Fifteen AI-callable tools for chess variant analysis, hex map generation, and board game utilities.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The moddable-tools MCP server exposes 89 tools, focused primarily on general-purpose capabilities. Its published description reads: "Fifteen AI-callable tools for chess variant analysis, hex map generation, and board game utilities". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates moddable-tools F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check moddable-tools's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add moddable-tools to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://tools.moddable.games/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Get a random chess puzzle. Filter by variant or difficulty. Variant puzzles have no themes and max rating 1400 — theme and hard difficulty filters only apply to standard puzzles.
List available puzzle variants, themes, and per-variant counts from the puzzle pool
[DEPRECATED — use play_list_variants] List chess variants. Removal: v1.0.0.
[DEPRECATED — use play_create_game + play_get_moves] Get legal moves for a chess position. Removal: v1.0.0.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: chess_list_variants
A tool description tries to alter the model’s use of another tool.
EPRECATED — use play_list_variants] List chess variants. Removal: v1.0.0.RecommendationDescriptions must describe only their own tool.
tool: chess_get_legal_moves
A tool description tries to alter the model’s use of another tool.
EPRECATED — use play_create_game + play_get_moves] Get legal moves for a chess pRecommendationDescriptions must describe only their own tool.
tool: chess_analyze_position
A tool description tries to alter the model’s use of another tool.
EPRECATED — use play_suggest_move] Analyse a chess position. Removal: v1.0.0.RecommendationDescriptions must describe only their own tool.
tool: chess_make_move
A tool description tries to alter the model’s use of another tool.
EPRECATED — use play_apply_move] Apply a move to a chess game. Removal: v1.0.0.RecommendationDescriptions must describe only their own tool.
tool: chess_validate_move
A tool description tries to alter the model’s use of another tool.
EPRECATED — use play_validate_move] Check if a chess move is legal. Removal: v1.0.RecommendationDescriptions must describe only their own tool.
tool: chess_get_status
A tool description tries to alter the model’s use of another tool.
EPRECATED — use play_check_status] Get chess game status. Removal: v1.0.0.RecommendationDescriptions must describe only their own tool.
tool: chess_render_svg
A tool description tries to alter the model’s use of another tool.
EPRECATED — use play_render_board] Render a chess position as SVG. Removal: v1.0.RecommendationDescriptions must describe only their own tool.
tool: chess_make_moves
A tool description tries to alter the model’s use of another tool.
EPRECATED — use play_make_moves] Apply a sequence of chess moves. Removal: v1.0RecommendationDescriptions must describe only their own tool.
tool: play_list_variants
A tool description tries to alter the model’s use of another tool.
an be passed to play_create_game. Variants with flags (e.g. +random) can be requRecommendationDescriptions must describe only their own tool.
tool: play_get_moves
A tool description tries to alter the model’s use of another tool.
ires state from play_create_game or play_apply_move.RecommendationDescriptions must describe only their own tool.
tool: play_apply_move
A tool description tries to alter the model’s use of another tool.
as returned by play_get_moves (format varies by family: chess uses {from,to},RecommendationDescriptions must describe only their own tool.
tool: play_validate_move
A tool description tries to alter the model’s use of another tool.
same format as play_get_moves returns.RecommendationDescriptions must describe only their own tool.
tool: play_make_moves
A tool description tries to alter the model’s use of another tool.
ects must match play_get_moves format.RecommendationDescriptions must describe only their own tool.
tool: rules_get_game
A tool description tries to alter the model’s use of another tool.
adata only, use rules_get_game_meta instead.RecommendationDescriptions must describe only their own tool.
tool: rules_get_page
A tool description tries to alter the model’s use of another tool.
rketplace). Use rules_get_game_meta to see available pages.RecommendationDescriptions must describe only their own tool.
tool: game_deck_deal
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: play_create_game
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "play_create_game"RecommendationScope tools to the minimum needed.
tool: play_load_fen
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "play_load_fen"RecommendationScope tools to the minimum needed.
tool: tile_gallery_search
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "tile_gallery_search"RecommendationScope tools to the minimum needed.
tool: tile_gallery_get
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "tile_gallery_get"RecommendationScope tools to the minimum needed.
tool: tile_gallery_stats
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "tile_gallery_stats"RecommendationScope tools to the minimum needed.
tool: piece_gallery_search
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "piece_gallery_search"RecommendationScope tools to the minimum needed.
tool: piece_gallery_get_set
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "piece_gallery_get_set"RecommendationScope tools to the minimum needed.
tool: piece_gallery_stats
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "piece_gallery_stats"RecommendationScope tools to the minimum needed.
tool: game_deck_create
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "game_deck_create"RecommendationScope tools to the minimum needed.
tool: talisman_draw_characters
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "talisman_draw_characters"RecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
[DEPRECATED — use play_suggest_move] Analyse a chess position. Removal: v1.0.0.
[DEPRECATED — use play_apply_move] Apply a move to a chess game. Removal: v1.0.0.
[DEPRECATED — use play_validate_move] Check if a chess move is legal. Removal: v1.0.0.
[DEPRECATED — use play_check_status] Get chess game status. Removal: v1.0.0.
[DEPRECATED — use play_render_board] Render a chess position as SVG. Removal: v1.0.0.
[DEPRECATED — use play_make_moves] Apply a sequence of chess moves. Removal: v1.0.0.
[REMOVED — engine#98] Opening book resolution is broken in Worker context. No replacement.
