
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
rpgmaker-mz-mcp
Advanced tools
High-quality MCP server for RPG Maker MZ integration - manage game data, maps, events, and plugins
119 tools that let an AI assistant read and write an RPG Maker MZ project directly — actors, classes, skills, items, equipment, states, enemies, troops, common events, maps, tiles, tilesets, events, and system settings — instead of hand-editing everything in the editor.
"Add a town under the world map, paint it with grass, and drop in a shopkeeper who sells potions" → done, in-project, no editor clicks.
Claude Code (recommended) — installs the server and the authoring skills as one plugin:
claude plugin marketplace add Redseb/rpgmaker-mz-mcp
claude plugin install rpgmaker-mz@rpgmaker-mz-mcp
You'll be prompted for your RPG Maker MZ project directory (optional — you can also just ask Claude to set_project later).
Any other MCP client — the server is on npm; no clone or build needed:
{
"mcpServers": {
"rpgmaker-mz": {
"command": "npx",
"args": ["-y", "rpgmaker-mz-mcp@latest"],
"env": { "RPGMAKER_PROJECT_PATH": "/path/to/your/rpgmaker/project" }
}
}
}
Claude Desktop — either the JSON config above, or download the one-click rpgmaker-mz-mcp.mcpb bundle from Releases and open it with Claude Desktop.
New here? Read SETUP.md for the full walkthrough and EXAMPLES.md for end-to-end recipes.
name is required to create; everything else falls back to the editor's true "New X" template.MapInfos.json exactly as the editor expects.paint_tiles/fill_area set tiles on any of the six map layers and recompute autotile shapes (and their neighbours') from same-kind adjacency, so a filled region borders itself correctly. place_object stamps multi-tile B/C objects (houses, trees) and reports their passability footprint.find_tile "grass" → a paintable tile id. Built-in catalogs for every default tileset (Overworld, Outside, Inside, Dungeon, SF), sourced from RPG Maker's own English name sidecars. A bundled vision-bootstrap skill catalogs custom tilesets.get_tile_flags/check_passability), and edit passability/terrain-tag/behaviour flags (set_tile_flags).EventCommand sequences the editor writes (including tricky recursive branch blocks and continuation rows), landed on a page via insert_event_commands. Covers dialogue & flow, game-state changes, presentation/transitions, and scene processing.create_npc places a complete talking NPC in one call; set_event_page merges a page's graphic + behavior in place.list_assets enumerates valid character/face/tileset/audio names so events never reference a missing file.validate_references), and a dry-run/diff preview on every write.Pick one:
claude plugin marketplace add Redseb/rpgmaker-mz-mcp, then claude plugin install rpgmaker-mz@rpgmaker-mz-mcp. This bundles the MCP server (run via npx from the npm package) together with the two authoring skills (rpgmaker-authoring, tileset-catalog) — the skills carry the judgment the tools don't enforce, so this is the full experience.npx -y rpgmaker-mz-mcp@latest (see Quick start). Tools only, no skills.rpgmaker-mz-mcp.mcpb from Releases, open it with Claude Desktop, and pick your project folder in the install dialog.npm install
npm run build
Set the RPG Maker MZ project path as an environment variable:
# macOS/Linux
export RPGMAKER_PROJECT_PATH=/path/to/your/rpgmaker/project
# Windows
set RPGMAKER_PROJECT_PATH=C:\path\to\your\rpgmaker\project
The path must point to a directory containing game.rmmzproject and a data/ directory with System.json.
The environment variable is only the startup default: the set_project tool can retarget a running server at a different project (and get_project reports the current one), so switching games doesn't require editing config or restarting.
npm start # or: node dist/index.js
The easiest path is the .mcpb bundle from Releases — open it with Claude Desktop and pick your project folder. To configure by hand instead, add to your Claude Desktop configuration file (%APPDATA%\Claude\claude_desktop_config.json on Windows, ~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"rpgmaker-mz": {
"command": "npx",
"args": ["-y", "rpgmaker-mz-mcp@latest"],
"env": {
"RPGMAKER_PROJECT_PATH": "/path/to/your/rpgmaker/project"
}
}
}
}
(For a from-source checkout, use "command": "node" with "args": ["/path/to/rpgmaker-mz-mcp/dist/index.js"] instead.)
