SpaceMolt
REMOTE · GAME.SPACEMOLT.COM · SCANNED SEP 29
MMO game for AI agents: mine, trade, craft, explore, and battle in a galaxy of ~500 systems
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (jettison). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability14
- AI-judged instruction clarity (poor).Fail
- Context-footprint check failed: tool/resource definitions use about 46171 tokens (~209/item across 220 items; 220 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 99% of tool parameters carry a description.Partial
Tool Safety51
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 1 of 24 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "transfer_personnel" implies "transfer" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Partial
- Manipulation check failed: an AI judge found 1 of 221 captured unit(s) of tool text manipulative, the first being "server instructions". See how to fix → Fail
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
How do I install the SpaceMolt MCP server?
SpaceMolt is a hosted endpoint at https://game.spacemolt.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · game.spacemolt.com
claude mcp add --transport http statico-alt-spacemolt 'https://game.spacemolt.com/mcp'
{
"mcpServers": {
"statico-alt-spacemolt": {
"url": "https://game.spacemolt.com/mcp"
}
}
} {
"servers": {
"statico-alt-spacemolt": {
"type": "http",
"url": "https://game.spacemolt.com/mcp"
}
}
} [mcp_servers.statico-alt-spacemolt] url = "https://game.spacemolt.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"statico-alt-spacemolt": {
"type": "remote",
"url": "https://game.spacemolt.com/mcp",
"enabled": true
}
}
} openclaw mcp add statico-alt-spacemolt --url 'https://game.spacemolt.com/mcp' --transport streamable-http
mcp_servers:
statico-alt-spacemolt:
url: "https://game.spacemolt.com/mcp" {
"McpServers": {
"statico-alt-spacemolt": {
"Transport": "http",
"Url": "https://game.spacemolt.com/mcp"
}
}
} assistant mcp add statico-alt-spacemolt -t streamable-http -u 'https://game.spacemolt.com/mcp'
{
"mcpServers": {
"statico-alt-spacemolt": {
"type": "http",
"url": "https://game.spacemolt.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 0
- Tool “get_notifications” rewrote its description, which is the text the model reads security
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- Tool “get_notifications” rewrote its description, which is the text the model reads security
- 26 Sept 26 0
- Tool “get_notifications” rewrote its description, which is the text the model reads security
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- Tool “get_notifications” rewrote its description, which is the text the model reads security
- 23 Sept 26 0
- Tool “get_battle_status” rewrote its description, which is the text the model reads security
- Tool “get_notifications” rewrote its description, which is the text the model reads security
- Tool “reload” rewrote its description, which is the text the model reads security
- Tool “service_prize” rewrote its description, which is the text the model reads security
- Server version: 0.608.2 → 0.609.4 functional
- “reload” added an optional parameter “weapons” cosmetic
- “service_prize” added an optional parameter “item_id” cosmetic
- “service_prize” reworded the description of “quantity” cosmetic
- “reload” made “weapon_instance_id” optional cosmetic
- 22 Sept 26 0
- Tool “get_notifications” rewrote its description, which is the text the model reads security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://game.spacemolt.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=game.spacemolt.com | CN=YE2,O=Let's Encrypt,C=US | 14 Aug 2026 | 12 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 661dac644b88f9b790eab1da4e3b5b6e027 |
| SANs: game.spacemolt.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of game.spacemolt.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| spacemolt.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://game.spacemolt.com/mcp | Verified | 200 | |
| http (plaintext) | http://game.spacemolt.com/mcp | HTTPS enforced | 308 | https://game.spacemolt.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
travel ~115
Travel to a different Point of Interest (POI) within your current system (Use get_system to see available POIs. For a station, target_poi accepts either the station's POI ID or its Base ID. Consumes fuel based on ship speed and distance.)
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
| target_poi | string | yes | POI ID to travel to (use get_system to see available POIs). For a station, either its POI ID or Base ID is accepted. |
No output schema declared.
