GardenArena GardenScript
REMOTE · GARDENARENA.IO · SCANNED SEP 24
Simulate farms, validate GardenScript and compare policies with Rust. No outbound LLM calls.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability79
- 79% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Partial
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 3769 tokens (~83/item across 45 items; 30 tools + 15 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management37
- Stability observed for 11 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the GardenArena GardenScript MCP server?
GardenArena GardenScript is a hosted endpoint at https://gardenarena.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · gardenarena.io
claude mcp add --transport http io-gardenarena-gardenscript 'https://gardenarena.io/mcp'
{
"mcpServers": {
"io-gardenarena-gardenscript": {
"url": "https://gardenarena.io/mcp"
}
}
} {
"servers": {
"io-gardenarena-gardenscript": {
"type": "http",
"url": "https://gardenarena.io/mcp"
}
}
} [mcp_servers.io-gardenarena-gardenscript] url = "https://gardenarena.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-gardenarena-gardenscript": {
"type": "remote",
"url": "https://gardenarena.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-gardenarena-gardenscript --url 'https://gardenarena.io/mcp' --transport streamable-http
mcp_servers:
io-gardenarena-gardenscript:
url: "https://gardenarena.io/mcp" {
"McpServers": {
"io-gardenarena-gardenscript": {
"Transport": "http",
"Url": "https://gardenarena.io/mcp"
}
}
} assistant mcp add io-gardenarena-gardenscript -t streamable-http -u 'https://gardenarena.io/mcp'
{
"mcpServers": {
"io-gardenarena-gardenscript": {
"type": "http",
"url": "https://gardenarena.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 0
- New tool “farm_campaign_get” functional
- New tool “farm_campaign_run” functional
- 14 Sept 26 +1
- Stability: unverified → 0.03 ▲ functional
- 13 Sept 26 72
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://gardenarena.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=gardenarena.io | CN=WE1,O=Google Trust Services,C=US | 11 Sept 2026 | 10 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 24b8b7ec2303f7af0e92345f21180d33 |
| SANs: gardenarena.io, *.gardenarena.io | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of gardenarena.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| gardenarena.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://challenges.cloudflare.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; media-src 'self' blob:; connect-src 'self' https://cloudflareinsights.com https://*.cloudflareinsights.com; worker-src 'self' blob:; frame-src 'self' https://challenges.cloudflare.com; frame-ancestors 'self'; base-uri 'self'; object-src 'none'; form-action 'self'; upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://gardenarena.io/mcp | Verified | 200 | |
| http (plaintext) | http://gardenarena.io/mcp | HTTPS enforced | 301 | https://gardenarena.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
artifact_verify ~30
Verify a SHA-256 digest against published contracts, scenarios and sealed entries.
| Name | Type | Req | Description |
|---|---|---|---|
| digest | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
bamboo_challenge_get ~54
Read the fixed 365-day bamboo training mission, exact Dry Patience reference, scenario hash, budgets and quotas. No run or publication. Read gardenarena://gardenscript/v0.5 for the full language.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
bamboo_training_artifact ~60
Read the exact reproducible request and expected result hashes for a private training run. Includes strategy sources: do not publish automatically. Full trace JSON downloadable through the documented POST export. No run or official ledger write.
| Name | Type | Req | Description |
|---|---|---|---|
| run_token | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
bamboo_training_explain ~64
Read a private training comparison and evidence-linked moments. Optional day 1-365 returns both actual Rust decision traces, not a rerun. Requires the private GardenArena run_token, not a provider credential.
| Name | Type | Req | Description |
|---|---|---|---|
| day | – | – | – |
| run_token | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
bamboo_training_run ~71
Consume one bounded private training run against Dry Patience after user agreement. GardenScript 0.5 bamboo only, fixed public scenario and budgets. Shared web/MCP quotas; temporary local storage, no official submission or publication, no LLM call. Keep run_token private.
| Name | Type | Req | Description |
|---|---|---|---|
| source | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
coop_workshop_get ~56
Read the playable chicken workshop mission: breeds, breeding/incubation, production balance, non-lethal predators, closed JSON commands, exact scenario and quotas. No simulation or database write. Distinct from GardenScript/official competitions.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
coop_workshop_run ~93
Execute one bounded Rust chicken-workshop journal after human agreement. journal_json is the complete closed JSON journal (64 KiB), NOT GardenScript or arbitrary code. Returns reproducible state, event explanations and an export for explicit human import in the 3D game. No persistent game, official write, provider API or automatic publication. Respect retry delays and the agreed call budget.
| Name | Type | Req | Description |
|---|---|---|---|
| journal_json | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
entry_create ~156
Create a Reality Trial 001 policy entry. Returns an explicit entry_id. Returns a private entry_nonce once; keep it for all mutations. An idempotent retry requires that nonce and never returns it again. Identity assurance can only be anonymous or declared. Does not occupy an official seat until the organizer confirms on the web. Write-gated.
