Minecraft Server MCP (tamo2918/Minecraft-Server-MCP) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 40 tools. No publisher has claimed this listing.

D
Caution
58/100

Minecraft Server MCP

Provides comprehensive administrator-level control for Minecraft Java Edition servers, allowing AI to manage world generation, server configuration, and player moderation. It enables remote execution of RCON commands, NBT data parsing, and automated backup management through the Model Context Protocol.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

tamo2918

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: MC_RCON_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes40 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

create_backup

Create a compressed backup (tar.gz) of a world. Safe to use while the server is running (uses save-off/save-on).

list_backups

List all available world backups, optionally filtered by world name.

restore_backup

Restore a world from a backup. Creates a safety backup of the current world before overwriting. The server MUST be stopped first.

delete_backup

Delete a backup file.

execute_command

Execute a Minecraft server command via RCON. Send any command without the leading '/'. Examples: 'time set 0', 'weather clear', 'give @a diamond 64', 'tp @a 0 64 0', 'setblock 0 64 0 diamond_block'.

execute_commands

Execute multiple Minecraft commands sequentially via RCON. Useful for batch operations like building structures or setting up game scenarios.

set_time

Set the world time. Presets: 'day' (1000), 'noon' (6000), 'sunset' (12000), 'night' (13000), 'midnight' (18000), 'sunrise' (23000). Or use a tick value.

set_weather

Set the weather. Options: clear, rain, thunder.

set_block

Place a block at a specific position. Uses the /setblock command.

fill_blocks

Fill a region with blocks. Uses the /fill command. Max 32,768 blocks per operation.

summon_entity

Summon an entity at a position. Examples: 'zombie', 'skeleton', 'villager', 'item_frame', 'armor_stand'.

teleport

Teleport a player or entity to coordinates or another entity.

give_item

Give items to a player. Examples: 'diamond', 'diamond_sword', 'golden_apple'.

get_server_properties

Read all server.properties settings. Returns key-value pairs with descriptions for known settings.

set_server_property

Set a server.properties value. The server must be restarted for changes to take effect. Common properties: gamemode, difficulty, level-seed, level-type, max-players, view-distance, motd, online-mode, pvp, spawn-protection.

set_server_properties_bulk

Set multiple server.properties values at once. Useful for configuring a new server or changing world generation settings.

get_game_rules

Get all game rules for the current world via RCON. Server must be running.

set_game_rule

Set a game rule value via RCON. Common rules: doDaylightCycle, doWeatherCycle, doMobSpawning, keepInventory, mobGriefing, doFireTick, randomTickSpeed, playersSleepingPercentage.

setup_world

Configure server.properties for generating a new world. Sets the level name, seed, world type, and other generation options. The server must be restarted (with the old world deleted or renamed) to generate the new world.

list_players

List all online players and the server's max player count.

op_player

Grant operator status to a player.

deop_player

Revoke operator status from a player.

kick_player

Kick a player from the server with an optional reason.

ban_player

Ban a player from the server.

pardon_player

Remove a ban from a player.

whitelist_manage

Manage the server whitelist.

set_gamemode

Change a player's game mode.

apply_effect

Apply a status effect to a player. Examples: speed, strength, regeneration, night_vision, invisibility, resistance.

list_ops

List all server operators from ops.json.

start_server

Start the Minecraft Java Edition server. Ensures RCON is enabled and waits for startup completion.

stop_server

Gracefully stop the Minecraft server. Uses RCON 'stop' command, falls back to stdin, then SIGKILL after 30s.

restart_server

Restart the Minecraft server (stop then start). Useful after configuration changes.

server_status

Get the current server status including running state, uptime, online players, and MOTD.

server_logs

Get recent server console output. Useful for debugging startup issues or monitoring activity.

validate_server

Check if the server directory, JAR file, and EULA are properly configured.

configure_mcp

Update the MCP server configuration (server directory, JAR path, RCON settings, Java path, JVM args).

list_worlds

List all Minecraft worlds in the server directory with their sizes.

get_world_info

Get detailed information about a world from its level.dat file, including seed, spawn point, game type, and version.

delete_world

Delete a world folder. WARNING: This is irreversible! Consider creating a backup first. The server must be stopped.

set_world_spawn

Set the world spawn point by modifying level.dat. The server must be stopped.

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configMC_BACKUP_DIRexport ="/path/to/backups"
configMC_JAVA_PATH
configMC_JVM_ARGS
configMC_RCON_HOST
🔐 secretMC_RCON_PASSWORDexport ="your_secure_password"
configMC_RCON_PORT
configMC_SERVER_DIRexport ="/path/to/minecraft-server"
configMC_SERVER_JAR
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

40/40 tools missing one or more hints — create_backup (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_backups (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); restore_backup (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +37 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

22/40 tool handlers declare input schemas (55%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

24/40 tool handlers wrap calls in try/catch (60%)

Wrap each tool handler body in try/catch and return a structured error response.

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/tamo2918/minecraft-server-mcp?variant=verified)](https://m8ven.ai/mcp/tamo2918/minecraft-server-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: a30a3480d68f1868625064e65cb3d8728774f968
code hash: babb20690122b1da5a78063cb8eb7a72d0a73f0bfd09558d720cd4f680f66c3d
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client