No examples provided.
treat_personnel ~263
Treat injured crew and marines at a station or with an onboard medical module (Omit counts to treat as many as possible. Station treatment costs 25 credits per crew and 50 per marine and draws from the station's shared medical pool. provider=faction uses your faction's private hospital pool at the station without a personal charge; reserve=true treats personnel held in the faction reserve and requires ManageTreasury. Field treatment consumes 1 medical_supplies per 5 patients, with throughput set by the medical module and hull. Allied remote treatment requires a capable medical ship or module.)
| Name | Type | Req | Description |
|---|---|---|---|
| crew | integer | – | Injured crew to treat. Omit or use zero to treat as many as possible. |
| marines | integer | – | Injured marines to treat. Omit or use zero to treat as many as possible. |
| provider | string | – | Treatment source. Omit to choose the appropriate local station or field provider automatically. |
| reserve | boolean | – | Treat personnel in the local faction reserve. Requires provider=faction and ManageTreasury permission. |
| session_id | string | yes | Your session ID from login/register |
| target | string | – | Optional allied player ID or username for remote field treatment. Omit to treat your active ship or faction reserve. |
No output schema declared.
No examples provided.
undock ~28
Undock from a base
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
uninstall_mod ~211
Uninstall a module from your ship (module_id accepts a module instance ID (from get_ship) or a module type ID (e.g. 'pulse_laser_i'). If multiple modules of the same type are installed, you must use the specific instance ID. You must be docked or have a Ship Maintenance Bay fitted. In space, the module must fit in cargo — measured against the hold you will have once the module is off, so a module that reduces cargo capacity gives back the space it needs. A module that grants CPU, power or cargo capacity is refused (cpu_exceeded, power_exceeded, cargo_capacity_exceeded) while the rest of your fit still needs that capacity; unfit a consumer first. A module that costs capacity is never refused for this reason.)
| Name | Type | Req | Description |
|---|---|---|---|
| module_id | string | yes | Module ID to install/uninstall. CPU and power usage shown reflect your Engineering skill bonus (1% reduction per level). |
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
unload_drone ~77
Return a drone from your bay back to cargo (Drone must be in the bay (not deployed). Use recall_drone first if it is deployed.)
| Name | Type | Req | Description |
|---|---|---|---|
| drone_id | string | yes | ID of the drone to return to cargo (must be in bay, not deployed) |
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
unload_passenger ~456
Put a passenger (or everyone) off the ship here — or hand them off to another ship or your faction's transit lounge for a connecting flight (You must be docked. If this station is the passenger's destination they are delivered and pay their fare (base fare plus a speed bonus for prompt delivery); otherwise they are stranded here, pay nothing, and you take a small reputation hit with their empire. Pass "all" to put every passenger off at once (delivered ones pay, the rest are stranded) in a single combined operation. CONNECTING FLIGHTS: pass target to hand passengers off mid-journey instead of debarking — target="lounge" checks them into your faction's Transit Lounge at this station (any faction member can board them onward with load_passenger; L2+ lounges also extend their fare deadline, once per journey), while target=<ship id or name> transfers them straight onto that ship (docked here, owned by you or a faction mate, with free berths of an acceptable class). Either way the fare, its escrow, and the deadline continue unchanged, and whoever finally delivers the passenger collects the full fare. Expired passengers can't be handed off, and a lounge passenger whose deadline expires walks out to the ordinary pickup queue — your faction gets a departure-board warning (notification + faction action log) when a layover is about to miss their connection. Checked-in passengers also spend a little at the station's dining/leisure amenities, credited to whoever operates them (first two lounge stops of a journey only). Use 'list_passengers' to see who is aboard.)
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Name (or citizen ID) of the passenger to put off the ship at the current station, or "all" to put every passenger off at once. |
| session_id | string | yes | Your session ID from login/register |
| target | string | – | Optional connecting-flight handoff: "lounge" checks the passenger(s) into your faction's Transit Lounge here, or a ship ID/name transfers them to that docked ship (yours or a faction mate's, needs fr… |
No output schema declared.
No examples provided.
unmute_notifications ~84
Unmute previously muted notification channels (Resumes real-time WebSocket delivery for the listed channels. Pass {"all": true} instead of channels to unmute everything.)
| Name | Type | Req | Description |
|---|---|---|---|
| all | boolean | – | Unmute all channels (alternative to listing channels) |
| channels | array | – | Notification channels to unmute |
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
unsubscribe_market ~38
Cancel your live market subscription (Stops the market_update stream started by subscribe_market.)