List all available hex map game types with configuration options
Generate a hex map for a specific game and player count
Generate a hex map and export as SVG
Get info about a specific hex coordinate (terrain, neighbours, distance)
Compute field of view from a hex position
Find shortest path between two hex coordinates
List all playable game families supported by the engine (chess, draughts, go, reversi, shogi, xiangqi)
List available variants for a game family. Each variant can be passed to play_create_game. Variants with flags (e.g. +random) can be requested as "slug+flag".
Get the full engine definition (topology, render config, pieces, setup FEN) for a game variant. Returns the resolved frontmatter used to render and play the game.
Create a new game instance for a given family. Returns initial state to pass to subsequent calls. Variant can include flags like "grand+random" or "standard+drops".
Get all legal moves for the current position. Requires state from play_create_game or play_apply_move.
Apply a move to the game and return the new state. Pass the move object exactly as returned by play_get_moves (format varies by family: chess uses {from,to}, go uses {coord} or {action:"pass"}).
Check the current game status: whose turn it is, whether the game is over, and who won.
Use AI to analyse the position and suggest the best move. Supports 5 difficulty levels across all 6 playable families.
Render the current board position as SVG for any playable family (chess, draughts, go, reversi, shogi, xiangqi).
Export the current board position as a FEN-style notation string. Works for all 6 families (chess, draughts, go, reversi, shogi, xiangqi).
Create a game state from a FEN-style position string. Works for all 6 families.
Check whether a move is legal in the current position without applying it. Pass the move object in the same format as play_get_moves returns.
Apply a sequence of moves to a game and return the final state. Stops at the first illegal move. Move objects must match play_get_moves format.
List all available game rulebooks with metadata (players, duration, complexity, mechanics). Filterable by type, complexity, and mechanics.
Get full rulebook content for a specific game (markdown). For metadata only, use rules_get_game_meta instead.
Get structured metadata for a game: players, duration, complexity, mechanics, how_to_play, variant list, page list, related games. Lightweight alternative to fetching the full rulebook.
Get a specific page/section from a game rulebook (e.g. character creation, combat rules, marketplace). Use rules_get_game_meta to see available pages.
List all variants for a game with structured metadata (players, board, playable status, topology, engine config). Much richer than parsing the rulebook.
Get board diagram SVG URL for a game variant. Returns the diagram path, topology, and rendering metadata.
Get rules for a specific game variant
Full-text search across all published rulebooks. Returns section-typed results with deep-link anchors.
Get a random game suggestion from the library
Search the board gallery (333 rendered board layouts across 33 game families)
Get details of a specific board layout by ID
Search hex tile sets by name, game, or terrain type
Get details of a specific tile set with all tile types
Get statistics about available tile sets
Get statistics about the board gallery (total boards, families, topologies)
Search the piece set gallery by name, style, or game type
Get full details and piece list for a specific set
Get statistics about the piece gallery (total sets, styles, authors, game families)
List all supported RPG systems with oracle tables and entity data availability
Generate a random character for an RPG system (D&D 5e, Pathfinder, Ironsworn, Cairn, Knave, etc)
Roll on a random oracle table (Ironsworn, Starforged, Maze Rats, etc)
List available oracle tables for a system
Ask the oracle a yes/no question with likelihood modifier
Generate a scene using oracle tables. With a recipe, rolls each table in the recipe, resolves cross-references, and composes a narrative sentence. Without, picks random tables.
Search RPG entities (spells, monsters, classes, items) across all systems
Get full details of a specific RPG entity by name
Generate a random encounter for a system and difficulty level
Browse entities by category with pagination
Generate random loot/treasure for a system and tier
List all predefined scene recipes — curated multi-table compositions that produce coherent narrative prompts
Resolve oracle cross-references. Given a result like "Action + Theme", follows references and returns expanded results
View the complete contents of an oracle table — all entries with roll ranges
Generate a tabletop RPG encounter with CR-appropriate monsters, terrain, and loot (D&D 5e or Pathfinder 1e)
List entity categories for an RPG system (spells, monsters, classes, equipment, etc)
Get random entities from an RPG system for inspiration or encounter prep
Generate random faction assignments for Twilight Imperium 4th Edition
Milty-style TI4 draft with pick pools per player
List all TI4 factions with colors, flags, and expansion info
Draw random public objectives for TI4
Draw random agenda cards for TI4 political phase
Generate random territory/resource setup for a Nukes game
Resolve a Nukes combat encounter between units
Calculate settlement dice probability for Colony/Catan-style resource numbers
Create, shuffle, and optionally draw/deal from a card deck
List all available deck types with metadata
Shuffle and deal a custom deck of arbitrary named cards
Track scores for players in any game
Draw random characters from the Talisman 4e (revised) base set for a character lottery
Draw a random encounter for a Talisman ring (outer, middle, inner, crown)
Get the current Mod Jam status (active jam, deadline, submissions)
Get time remaining in the current Mod Jam
Get voting status for the current Mod Jam
Roll dice using standard notation (e.g. 2d6+3, 4d8, d20). Supports comma-separated pools and keep-high/low (4d6kh3).
Flip one or more coins, or pick from a list of choices
Randomly divide players into teams
Randomise turn order for a list of players
Suggest time controls for a game based on player count and complexity
Generate a random game jam theme combining mechanics and themes
Calculate probability of meeting a target with a dice expression. Supports keep-high/low (4d6kh3).