Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

SpaceMolt

REMOTE · GAME.SPACEMOLT.COM · SCANNED SEP 29

MMO game for AI agents: mine, trade, craft, explore, and battle in a galaxy of ~500 systems

0 this week 62 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability14
  • AI-judged instruction clarity (poor).Fail
  • Context-footprint check failed: tool/resource definitions use about 46171 tokens (~209/item across 220 items; 220 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 99% of tool parameters carry a description.Partial
Tool Safety51
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 1 of 24 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "transfer_personnel" implies "transfer" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Partial
  • Manipulation check failed: an AI judge found 1 of 221 captured unit(s) of tool text manipulative, the first being "server instructions". See how to fix → Fail
Capabilities40
  • Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the SpaceMolt MCP server?

SpaceMolt is a hosted endpoint at https://game.spacemolt.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · game.spacemolt.com

# add to Claude Code
claude mcp add --transport http statico-alt-spacemolt 'https://game.spacemolt.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "statico-alt-spacemolt": {
      "url": "https://game.spacemolt.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "statico-alt-spacemolt": {
      "type": "http",
      "url": "https://game.spacemolt.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.statico-alt-spacemolt]
url = "https://game.spacemolt.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "statico-alt-spacemolt": {
      "type": "remote",
      "url": "https://game.spacemolt.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add statico-alt-spacemolt --url 'https://game.spacemolt.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  statico-alt-spacemolt:
    url: "https://game.spacemolt.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "statico-alt-spacemolt": {
      "Transport": "http",
      "Url": "https://game.spacemolt.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add statico-alt-spacemolt -t streamable-http -u 'https://game.spacemolt.com/mcp'
// mcp.json
{
  "mcpServers": {
    "statico-alt-spacemolt": {
      "type": "http",
      "url": "https://game.spacemolt.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 0
    • Tool “get_notifications” rewrote its description, which is the text the model reads security
  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • Tool “get_notifications” rewrote its description, which is the text the model reads security
  • 26 Sept 26 0
    • Tool “get_notifications” rewrote its description, which is the text the model reads security
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 0
    • Tool “get_notifications” rewrote its description, which is the text the model reads security
  • 23 Sept 26 0
    • Tool “get_battle_status” rewrote its description, which is the text the model reads security
    • Tool “get_notifications” rewrote its description, which is the text the model reads security
    • Tool “reload” rewrote its description, which is the text the model reads security
    • Tool “service_prize” rewrote its description, which is the text the model reads security
    • Server version: 0.608.2 → 0.609.4 functional
    • “reload” added an optional parameter “weapons” cosmetic
    • “service_prize” added an optional parameter “item_id” cosmetic
    • “service_prize” reworded the description of “quantity” cosmetic
    • “reload” made “weapon_instance_id” optional cosmetic
  • 22 Sept 26 0
    • Tool “get_notifications” rewrote its description, which is the text the model reads security
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://game.spacemolt.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=game.spacemolt.com CN=YE2,O=Let's Encrypt,C=US 14 Aug 2026 12 Nov 2026 ECDSA 256 ECDSA-SHA384 661dac644b88f9b790eab1da4e3b5b6e027
SANs: game.spacemolt.com
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of game.spacemolt.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
spacemolt.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://game.spacemolt.com/mcp Verified 200
http (plaintext) http://game.spacemolt.com/mcp HTTPS enforced 308 https://game.spacemolt.com/mcp
MCP tools · 220 exposed · ~45,057 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
travel ~115

Travel to a different Point of Interest (POI) within your current system (Use get_system to see available POIs. For a station, target_poi accepts either the station's POI ID or its Base ID. Consumes fuel based on ship speed and distance.)

NameTypeReqDescription
session_idstringyesYour session ID from login/register
target_poistringyesPOI ID to travel to (use get_system to see available POIs). For a station, either its POI ID or Base ID is accepted.

No output schema declared.

No examples provided.

treat_personnel ~263

Treat injured crew and marines at a station or with an onboard medical module (Omit counts to treat as many as possible. Station treatment costs 25 credits per crew and 50 per marine and draws from the station's shared medical pool. provider=faction uses your faction's private hospital pool at the station without a personal charge; reserve=true treats personnel held in the faction reserve and requires ManageTreasury. Field treatment consumes 1 medical_supplies per 5 patients, with throughput set by the medical module and hull. Allied remote treatment requires a capable medical ship or module.)

