
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
3dassets-mcp
Advanced tools
MCP server for 3dassets.dev: search and download free CC0 GLB 3D models and game asset packs for three.js, Blender, Godot and Unity, and submit new ones on a user's behalf. Runs over stdio and bridges to the hosted server.
Free, web-optimised CC0 GLB models and game asset packs for three.js, React Three Fiber, Blender, Godot, Unity and any glTF-capable tool. This repository holds the machine-readable pieces of https://3dassets.dev in one place for directories and agent tooling that index GitHub:
SKILL.md: the agent skill, a copy of https://3dassets.dev/skill.md (kept in sync daily by a workflow)bin/3dassets-mcp.js: the 3dassets-mcp npm package, a stdio bridge to the hosted server.mcp.json: MCP client configuration for the hosted serverserver.json: the official MCP Registry entryllms-install.md: setup notes for agents that install from a READMEThe site, the API and the MCP server itself are hosted at 3dassets.dev, so the only code here is the thin stdio bridge; the catalogue is at https://3dassets.dev/assets.
Two ways in. Hosted (Streamable HTTP) needs nothing installed; the npm package runs the same server over stdio for clients that only speak stdio or want a pinned dependency. Both expose the same tools.
# stdio, via npm (bridges to the hosted server; no local state)
npx -y 3dassets-mcp
{
"mcpServers": {
"3dassets": { "command": "npx", "args": ["-y", "3dassets-mcp"] }
}
}
Set THREEDASSETS_API_KEY in the environment to submit models on the user's behalf; leave it unset for read-only use.
Streamable HTTP endpoint: https://3dassets.dev/mcp. Search and download need no auth. Submitting models on a user's behalf takes their API key as a Bearer token; https://3dassets.dev/auth.md explains how an agent obtains one without the user ever handling a password.
# Claude Code
claude mcp add --transport http 3dassets https://3dassets.dev/mcp
# Codex CLI
codex mcp add 3dassets --url https://3dassets.dev/mcp
# VS Code
code --add-mcp '{"name":"3dassets","type":"http","url":"https://3dassets.dev/mcp"}'
Cursor, Windsurf or any mcp.json:
{
"mcpServers": {
"3dassets": { "url": "https://3dassets.dev/mcp" }
}
}
Tools: search_assets, search_packs, get_pack, list_demos, get_demo, get_asset, get_asset_usage, list_categories, list_tags, list_licenses, list_ai_models, create_account, verify_account, submit_asset_from_url, get_upload_url, finalize_upload, my_assets, update_asset, submit_pack, my_packs. Full reference: https://3dassets.dev/docs/mcp.
npx skills add 3dassets-dev/3dassets
Or point any agent at https://3dassets.dev/skill.md directly. The skill uses plain HTTP, so it works without MCP.
Base https://3dassets.dev/api/v1, OpenAPI at https://3dassets.dev/api/v1/openapi.json, guide at https://3dassets.dev/docs/api. Every asset also has a Markdown view at https://3dassets.dev/assets/{slug}.md.
Every asset on the site is CC0 1.0. The files in this repository are CC0 1.0 too.
Questions: hello@3dassets.dev
FAQs
MCP server for 3dassets.dev: search and download free CC0 GLB 3D models and game asset packs for three.js, Blender, Godot and Unity, and submit new ones on a user's behalf. Runs over stdio and bridges to the hosted server.
We found that 3dassets-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.