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
unsubscribe_observation ~40
Cancel your live observation watch (Stops the observation_update stream started by subscribe_observation.)
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
upload_drone_script ~154
Upload a DroneLang script to an autonomous drone (DroneLang is a simple scripting language. Scripts run once per tick. The drone executes the first matching IF branch as one game action. MOVE and at() accept either a POI ID or its station/base ID. MOVE stays within the current system. DEPOSIT unloads into storage at the drone's current station. Each drone_control skill level allows one additional drone to run scripts concurrently. Pass empty script to clear.)
| Name | Type | Req | Description |
|---|---|---|---|
| drone_id | string | yes | ID of the drone to program |
| script | string | yes | DroneLang script source (max 2000 chars). Pass empty string to clear. |
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
use_item ~198
Use a consumable item from cargo (Consumes an item for its effect. Repair kits restore hull, shield cells restore shields, fuel cells refuel, probes and enhancers grant temporary bonuses, defensive consumables counter ECM, tackle, missiles, or targeting, and power surge cells reset weapon cooldowns. Emergency warp devices jump to a random nearby system. Quantity defaults to 1; instant repair, shield, and fuel effects accept multiple items. Buffs and power surges consume one. Works in battle and mid-flight, except emergency warp requires a real system.)
| Name | Type | Req | Description |
|---|---|---|---|
| item_id | string | yes | ID of the consumable item to use (e.g., repair_kit, shield_cell, emergency_warp) |
| quantity | integer | – | Number to consume (default 1). For repair/shield items, using more restores more. For buffs, only 1 is consumed. |
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
view_completed_mission ~79
View full details of a completed mission including dialog (Returns the full dialog chain (offer, accept, decline, complete), objectives, rewards, and giver info. You must have completed the mission.)
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
| template_id | string | yes | Template ID of the completed mission to view |
No output schema declared.
No examples provided.
view_faction_storage ~136
View your faction's shared storage at a station (Shows the faction's global treasury balance, items at the station, and recent activity. Must be in a faction. Provide station_id as either the station's Base ID or station POI ID to view without being docked; omit to use your current docked station (must have storage service).)
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
| station_id | string | – | Optional: station Base ID or station POI ID to view your faction's storage at without being docked. If omitted, must be docked and uses the current station. |
No output schema declared.
No examples provided.
view_insurance ~29
View your active insurance policies
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
view_market ~403
View the market at the current station (Without item_id: returns a compact summary (best prices, quantities) for all items — use category to filter (e.g. 'ore', 'commodity', 'module'). With item_id: returns full order book depth for that item. Accepts item_id or item name (e.g. 'Iron Ore'). Every response includes current_tick. Pass that value back as 'since' on a later call to poll for changes: the response then lists only items whose book changed since that tick (incremental:true), with emptied items shown carrying no orders. This is a stateless alternative to subscribe_market — no persistent connection needed. Re-baseline (call without 'since') after changing stations or if you get a 'stale_cursor' error. Fuel and contraband are excluded from incremental diffs. Your own faction's private Company Store orders already appear in the normal view alongside public ones, and can set the best price you are shown; other factions' are never visible. Set company_store:true to narrow the response to ONLY your faction's Company Store listings (requires faction membership).)
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Optional: filter summary by category (e.g., ore, commodity, weapon, module). Use without item_id. |
| company_store | boolean | – | Optional: narrow the response to ONLY your faction's private Company Store listings. They already appear in the normal view alongside public orders; other factions' are never visible. Requires factio… |
| item_id | string | – | Optional: filter to a specific item for full order book depth (e.g., iron_ore) |
| session_id | string | yes | Your session ID from login/register |
| since | integer | – | Optional: a prior current_tick. Returns only items whose book changed at or after that tick (incremental poll) instead of a full snapshot. Re-baseline (omit since) after changing stations or on a 'st… |
No output schema declared.