| Name | Type | Req | Description |
|---|---|---|---|
| arena_id | string | – | – |
| competition_scope | string | – | – |
| entry_nonce | – | – | – |
| evaluation_mode | string | – | – |
| host_claim | string | – | – |
| idempotency_key | – | – | – |
| identity_assurance | string | – | – |
| model_claim | string | – | – |
| provider_claim | string | – | – |
| trial_id | string | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_autopilot_run ~136
Run a bounded pantry-oriented farmer tour after user agreement: 1–7 simulated days, 0–1000 game credits, at most 64 added ordinary commands. Deterministic Rust rules, not a live LLM. Gathers food, handles care and irrigation, cuts mature bamboo for supports, composts and cooks available ingredients. No sales, new animals, publication or background daemon. Returns the exact replayable journal and per-action reasons/costs; a human chooses whether to import.
| Name | Type | Req | Description |
|---|---|---|---|
| budget_credits | integer | – | – |
| journal_json | string | yes | – |
| max_days | integer | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_campaign_get ~56
Read chapter 2 stewardship-v1: exact teaching farm J95, three management choices, ten-day routine, success criteria and complete original journal. No calculation or publication; not the player's private farm. JSON plan, NOT GardenScript.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
farm_campaign_run ~142
Try the fixed J95 to J105 farm chapter after agreeing a finite call budget. choices_json is a CLOSED object: mission_id stewardship-v1, choices {harvest: pantry/kitchen/market, egg_reserve: 0/2/6, rotate: boolean}. At most ten days, 100 added ordinary commands; shared workshop quotas. Rust decides from current state, retains adverse days and reports costs/refusals/meals. No arbitrary journal, GardenScript, publication, persistent save, LLM call or background search. Return the complete export; human chooses adoption. Local meals do not imply full autonomy.
| Name | Type | Req | Description |
|---|---|---|---|
| choices_json | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_compare_get ~76
Read the bounded two-policy farm comparison contract and its fixed week-after-v1 teaching mission (exact J96 journal, two sources, seven days, 540 credits). V4 only, same start and days/budget per branch, no global winner or publication. Read the farm policy contract for syntax. No paired trial or persistent write.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
farm_compare_run ~170
Compare two GardenScript farm.v1 policies from the SAME complete v4 journal after agreeing a finite call budget. Two trials, 1–7 days and identical 0–1000 game-credit ceilings. Rust returns both branches, trace witnesses of the first work divergence and honest elapsed-day/command-cap metrics, never an overall winner. Charges two shared workshop quota units. No game mutation, persistence, publication, LLM calls or unattended search. Return the complete comparison export; only the human can adopt a branch in their browser. No legacy future-veto helper, v5 weather or official ranking.
| Name | Type | Req | Description |
|---|---|---|---|
| budget_credits | integer | – | – |
| journal_json | string | yes | – |
| max_days | integer | – | – |
| source_a | string | yes | – |
| source_b | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_next_event ~114
Advance a farm journal to the next detected important moment, checked daily for at most max_days (1–21). Use the full journal_json and care_json containing ration, access, ventilation, incubator. Consumes one agreed calculation call. Returns the accepted ordinary journal, unchanged Rust result, season guide and evidence-linked stop reason. No automatic care, publication or persistent write; human chooses whether to import.
| Name | Type | Req | Description |
|---|---|---|---|
| care_json | string | yes | – |
| journal_json | string | yes | – |
| max_days | integer | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_policy_get ~60
Read GardenScript 0.6 farm.v1: six decision channels, 29 current-state sensors, exact intention expansion, three application-authored presets and shared limits. No run, persistent write or LLM call. Read before writing a farm policy.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
farm_policy_run ~148
Run a GardenScript 0.6 farm.v1 policy from a COMPLETE v4/v5 journal after user agreement, within a finite call budget. Six decisions from each day's current snapshot become ordinary costed commands. No future weather archive access or cancellation of bad days: shortages pause AFTER commitment. Returns export, exact source, rule/sensor witnesses, accepted/rejected commands and costs. Not an official competition or the legacy precognitive safety helper. No LLM calls, publication, persistent game or daemon; human explicitly imports the result.
| Name | Type | Req | Description |
|---|---|---|---|
| budget_credits | integer | – | – |
| journal_json | string | yes | – |
| max_days | integer | – | – |
| source | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_policy_validate ~60
Validate a closed GardenScript 0.6 farm.v1 source, maximum 16 KiB. Local Rust only; line diagnostics and exact source/canonical hashes. Shared workshop quota; no run, persistence or publication.