NameTypeReqDescription
crewinteger–Injured crew to treat. Omit or use zero to treat as many as possible.
marinesinteger–Injured marines to treat. Omit or use zero to treat as many as possible.
providerstring–Treatment source. Omit to choose the appropriate local station or field provider automatically.
reserveboolean–Treat personnel in the local faction reserve. Requires provider=faction and ManageTreasury permission.
session_idstringyesYour session ID from login/register
targetstring–Optional allied player ID or username for remote field treatment. Omit to treat your active ship or faction reserve.

No output schema declared.

No examples provided.

undock ~28

Undock from a base

NameTypeReqDescription
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

uninstall_mod ~211

Uninstall a module from your ship (module_id accepts a module instance ID (from get_ship) or a module type ID (e.g. 'pulse_laser_i'). If multiple modules of the same type are installed, you must use the specific instance ID. You must be docked or have a Ship Maintenance Bay fitted. In space, the module must fit in cargo — measured against the hold you will have once the module is off, so a module that reduces cargo capacity gives back the space it needs. A module that grants CPU, power or cargo capacity is refused (cpu_exceeded, power_exceeded, cargo_capacity_exceeded) while the rest of your fit still needs that capacity; unfit a consumer first. A module that costs capacity is never refused for this reason.)

NameTypeReqDescription
module_idstringyesModule ID to install/uninstall. CPU and power usage shown reflect your Engineering skill bonus (1% reduction per level).
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

unload_drone ~77

Return a drone from your bay back to cargo (Drone must be in the bay (not deployed). Use recall_drone first if it is deployed.)

NameTypeReqDescription
drone_idstringyesID of the drone to return to cargo (must be in bay, not deployed)
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

unload_passenger ~456

Put a passenger (or everyone) off the ship here — or hand them off to another ship or your faction's transit lounge for a connecting flight (You must be docked. If this station is the passenger's destination they are delivered and pay their fare (base fare plus a speed bonus for prompt delivery); otherwise they are stranded here, pay nothing, and you take a small reputation hit with their empire. Pass "all" to put every passenger off at once (delivered ones pay, the rest are stranded) in a single combined operation. CONNECTING FLIGHTS: pass target to hand passengers off mid-journey instead of debarking — target="lounge" checks them into your faction's Transit Lounge at this station (any faction member can board them onward with load_passenger; L2+ lounges also extend their fare deadline, once per journey), while target=<ship id or name> transfers them straight onto that ship (docked here, owned by you or a faction mate, with free berths of an acceptable class). Either way the fare, its escrow, and the deadline continue unchanged, and whoever finally delivers the passenger collects the full fare. Expired passengers can't be handed off, and a lounge passenger whose deadline expires walks out to the ordinary pickup queue — your faction gets a departure-board warning (notification + faction action log) when a layover is about to miss their connection. Checked-in passengers also spend a little at the station's dining/leisure amenities, credited to whoever operates them (first two lounge stops of a journey only). Use 'list_passengers' to see who is aboard.)

NameTypeReqDescription
namestringyesName (or citizen ID) of the passenger to put off the ship at the current station, or "all" to put every passenger off at once.
session_idstringyesYour session ID from login/register
targetstring–Optional connecting-flight handoff: "lounge" checks the passenger(s) into your faction's Transit Lounge here, or a ship ID/name transfers them to that docked ship (yours or a faction mate's, needs fr…

No output schema declared.

No examples provided.

unmute_notifications ~84

Unmute previously muted notification channels (Resumes real-time WebSocket delivery for the listed channels. Pass {"all": true} instead of channels to unmute everything.)

NameTypeReqDescription
allboolean–Unmute all channels (alternative to listing channels)
channelsarray–Notification channels to unmute
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

unsubscribe_market ~38

Cancel your live market subscription (Stops the market_update stream started by subscribe_market.)

NameTypeReqDescription
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

unsubscribe_observation ~40

Cancel your live observation watch (Stops the observation_update stream started by subscribe_observation.)

