io.github.Redseb/rpgmaker-mz-mcp
NPM · RPGMAKER-MZ-MCP · SCANNED SEP 21
MCP server for RPG Maker MZ: maps, tile painting, events, database editing, and validation.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 95 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 48 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability68
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 19486 tokens (~163/item across 119 items; 119 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
- Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "delete_map" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 119 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.Redseb/rpgmaker-mz-mcp server?
io.github.Redseb/rpgmaker-mz-mcp runs locally as an npm package, launched with npx -y rpgmaker-mz-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · rpgmaker-mz-mcp
claude mcp add redseb-rpgmaker-mz-mcp -- npx -y rpgmaker-mz-mcp
{
"mcpServers": {
"redseb-rpgmaker-mz-mcp": {
"command": "npx",
"args": [
"-y",
"rpgmaker-mz-mcp"
]
}
}
} {
"servers": {
"redseb-rpgmaker-mz-mcp": {
"command": "npx",
"args": [
"-y",
"rpgmaker-mz-mcp"
]
}
}
} codex mcp add redseb-rpgmaker-mz-mcp -- npx -y rpgmaker-mz-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"redseb-rpgmaker-mz-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"rpgmaker-mz-mcp"
],
"enabled": true
}
}
} openclaw mcp add redseb-rpgmaker-mz-mcp --command npx --arg -y --arg rpgmaker-mz-mcp
mcp_servers:
redseb-rpgmaker-mz-mcp:
command: "npx"
args: ["-y", "rpgmaker-mz-mcp"] {
"McpServers": {
"redseb-rpgmaker-mz-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"rpgmaker-mz-mcp"
]
}
}
} assistant mcp add redseb-rpgmaker-mz-mcp -t stdio -c npx -a -y rpgmaker-mz-mcp
{
"mcpServers": {
"redseb-rpgmaker-mz-mcp": {
"command": "npx",
"args": [
"-y",
"rpgmaker-mz-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 −3
- Stability: pass → 0.80 functional
- 17 Sept 26 0
- Stability: 0.97 → pass security
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 −3
- Stability: pass → 0.80 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Analysed npm/rpgmaker-mz-mcp@1.2.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 95 packages
| Packages resolved | 95 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
set_tile_flags ~403
Edit a tile's passability/terrain/behaviour flags in a tileset's flags[] array (the write side of get_tile_flags). Only the fields you pass change — everything else on the tile is preserved (a non-destructive merge onto the current flag word). `passage` is walkability (down/left/right/up, true = a character can walk off that way). Also settable: star ([*] overlay), ladder, bush, counter, damage (damage floor), and terrainTag (0–7). For an autotile id (A1–A4) the change is applied to all 48 shape slots of its kind by default (set applyToAutotileKind:false to touch only the exact id) so painting any border shape keeps the same passability. Writes data/Tilesets.json through the commit choke point (dry-run/diff). Returns { tilesetId, tileId, appliedTileCount, before, after }.
| Name | Type | Req | Description |
|---|---|---|---|
| applyToAutotileKind | boolean | – | When the tile is an autotile (A1–A4), apply the change to all 48 shape slots of its kind (default true). Ignored for flat tiles. |
| bush | boolean | – | – |
| counter | boolean | – | – |
| damage | boolean | – | Damage floor (standing on it hurts). |
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| ladder | boolean | – | – |
| passage | object | – | Walkability per direction (true = walkable). Only the given directions change. |
| star | boolean | – | [*] overlay: tile drawn above the character. |
| terrainTag | integer | – | Terrain tag 0–7 (0 = none). |
| tileId | integer | yes | The raw tile id whose flags to edit |
| tilesetId | integer | yes | Tileset id (from Tilesets.json / the map) |
No output schema declared.
No examples provided.
set_type_name ~110
Rename one entry in a System.json type-name array (elements/skillTypes/weaponTypes/armorTypes/equipTypes). Index 0 is the conventional empty slot. Returns the updated array.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | Which type-name array to edit |
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| index | integer | yes | Index within the array (0 = empty slot) |
| name | string | yes | The new type name |
No output schema declared.
No examples provided.
set_variable_name ~123
Set a variable name. Grows the project's variable list if the id is past the end (padded to the editor's 20-slot block), so an id from next_free_id can always be labelled. Naming a variable as soon as you claim it is what makes it visible to the next session — see list_allocated_ids.
