.
[!NOTE] Only one Editor instance can be connected to the MCP server at a time.
All tools act on the project open in the connected Editor. The server does not discover, select, create, delete, transfer, or administer projects, and project IDs are not tool inputs.
| Category | Driver coverage | Tools |
|---|---|---|
| Entity | Exact reads, filtered lists, resolution, search, script lookup, creation, schema-safe batch edits, duplication, hierarchy changes, deletion and component lifecycle | list_entities, get_entity, resolve_entities, search_entities, find_entities_by_script, create_entities, modify_entities, duplicate_entities, reparent_entity, delete_entities, add_components, remove_components |
| Scripts | Asset text reads and writes, parsing, attachment, attributes, ordering and removal | get_asset_text, set_asset_text, set_script_text, script_parse, add_script_component_script, attach_script, add_entity_scripts, remove_entity_scripts, move_entity_script |
| Assets | Exact reads, reference graphs, native creation, streamed upload and atomic download up to 512 MiB, schema-safe edits, moves, duplication, source replacement, reimport, deletion and materials | list_assets, get_asset, get_asset_references, create_assets, upload_assets, modify_assets, move_assets, duplicate_assets, replace_asset, reimport_assets, download_asset, delete_assets, set_material_diffuse, set_material_properties |
| Templates | Instantiation and instance override inspection, application, reversion and unlinking | instantiate_template_assets, get_template_overrides, apply_template_overrides, revert_template_overrides, unlink_template_instances |
| Animation | Animation state graph reads and edits, mapping-safe state renames and animation events | get_anim_state_graph, modify_anim_state_graph, get_animation_events, modify_animation_events |
| Processing | Lightmaps, model unwrap and cancellation, texture conversion, atlases, cubemaps, fonts, metadata, compressed variants, prefiltering, sprites and bundles | bake_lightmaps, unwrap_model_asset, cancel_model_unwrap, convert_texture_asset, create_texture_atlas, create_cubemap_from_texture, process_font_asset, generate_texture_metadata, process_texture_variants, prefilter_cubemap, clear_cubemap_prefilter, modify_sprite_asset, modify_bundle_asset |
| Scene | Exact reads, listing, loading, creation, duplication, rename, deletion and scene settings | list_scenes, get_scene, load_scene, create_scene, duplicate_scene, rename_scene, delete_scene, query_scene_settings, modify_scene_settings |
| Settings | Scoped project, private, user, session and scene settings reads and edits | query_settings, modify_settings, query_project_settings, modify_project_settings |
| Viewport | Camera and viewport state, visibility, capture and focus | query_viewport_state, set_viewport_state, query_viewport_visibility, set_viewport_visibility, capture_viewport, focus_viewport, focus_camera |
| Editor | Selection, edit-time logs, transform gizmo state, undo and redo | get_selection, set_selection, clear_selection, read_editor_logs, set_transform_gizmo, undo, redo |
| Builds | Listing, exact reads, creation options, streamed downloads, primary build selection and deletion | list_builds, get_build, create_build, download_build, set_primary_build, delete_build |
| Store | PlayCanvas Store search and import, licenses, Sketchfab search and import, and My Assets search and import | store_search, store_get, store_download, list_store_licenses, sketchfab_search, sketchfab_get, sketchfab_import, my_assets_search, my_assets_import |
| Runtime | Launch lifecycle and options, screenshots, logs, live state inspection and keyboard, mouse and touch input | launch_start, launch_stop, capture_runtime, read_runtime_logs, query_runtime_state, inject_input |
| VCS | Branches, checkpoints, restore and hard reset, merges, conflict resolution and checkpoint diffs | vcs_status, list_branches, create_branch, switch_branch, close_branch, open_branch, delete_branch, list_checkpoints, create_checkpoint, get_checkpoint, restore_checkpoint, hard_reset_checkpoint, start_merge, get_merge, resolve_conflicts, get_conflict_file, apply_merge, cancel_merge, diff_checkpoints |
Asset transfers over 20 MiB use 1 MiB chunks. The server reads and writes local files incrementally, while the Editor spools uploads to browser storage and consumes downloads as streams instead of buffering the entire transfer in memory.
The Runtime tools drive a real Launch instance (the Editor's Launch button) so an agent can verify that a scene actually runs: screenshot the running app, read its console output, query live entity state, and inject keyboard/mouse/touch input. Allow pop-ups for the editor origin so launch_start can open the launch window — it reuses your existing PlayCanvas login session.
Every tool returns a consistent { data, meta } envelope: meta.status is ok or error (with an actionable message), list tools paginate via limit/offset and meta.nextCursor, and mutating tools return the resulting entity/asset summaries so follow-up list calls are rarely needed.
To hack on the server itself, ensure you have Node.js 22.18 or later installed. Follow these steps:
Clone the repository:
git clone https://github.com/playcanvas/editor-mcp-server.git
cd editor-mcp-server
Install dependencies:
npm install
Start the server (Node runs the TypeScript source directly — no build step):
npm run watch
Point your MCP client at the checkout instead of the npm package with "command": "node" and "args": ["/path/to/editor-mcp-server/src/server.ts"].
npm run debug starts the server under the MCP Inspector and npm run build produces the self-contained bundle that gets published.