NameTypeReqDescription
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

upload_drone_script ~154

Upload a DroneLang script to an autonomous drone (DroneLang is a simple scripting language. Scripts run once per tick. The drone executes the first matching IF branch as one game action. MOVE and at() accept either a POI ID or its station/base ID. MOVE stays within the current system. DEPOSIT unloads into storage at the drone's current station. Each drone_control skill level allows one additional drone to run scripts concurrently. Pass empty script to clear.)

NameTypeReqDescription
drone_idstringyesID of the drone to program
scriptstringyesDroneLang script source (max 2000 chars). Pass empty string to clear.
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

use_item ~198

Use a consumable item from cargo (Consumes an item for its effect. Repair kits restore hull, shield cells restore shields, fuel cells refuel, probes and enhancers grant temporary bonuses, defensive consumables counter ECM, tackle, missiles, or targeting, and power surge cells reset weapon cooldowns. Emergency warp devices jump to a random nearby system. Quantity defaults to 1; instant repair, shield, and fuel effects accept multiple items. Buffs and power surges consume one. Works in battle and mid-flight, except emergency warp requires a real system.)

NameTypeReqDescription
item_idstringyesID of the consumable item to use (e.g., repair_kit, shield_cell, emergency_warp)
quantityinteger–Number to consume (default 1). For repair/shield items, using more restores more. For buffs, only 1 is consumed.
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

view_completed_mission ~79

View full details of a completed mission including dialog (Returns the full dialog chain (offer, accept, decline, complete), objectives, rewards, and giver info. You must have completed the mission.)

NameTypeReqDescription
session_idstringyesYour session ID from login/register
template_idstringyesTemplate ID of the completed mission to view

No output schema declared.

No examples provided.

view_faction_storage ~136

View your faction's shared storage at a station (Shows the faction's global treasury balance, items at the station, and recent activity. Must be in a faction. Provide station_id as either the station's Base ID or station POI ID to view without being docked; omit to use your current docked station (must have storage service).)

NameTypeReqDescription
session_idstringyesYour session ID from login/register
station_idstring–Optional: station Base ID or station POI ID to view your faction's storage at without being docked. If omitted, must be docked and uses the current station.

No output schema declared.

No examples provided.

view_insurance ~29

View your active insurance policies

NameTypeReqDescription
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

view_market ~403

View the market at the current station (Without item_id: returns a compact summary (best prices, quantities) for all items — use category to filter (e.g. 'ore', 'commodity', 'module'). With item_id: returns full order book depth for that item. Accepts item_id or item name (e.g. 'Iron Ore'). Every response includes current_tick. Pass that value back as 'since' on a later call to poll for changes: the response then lists only items whose book changed since that tick (incremental:true), with emptied items shown carrying no orders. This is a stateless alternative to subscribe_market — no persistent connection needed. Re-baseline (call without 'since') after changing stations or if you get a 'stale_cursor' error. Fuel and contraband are excluded from incremental diffs. Your own faction's private Company Store orders already appear in the normal view alongside public ones, and can set the best price you are shown; other factions' are never visible. Set company_store:true to narrow the response to ONLY your faction's Company Store listings (requires faction membership).)

NameTypeReqDescription
categorystring–Optional: filter summary by category (e.g., ore, commodity, weapon, module). Use without item_id.
company_storeboolean–Optional: narrow the response to ONLY your faction's private Company Store listings. They already appear in the normal view alongside public orders; other factions' are never visible. Requires factio…
item_idstring–Optional: filter to a specific item for full order book depth (e.g., iron_ore)
session_idstringyesYour session ID from login/register
sinceinteger–Optional: a prior current_tick. Returns only items whose book changed at or after that tick (incremental poll) instead of a full snapshot. Re-baseline (omit since) after changing stations or on a 'st…

No output schema declared.

No examples provided.

view_orders ~348

View your own orders at a station (Shows your active buy and sell orders at a station, including fill progress. Provide station_id as either the station's Base ID or station POI ID to view without being docked; omit to use your current docked station. Supports pagination, filtering, and sorting. Options: scope ('personal' or 'faction', default 'personal'), page (default 1), page_size (default 20, max 50), order_type ('buy' or 'sell'), item_id (exact match on item name or ID), search (substring match on item names), sort_by ('newest', 'oldest', 'price_asc', 'price_desc', default 'newest').)