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| name | string | yes | The name to assign |
| variableId | integer | yes | The 1-based variable ID |
No output schema declared.
No examples provided.
update_actor ~64
Update an actor's properties
| Name | Type | Req | Description |
|---|---|---|---|
| actorId | integer | yes | The ID of the actor to update |
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| updates | object | yes | Object containing actor properties to update |
No output schema declared.
No examples provided.
update_armor ~73
Update an armor's properties (shallow merge into the existing record)
| Name | Type | Req | Description |
|---|---|---|---|
| armorId | integer | yes | The ID of the armor to update |
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| updates | object | yes | Object containing armor properties to update |
No output schema declared.
No examples provided.
update_class ~128
Update a class's properties (shallow merge into the existing record). Use for name, expParams, traits, or to replace the whole learnings/params arrays; for targeted edits prefer add_class_learning / set_class_param_curve. Warns when a learned skill's stypeId has no Add Skill Type trait ({ code: 41 }).
| Name | Type | Req | Description |
|---|---|---|---|
| classId | integer | yes | The ID of the class to update |
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| updates | object | yes | Object containing class properties to update |
No output schema declared.
No examples provided.
update_common_event ~169
Update a common event's properties (shallow merge into the existing record). Use for name, trigger, switchId, or to replace the whole command list. A structurally invalid command list refuses the write (nothing is saved) — pass force: true to override.
| Name | Type | Req | Description |
|---|---|---|---|
| commonEventId | integer | yes | The ID of the common event to update |
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| force | boolean | – | Write even if validation finds structural problems (wrong parameter count, unterminated command list). Off by default: such a write is refused and nothing is written. Advisory warnings never block re… |
| updates | object | yes | Object containing common event properties to update (name, trigger, switchId, list) |
No output schema declared.
No examples provided.
update_enemy ~100
Update an enemy's properties (shallow merge into the existing record). Returns `{ enemy, warnings? }` — a `battlerName` not found in img/enemies is flagged warn-by-default.
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| enemyId | integer | yes | The ID of the enemy to update |
| updates | object | yes | Object containing enemy properties to update |
No output schema declared.
No examples provided.
update_game_title ~47
Update the game title
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| title | string | yes | The new game title |
No output schema declared.
No examples provided.
update_item ~71
Update an item's properties (shallow merge into the existing record)
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| itemId | integer | yes | The ID of the item to update |
| updates | object | yes | Object containing item properties to update |
No output schema declared.
No examples provided.
update_map ~103
Update a map's top-level properties (name, display name, bgm, encounters, etc.). Does not repaint tiles. Cannot change width/height (that would desync the tile data array) — use resize_map for that.
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| mapId | integer | yes | The ID of the map |
| updates | object | yes | Partial MapData properties to merge |
No output schema declared.
No examples provided.
update_map_event ~146
Update a map event's properties. Refuses the write (nothing is saved) if the resulting event is structurally invalid — pass force: true to override.
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| eventId | integer | yes | The ID of the event |
| force | boolean | – | Write even if validation finds structural problems (wrong parameter count, unterminated command list). Off by default: such a write is refused and nothing is written. Advisory warnings never block re… |
| mapId | integer | yes | The ID of the map |
| updates | object | yes | Object containing event properties to update |
No output schema declared.
No examples provided.
update_map_tree ~109
Edit the map tree (MapInfos.json) only — reparent, reorder, rename, or expand/collapse maps without touching their tiles or events. Takes a batch of per-map updates; every referenced map (and any non-zero parentId) must exist, and the resulting tree must stay acyclic.
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| updates | array | yes | One or more per-map tree edits to apply together |
No output schema declared.
No examples provided.
update_skill ~59
Update a skill's properties
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| skillId | integer | yes | The skill ID to update |
| updates | object | yes | Properties to update |
No output schema declared.
No examples provided.
update_starting_position ~69
Update the game starting position
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| mapId | integer | yes | Starting map ID |
| x | integer | yes | Starting x tile |
| y | integer | yes | Starting y tile |
No output schema declared.
No examples provided.
update_state ~71
Update a state's properties (shallow merge into the existing record)
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| stateId | integer | yes | The ID of the state to update |
| updates | object | yes | Object containing state properties to update |
No output schema declared.