| Name | Type | Req | Description |
|---|---|---|---|
| source | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_weather_get ~124
Read cached real MET Norway forecasts and a continuous Météo-France station archive for a chosen French commune INSEE code. Optional start_date and station_id retain an existing game's station/start when refreshing. Returns a frozen snapshot, station distance, dates and licences. Forecasts are not observations and never fill the tank. No game mutation, precise user location, paid API, LLM call or publication. Applying the snapshot requires an explicit closed weather_station command in a v5 game.
| Name | Type | Req | Description |
|---|---|---|---|
| commune_code | string | yes | – |
| start_date | – | – | – |
| station_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_weather_search ~53
Find French metropolitan communes by name or postcode for opt-in farm weather. Public administrative data, cached and bounded. No IP geolocation, precise address, game mutation or LLM call.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
farm_workshop_get ~38
Read the playable whole-farm mission, shared resources, closed JSON actions and farmer task contract. Educational simulation, no run or official write.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
farm_workshop_run ~82
Execute one bounded whole-farm Rust journal after human agreement, within the agreed call budget. journal_json is complete closed JSON, max 64 KiB, not GardenScript. Returns game state, evidence-linked farmer tasks and an export for explicit human import. No autonomous daemon, publication, LLM call or persistent game.
| Name | Type | Req | Description |
|---|---|---|---|
| journal_json | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
get_bamboo_scene ~90
Read one day (1-365, default UTC day of year) of the published Rust bamboo replay used by the 3D scene. Includes sensors, entrant and SHA-256 provenance. Synthetic exhibition only; not an observation, strategy evaluation or hydraulic forecast. Koi are decorative and unranked. No database access, simulation launch, external network or LLM call.
| Name | Type | Req | Description |
|---|---|---|---|
| day | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
get_garden_arena ~43
Read one arena's ruleset, scenario, capabilities, limits and status by slug. This performs no LLM call.
| Name | Type | Req | Description |
|---|---|---|---|
| arena_slug | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
get_garden_results ~36
Read the sealed results for a GardenScript arena. Performs no simulation or LLM call.
| Name | Type | Req | Description |
|---|---|---|---|
| arena_slug | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
list_garden_arenas ~50
List GardenScript arenas. This is local, read-only, and performs no LLM call.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| offset | integer | – | – |
| status | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
strategy_prepare_seal ~68
Prepare a review and return its confirmation_url for the human organizer. Requires the private entry_nonce. Does not grant authority to seal. The organizer must use their own web session; never operate that page for them.
| Name | Type | Req | Description |
|---|---|---|---|
| entry_id | string | yes | – |
| entry_nonce | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
strategy_seal ~87
Read acknowledgment of an already human-confirmed seal. This tool can NEVER create a seal: pending entries return human_confirmation_required. Give the preparation's confirmation_url to the organizer instead. Legacy receipt/handle arguments are ignored, never approval credentials.
| Name | Type | Req | Description |
|---|---|---|---|
| confirmation_handle | – | – | – |
| entry_id | string | yes | – |
| entry_nonce | string | yes | – |
| validation_receipt_id | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
strategy_validate ~58
Compile GardenScript for an existing entry without running the official scenario. Requires its private entry_nonce. Consumes that entry's validation budget.
| Name | Type | Req | Description |
|---|---|---|---|
| entry_id | string | yes | – |
| entry_nonce | string | yes | – |
| source | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
submit_garden_strategy ~110
Submit externally generated GardenScript to an arena. The source is validated again by the local Rust compiler. Disabled by default; operator-owned identity comes only from server environment, never from a model token.
| Name | Type | Req | Description |
|---|---|---|---|
| arena_slug | string | yes | – |
| entrant_name | string | yes | – |
| model_name | string | – | – |
| model_provider | string | – | – |
| model_version | string | – | – |
| prompt_sha256 | – | – | – |
| source | string | yes | – |
| transcript_sha256 | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
validate_gardenscript ~43
Validate and compile an untrusted GardenScript source with the local Rust compiler. This performs no LLM call and stores nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| source | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
What is the GardenArena GardenScript MCP server?
GardenArena GardenScript is an MCP server listed in the public MCP registry as io.gardenarena/gardenscript. Simulate farms, validate GardenScript and compare policies with Rust. No outbound LLM calls. This page covers its hosted endpoint (https://gardenarena.io/mcp).
Is the GardenArena GardenScript MCP server safe to use?
GardenArena GardenScript scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the GardenArena GardenScript MCP server expose?
GardenArena GardenScript exposes 30 tools: validate_gardenscript, get_bamboo_scene, bamboo_challenge_get, coop_workshop_get, coop_workshop_run, and 25 more. Their descriptions and schemas cost roughly 2,428 tokens of context every time the server is loaded.
Does the GardenArena GardenScript MCP server require authentication?
No. We connected to GardenArena GardenScript without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the GardenArena GardenScript MCP server still maintained?
GardenArena GardenScript is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.