All 119 tools, grouped by area. Tools that write to the project accept an optional dryRun argument (see Dry-run preview); those that can refuse a structurally invalid write also accept force (see Event validation).
get_project — the project the server is operating on: path, validity, game titleset_project — retarget the server at another project directory for the rest of the session (no restart; overrides RPGMAKER_PROJECT_PATH)create_actor, update_actor, search_actorscreate_class, update_classadd_class_learning — attach a skill learned at a level (validates the skill, keeps learnings level-sorted)set_class_param_curve — replace one of the 8 parameter growth rowscreate_skill (full control), update_skill, search_skillscreate_damage_skill, create_healing_skill, create_buff_skill, create_state_skill — natural-language-friendly helpers for common skill typescreate_item, update_item, search_itemscreate_weapon, update_weaponcreate_armor, update_armorcreate_state, update_statecreate_enemy, update_enemy, search_enemiescreate_troop, update_troop, search_troops — create_troop validates that every member references an existing enemycreate_common_event, update_common_eventcall_common_event — builds the code-117 call command and validates the target existsget_map (pass includeData: false to omit the tile array on a big map), get_map_infos, get_map_dimensions, update_mapget_map_region — read a window of tile ids (x, y, width, height, layer) instead of the whole mapcreate_map — allocates the next id, writes a blank map, and registers it in the treedelete_map — removes a map and reparents its children onto its parentupdate_map_tree — batch reparent/reorder/rename/expand with an up-front existence check and cycle guardget_map_events, get_map_event, search_map_eventscreate_map_event, update_map_event, delete_map_eventadd_event_command — append a single command to an event pageset_map_tile — set a single raw tile id at (x, y) on a z-layer (no autotiling)create_npc — one-shot "talking NPC": graphic + trigger + a talk list from text or explicit commandscreate_chest — one-shot treasure chest: the two-page self-switch idiom (give item/weapon/armor/gold, then never again)create_transfer — one-shot map transfer, in either working idiom: face a solid landmark (action_button) or step on a doormat (player_touch)set_event_page — merge a page's graphic + behavior (sprite, trigger, priority, movement, flags) in placeRead-only builders that return editor-faithful EventCommand sequences; land them on a command list with insert_event_commands.
build_show_text (101/401), build_show_choices (102/402–404), build_conditional_branch (111/411/412), build_flow_command (wait/exit/label/jump)build_control_switch (121/123), build_control_variable (122), build_change_gold (125), build_change_items (126–128), build_change_party_member (129)build_transfer_player (201), build_play_audio (BGM/BGS/ME/SE), build_screen_effect (fade/tint/flash/shake), build_picture (show/erase), build_character_effect (animation/balloon)build_battle_processing (301), build_shop_processing (302/605), build_name_input (303), build_change_actor (HP/MP/state/recover/EXP/level, 311–316)insert_event_commands — splice a built sequence into a map event page (the default target), a common event body, or a troop battle-event page, then validatecreate_move_route — build a MoveRoute from a named pattern (patrol/approach/flee/wander/custom)set_movement_route — insert a forced Set Movement Route (code 205 + 505 continuation rows)scan_plugins — discover the plugin commands this project actually has, by parsing js/plugins/*.js annotations (+ enabled state from js/plugins.js)list_plugin_commands — view the known plugin commands (the project scan merged over a built-in allowlist)create_plugin_command — build a code-357 plugin command with normalized argsdescribe_tile — decode a raw tile id (sheet, autotile kind/shape, geometry)get_tile_catalog, find_tile — resolve human names ↔ paintable tile ids (find_tile can widen the search to a custom sheet's catalog descriptions with searchDescriptions)paint_tiles, fill_area — paint with automatic autotilingplace_object — stamp a multi-tile B/C object and report its passability footprintget_tile_flags — decode a tile's passability/star/ladder/bush/counter/damage/terrain-tagcheck_passability — the map-aware, layered answer for a cellset_tile_flags — edit a tile's flags (non-destructive merge; auto-applies to all 48 shape slots of an autotile kind)list_assets — enumerate available asset basenames (characters, faces, tilesets, pictures, audio, …)get_system, get_game_title, update_game_titleget_title_screen, update_title_screen — background layers, BGM, and the "draw game title" toggleget_variables, set_variable_name, get_switches, set_switch_nameget_starting_position, update_starting_positionget_party, set_party — the starting party (set_party validates every actor id)get_terms, set_term — menu vocabularyget_types, set_type_name — element/skill/weapon/armor/equip type-name listsset_currency_unitbatch_create — create many records of one type (actors, items, weapons, armors, skills, enemies, states, classes) in a single call and a single file write; ids allocate sequentially, so a record can reference a sibling made earlier in the same batchlist_names — cheap { id, name } index for a table (actors, items, skills, maps, enemies, …)get_database — full records from one table (actors, classes, items, weapons, armors, skills, enemies, troops, states, common_events), or a single record by idvalidate_event, validate_project — event-command-shape validation (read-only)validate_references — cross-file id-integrity audit (party→actor, transfer→map, effect→state/skill/common-event, drops→item, map-tree cycles, …)list_allocated_ids — which switch / variable / common-event IDs are already spoken for, derived from the project's own JSON; with id, every place that one is referencednext_free_id — reserve the next unallocated ID(s) instead of picking one by handEvery tool declares its arguments as a Zod schema. The server (built on the MCP SDK's high-level McpServer) validates incoming arguments against that schema before a handler runs, so malformed calls are rejected with a clear Input validation error naming the offending field instead of writing garbage to disk.
Event command lists are checked against a table of known RPG Maker MZ command codes (101 Show Text, 201 Transfer Player, 122 Control Variables, …), and against the block structure those commands form. Findings come in two tiers, and the tier decides what happens to the write:
0 end marker, a non-array parameters, a broken block (a Show Choices/Conditional Branch/Loop that is never closed, a branch or closer row orphaned or written at the wrong indent, a choice with no When branch), or an action-button event stranded on an impassable tile. These are almost always bugs, so the event-writing tools validate the would-be result before committing and refuse the write: the tool errors and nothing reaches disk. Pass force: true to write anyway (the argument is advertised on exactly the tools that can refuse).When Cancel branch disagree (dead code, not corruption). These are legitimately possible, so they never block; they ride along as warnings on the normal response.Because the check runs before the commit, a dryRun of a write that would be refused fails too, rather than previewing a write that could never happen.
validate_event / validate_project remain read-only audits: they report both tiers (each finding carries a severity) without changing anything.
The over-long-text-line warning is measured in characters by default — 55 per line, 38 when a face graphic is shown — which suits the stock RTP font and needs no setup. If your project ships a different font, that estimate goes wrong in one of two directions: a narrower font makes it warn on lines that fit comfortably, and a wider or larger one makes it stay quiet on lines that really are cut off (38 characters of a 24px glyph is 912px in a 616px window). No single character limit fixes both, because glyph widths in a proportional font span a wide range — a full stop can be a third the width of a capital.
Drop a .rpgmaker-mcp.json in the project root to replace the estimate with a real measurement:
{
"text": {
"lineBudget": { "noFace": 784, "withFace": 616 },
"nameBudgetChars": 8,
"charWidths": { "_default": 13, "a": 11.38, ".": 4.88, " ": 8.12 }
}
}
lineBudget — the message window's usable width, without and with a face graphic. In pixels if you give charWidths, otherwise in characters (a bare lineBudget is just a character-limit override).charWidths — per-character advance; _default covers anything unlisted. Get these from the engine itself: Window_Base.textWidth(c.repeat(40)) / 40 in a running game is exact.nameBudgetChars — how wide to assume \N[3] / \P[1] renders. A name is typed by the player at runtime, so budget the Name Input maxLength (usually 8) rather than the default name, or a long name overflows a line that fitted while you were testing. Defaults to 0, which ignores name escapes as before.Everything fails soft: no file, bad JSON, or a malformed text section leaves the built-in estimate in place, so a broken config is never worse than no config. The file is re-read when its mtime changes, and warnings then report real widths (Show Text line is 650px but the message window fits 616px with a face shown).
validate_references performs a cross-file id-integrity audit — orthogonal to the command-shape check above. It walks the whole database and flags references that point at something that doesn't exist: a starting party member with no matching actor, a Transfer Player targeting a missing map, a skill effect that adds a non-existent state, an enemy dropping an unknown item, a cyclic map-tree parent, and more. Every check is warn-by-default and guarded against false positives on partially-loaded projects.