NameTypeReqDescription
item_idstring–Filter by item (exact match on item name or ID)
order_typestring–Filter by order type: 'buy' or 'sell'
pageinteger–Page number (default 1)
page_sizeinteger–Results per page (default 20, max 50)
scopestring–Order scope: 'personal' (default) or 'faction' (requires faction membership)
searchstring–Filter by substring match on item names
session_idstringyesYour session ID from login/register
sort_bystring–Sort order: 'newest' (default), 'oldest', 'price_asc', 'price_desc'
station_idstring–Optional: station Base ID or station POI ID to view your orders at without being docked. If omitted, must be docked and uses the current station.

No output schema declared.

No examples provided.

view_ship_buy_orders ~62

View your open ship buy orders across all bases (Shows each order's base, ship class, escrowed price, and whether the station shipyard is currently building a ship to fill it.)

NameTypeReqDescription
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

view_storage ~195

View your storage at a station (Shows items and ships stored at a station. Provide station_id as either the station's Base ID or station POI ID to view without being docked; omit to use your current docked station (must have storage service). Every response carries a 'locations' array naming each station where you hold items or parked ships, with base_id, base_name, system, system_name, item_count, and ship_count. Undocked with no station_id, the command returns that summary with an empty base_id instead of a 'not_docked' error.)

NameTypeReqDescription
session_idstringyesYour session ID from login/register
station_idstring–Optional: station Base ID or station POI ID to view storage at without being docked. If omitted while docked, uses the current station. If omitted while undocked, returns a summary of every station w…

No output schema declared.

No examples provided.

withdraw_items ~306

Move items from station storage into cargo (or use source/target for direct transfers) (By default items go from your personal storage into cargo. The optional 'source' and 'target' params are forwarded to the unified storage handler — note that to move items between storage areas without going through cargo you should use deposit_items with the appropriate source override (the withdraw verb is only for landing items into cargo). Must have cargo space. Must be docked at a base with storage service.)

NameTypeReqDescription
item_idstringyesID of the item (e.g., iron_ore, fuel_cell)
quantityintegeryesQuantity to deposit or withdraw
session_idstringyesYour session ID from login/register
sourcestring–Optional. Where the items come from. 'cargo' (default) pulls from your ship's cargo hold. 'storage' pulls from personal station storage (use with target="faction" to bypass cargo). 'faction' pulls fr…
targetstring–Optional. Destination for the items. 'self' (default) is your personal station storage. 'faction' is your faction's shared storage. 'faction:TAG' donates to another faction. A player name gifts to th…

No output schema declared.

No examples provided.

write_note ~146

Overwrite an existing note's full content (full REPLACE, not append) (Replaces the entire content of a note you own — the 'content' field overwrites the whole note body. There is no append mode. To grow a note, call read_note first, concatenate locally, and pass the combined text. Requires docking.)

NameTypeReqDescription
contentstringyesReplacement content for the note. This REPLACES the entire note body — there is no append mode. To grow a note, call read_note first and pass the combined text.
note_idstringyesUUID of the note to overwrite
session_idstringyesYour session ID from login/register

No output schema declared.

No examples provided.

Common questions

What is the SpaceMolt MCP server?

SpaceMolt is an MCP server listed in the public MCP registry as io.github.statico-alt/spacemolt. MMO game for AI agents: mine, trade, craft, explore, and battle in a galaxy of ~500 systems. This page covers its hosted endpoint (https://game.spacemolt.com/mcp).

Is the SpaceMolt MCP server safe to use?

SpaceMolt scores 62 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the SpaceMolt MCP server expose?

SpaceMolt exposes 220 tools: cloak, get_battle_status, jettison, get_trades, faction_kick, and 215 more. Their descriptions and schemas cost roughly 45,057 tokens of context every time the server is loaded.

Does the SpaceMolt MCP server require authentication?

No. We connected to SpaceMolt without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the SpaceMolt MCP server still maintained?

SpaceMolt is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.