Server data from the Official MCP Registry
Attach weapons and props to rigged 3D characters: hand-bone detection, fist close, engine binds.
About
Attach weapons and props to rigged 3D characters: hand-bone detection, fist close, engine binds.
Security Report
This is a lean MCP client for the GripForge 3D rigging API with appropriate authentication and minimal attack surface. The code properly validates inputs, handles file I/O safely with path resolution, and stores the API key via environment variables. The main concerns are modest: no input validation on out_dir path traversal despite using resolve(), broad error messages that could leak API structure details, and lack of request timeout handling on the fetch call. Permissions align well with the server's purpose (file read/write for 3D models, HTTP to GripForge API). Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
3 files analyzed · 7 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: GRIPFORGE_API_KEY
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-gripforgeai-mcp": {
"env": {
"GRIPFORGE_API_KEY": "your-gripforge-api-key-here"
},
"args": [
"-y",
"@gripforgeai/mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
@gripforgeai/mcp
Attach weapons & props to rigged characters — from Claude Code, Cursor or any MCP client. Thin client for the GripForge API.
Hosted endpoint (zero install)
No Node required — point any remote-capable MCP client at:
https://gripforge.ai/mcp
Auth: x-api-key: gf_... header (or Authorization: Bearer). Assets are passed
as URLs (character_url, prop_url) — Tripo/Meshy download links work
directly.
// Cursor (.cursor/mcp.json)
{
"mcpServers": {
"gripforge": {
"url": "https://gripforge.ai/mcp",
"headers": { "x-api-key": "gf_..." }
}
}
}
Example
"Attach this sword to my knight, right hand, then export the armed GLB."
The agent calls gripforge_attach with the two asset URLs (or local paths with
the npm package); GripForge finds the hand bone, scales the prop to the
character's hand, closes the fist around the grip and returns the bind JSON,
ready-to-paste Three.js / Unity / Godot snippets, and optionally the armed GLB.
Install (Claude Code)
claude mcp add gripforge -e GRIPFORGE_API_KEY=gf_... -- npx -y @gripforgeai/mcp
Or in .mcp.json:
{
"mcpServers": {
"gripforge": {
"command": "npx",
"args": ["-y", "@gripforgeai/mcp"],
"env": { "GRIPFORGE_API_KEY": "gf_..." }
}
}
}
Get a free API key at https://gripforge.ai/login — the free plan includes 3 API/MCP attaches per month to try it out (plus 15 in the web Studio). Paid plans from €29/mo for production use.
Install (Grok)
grok mcp add gripforge --env GRIPFORGE_API_KEY=gf_... -- npx -y @gripforgeai/mcp
Or in ~/.grok/config.toml:
[mcp_servers.gripforge]
command = "npx"
args = ["-y", "@gripforgeai/mcp"]
enabled = true
startup_timeout_sec = 45
[mcp_servers.gripforge.env]
GRIPFORGE_API_KEY = "gf_..."
Also works with Cursor, Windsurf and any MCP-compatible client — same
command / args / env triple.
Tools
gripforge_style_kit— resolve "Devil May Cry like" / "genshin" to locker ids already tagged with that look. Call this before generating. Reuse the ids.gripforge_generate_character— new T-pose + auto-rig into Library (10 credits).kind=enemyor the word "enemy" in the prompt. Skip this if style_kit already returned a character.gripforge_concept_correct— concept image → strict T-pose sheet (1 credit).gripforge_attach— character + prop (paths or Library ids) in, bone-local bind + Three.js / Unity / Godot snippets out. Styles: melee, gun, shield, staff (scythe/polearm). Withexport_glb: true(+out_dir) it also writesattached.glb: the character with the fist closed and the prop attached, textures preserved — use this for mitten-hand rigs, whose closed fist cannot travel in a JSON bind.gripforge_formats— supported formats & options.gripforge_library_list/get/push/pull— the Library locker.pullwrites bind.json + mesh into the open repo (out_dir, default./gripforge-library). Saving a bind after attach is not a second credit.gripforge_texture_prep— local path ortexture_id→ seamless blend + faithful lanczos upscale (1×/2×/4×, max 1024 or 2048). Writes the PNG intoout_dirand returns the Library albedo URL. Not a generator. No credit.gripforge_vfx/gripforge_vfx_preview— strike VFX (admin keys).gripforge_shaders— list the authorized shader catalog ({ id, name, engines }). Searchq=slash_reveal.gripforge_shader_pull—id+engine(godot|unity|three) +out_dir→ write sources into the repo and return an assignment snippet. v1 pull is free.
Env
GRIPFORGE_API_KEY(required) — 1 credit = 1 successful attachGRIPFORGE_API_URL(optional) — defaults to https://gripforge.ai
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