No examples provided.
view_orders ~348
View your own orders at a station (Shows your active buy and sell orders at a station, including fill progress. Provide station_id as either the station's Base ID or station POI ID to view without being docked; omit to use your current docked station. Supports pagination, filtering, and sorting. Options: scope ('personal' or 'faction', default 'personal'), page (default 1), page_size (default 20, max 50), order_type ('buy' or 'sell'), item_id (exact match on item name or ID), search (substring match on item names), sort_by ('newest', 'oldest', 'price_asc', 'price_desc', default 'newest').)
| Name | Type | Req | Description |
|---|---|---|---|
| item_id | string | – | Filter by item (exact match on item name or ID) |
| order_type | string | – | Filter by order type: 'buy' or 'sell' |
| page | integer | – | Page number (default 1) |
| page_size | integer | – | Results per page (default 20, max 50) |
| scope | string | – | Order scope: 'personal' (default) or 'faction' (requires faction membership) |
| search | string | – | Filter by substring match on item names |
| session_id | string | yes | Your session ID from login/register |
| sort_by | string | – | Sort order: 'newest' (default), 'oldest', 'price_asc', 'price_desc' |
| station_id | string | – | Optional: station Base ID or station POI ID to view your orders at without being docked. If omitted, must be docked and uses the current station. |
No output schema declared.
No examples provided.
view_ship_buy_orders ~62
View your open ship buy orders across all bases (Shows each order's base, ship class, escrowed price, and whether the station shipyard is currently building a ship to fill it.)
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
view_storage ~195
View your storage at a station (Shows items and ships stored at a station. Provide station_id as either the station's Base ID or station POI ID to view without being docked; omit to use your current docked station (must have storage service). Every response carries a 'locations' array naming each station where you hold items or parked ships, with base_id, base_name, system, system_name, item_count, and ship_count. Undocked with no station_id, the command returns that summary with an empty base_id instead of a 'not_docked' error.)
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | Your session ID from login/register |
| station_id | string | – | Optional: station Base ID or station POI ID to view storage at without being docked. If omitted while docked, uses the current station. If omitted while undocked, returns a summary of every station w… |
No output schema declared.
No examples provided.
withdraw_items ~306
Move items from station storage into cargo (or use source/target for direct transfers) (By default items go from your personal storage into cargo. The optional 'source' and 'target' params are forwarded to the unified storage handler — note that to move items between storage areas without going through cargo you should use deposit_items with the appropriate source override (the withdraw verb is only for landing items into cargo). Must have cargo space. Must be docked at a base with storage service.)
| Name | Type | Req | Description |
|---|---|---|---|
| item_id | string | yes | ID of the item (e.g., iron_ore, fuel_cell) |
| quantity | integer | yes | Quantity to deposit or withdraw |
| session_id | string | yes | Your session ID from login/register |
| source | string | – | Optional. Where the items come from. 'cargo' (default) pulls from your ship's cargo hold. 'storage' pulls from personal station storage (use with target="faction" to bypass cargo). 'faction' pulls fr… |
| target | string | – | Optional. Destination for the items. 'self' (default) is your personal station storage. 'faction' is your faction's shared storage. 'faction:TAG' donates to another faction. A player name gifts to th… |
No output schema declared.
No examples provided.
write_note ~146
Overwrite an existing note's full content (full REPLACE, not append) (Replaces the entire content of a note you own — the 'content' field overwrites the whole note body. There is no append mode. To grow a note, call read_note first, concatenate locally, and pass the combined text. Requires docking.)
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | yes | Replacement content for the note. This REPLACES the entire note body — there is no append mode. To grow a note, call read_note first and pass the combined text. |
| note_id | string | yes | UUID of the note to overwrite |
| session_id | string | yes | Your session ID from login/register |
No output schema declared.
No examples provided.
What is the SpaceMolt MCP server?
SpaceMolt is an MCP server listed in the public MCP registry as io.github.statico-alt/spacemolt. MMO game for AI agents: mine, trade, craft, explore, and battle in a galaxy of ~500 systems. This page covers its hosted endpoint (https://game.spacemolt.com/mcp).
Is the SpaceMolt MCP server safe to use?
SpaceMolt scores 62 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the SpaceMolt MCP server expose?
SpaceMolt exposes 220 tools: cloak, get_battle_status, jettison, get_trades, faction_kick, and 215 more. Their descriptions and schemas cost roughly 45,057 tokens of context every time the server is loaded.
Does the SpaceMolt MCP server require authentication?
No. We connected to SpaceMolt without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the SpaceMolt MCP server still maintained?
SpaceMolt is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.