No examples provided.
update_title_screen ~210
Update the title screen: background layers (title1Name/title2Name, basenames from list_assets("titles1"/"titles2")), the BGM that plays while it is shown, and/or whether the game title text is drawn over the art. Only the provided fields are changed. Warns (never blocks) when an image/audio name is not a known asset. Returns the updated title screen settings.
| Name | Type | Req | Description |
|---|---|---|---|
| drawTitle | boolean | – | Whether to draw the game title text over the background art (the editor's "Draw Game Title" option) |
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| title1Name | string | – | Background image basename from list_assets("titles1") (the far layer) |
| title2Name | string | – | Background image basename from list_assets("titles2") (drawn over title1Name) |
| titleBgm | object | – | BGM that plays while the title screen is shown |
No output schema declared.
No examples provided.
update_troop ~158
Update a troop's properties (shallow merge). If `members` is provided, each enemyId is validated to exist. A structurally invalid battle-event page refuses the write (nothing is saved) — pass force: true to override.
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| force | boolean | – | Write even if validation finds structural problems (wrong parameter count, unterminated command list). Off by default: such a write is refused and nothing is written. Advisory warnings never block re… |
| troopId | integer | yes | The ID of the troop to update |
| updates | object | yes | Object containing troop properties to update (name, members, pages) |
No output schema declared.
No examples provided.
update_weapon ~72
Update a weapon's properties (shallow merge into the existing record)
| Name | Type | Req | Description |
|---|---|---|---|
| dryRun | boolean | – | Preview only: return a diff of what would change without writing to disk. |
| updates | object | yes | Object containing weapon properties to update |
| weaponId | integer | yes | The ID of the weapon to update |
No output schema declared.
No examples provided.
validate_assets ~180
Audit asset-filename integrity across the whole project (read-only, warn-by-default): every image/audio name field — actor characterName/faceName/battlerName, enemy battlerName, tileset sheets, map bgm/bgs/parallax/battlebacks, event page graphics, event Play BGM/BGS/ME/SE / Show Picture / Show Text face / Change Actor Images, and system titles/battlebacks/default audio/vehicle graphics — is checked against the files present under img/ and audio/. Catches a wrong filename (e.g. a battlerName with no matching img/enemies/*.png) before it becomes a runtime "Failed to load" error. An asset kind whose directory is empty/missing is skipped (not flagged). Complements validate_references (which checks id integrity). Returns { ok, warnings[] }.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
validate_event ~65
Validate a single event's command lists against the known RPG Maker MZ command table. Read-only: reports parameter/structure warnings without changing anything.
| Name | Type | Req | Description |
|---|---|---|---|
| eventId | integer | yes | The ID of the event to validate |
| mapId | integer | yes | The ID of the map |
No output schema declared.
No examples provided.
validate_project ~40
Validate the event command lists of every map in the project. Read-only: returns aggregated, map-tagged warnings for auditing before or after a batch of edits.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
validate_references ~102
Audit cross-file reference integrity across the whole project (read-only, warn-by-default): Transfer Player targets and starting position point at existing maps; starting party, actor classes, class/enemy skills, troop members, enemy drops, and skill/item effects (states, learned skills, common events, animations) all resolve; and the map tree has no dangling or cyclic parentId. Complements validate_project (which checks command shape). Returns { ok, warnings[] }.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the io.github.Redseb/rpgmaker-mz-mcp server?
io.github.Redseb/rpgmaker-mz-mcp is listed in the public MCP registry as io.github.Redseb/rpgmaker-mz-mcp. MCP server for RPG Maker MZ: maps, tile painting, events, database editing, and validation. This page covers its npm package (rpgmaker-mz-mcp).
Is the io.github.Redseb/rpgmaker-mz-mcp server safe to use?
io.github.Redseb/rpgmaker-mz-mcp scores 80 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 21 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.Redseb/rpgmaker-mz-mcp server expose?
io.github.Redseb/rpgmaker-mz-mcp exposes 119 tools: get_project, set_project, update_actor, create_actor, search_actors, and 114 more. Their descriptions and schemas cost roughly 19,486 tokens of context every time the server is loaded.
Is the io.github.Redseb/rpgmaker-mz-mcp server still maintained?
io.github.Redseb/rpgmaker-mz-mcp is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.Redseb/rpgmaker-mz-mcp server under?
io.github.Redseb/rpgmaker-mz-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.