Switches, variables and common-event IDs are one global namespace, and nothing in RPG Maker stops a later edit from claiming an ID an earlier one already used. The failure is silent — no crash, no validator hit, just a door that is inexplicably already open hours into a playtest.
list_allocated_ids answers "what's taken?" from the project files themselves — never a hand-maintained list, which would drift the moment someone edited in the RPG Maker editor. An ID counts as allocated if it is declared (a System.json label, a CommonEvents row) or referenced anywhere: event page conditions and command lists, common events, troop pages, and Common Event skill/item effects. Both halves matter — a named-but-unused switch is a claim someone staked, and a used-but-unnamed one is a claim nobody wrote down. Pass id to ask the narrower question: where is switch 23 actually used, before I touch it?
next_free_id hands back the next unallocated ID(s), strictly above everything already taken. Holes below the highest ID are left alone by default (a hole is often an ID claimed in notes but not yet written); reuseGaps: true fills them when you're compacting deliberately. It's read-only — it suggests IDs, it doesn't write them, so name what you take with set_switch_name / set_variable_name to make the claim visible to whoever edits next. Those two grow the System.json name list when the ID is past the end, so an ID from next_free_id can always be labelled without opening the editor.
Like the command validator, the usage scan is curated, not exhaustive: it covers the commands that carry switch/variable IDs (Control Switches/Variables, Conditional Branch, the "designation by variable" forms of Transfer Player, Change Gold/Items, Change HP/MP/EXP/Level, …), and every report states the command codes it scanned. An ID used only from a Script (355) or a plugin command (357) will read as free.
Every tool that writes to the project accepts an optional dryRun argument. When dryRun: true, the tool computes what it would write and returns a diff instead of touching any files:
{
"dryRun": true,
"wouldChange": [
{
"file": "System.json",
"changed": true,
"diff": {
"changes": [{ "path": "gameTitle", "from": "Old Title", "to": "New Title" }],
"truncated": false
}
}
],
"wouldReturn": { "...": "what the tool would have returned, warnings included" }
}
wouldReturn carries the response the tool would have produced, so a dry-run also previews the validation warnings a write would have reported — not just the diff.
All writes go through a single choke point that skips no-op writes and keeps the on-disk JSON in the editor's compact single-line format. File deletions (e.g. delete_map) share the same dry-run machinery.
A write tool that echoes the whole record back costs the one caller that always pays for it — an AI assistant, whose context is the scarce resource. So the tools that would otherwise replay a command list or a map's events return a summary by default:
| tool | echoes |
|---|---|
update_map, resize_map | the map without its tile data or its events, plus dataTileCount / eventCount |
update_map_event, set_event_page, add_event_command | event identity + per-page trigger / priorityType / moveType / graphic / listLength |
insert_event_commands | listLength + listCodes — the resulting command codes, without the parameters |
create_common_event, update_common_event | identity, trigger wiring, listLength + listCodes |
create_troop, update_troop | identity, members, per-page listLength |
The rule: keep what you would assert on, drop what you would only re-read. Command codes stay, because they are how you verify a splice landed where you asked (is the 302 still after the two 101s); command parameters go, because they are what you just wrote.
Pass verbose: true on any of those calls for the old full record, or read it back with get_map / get_map_event / get_database. warnings always survive summarization, and a dry-run's wouldReturn is summarized the same way so a preview and the real call report the same shape.
Measured on six calls from one real authoring session: 115,080 → 3,672 characters (-97%). A single update_map that set a map's BGM was echoing 46,846 characters of dialogue back at the caller.
The default tilesets are cataloged out of the box. For a custom (non-RTP) tileset, a bundled Claude skill under .claude/skills/tileset-catalog/ slices each sheet into labelled samples, has Claude vision-name them, and writes a versioned, project-scoped catalog to data/tilecatalog/ — after which find_tile/get_tile_catalog resolve names for that sheet too. Those drafts also record what each tile looks like, so find_tile with searchDescriptions: true can match that text when a machine-drafted name is too terse to search by. The skill ships a dependency-free PNG codec and engine-exact tile geometry, so it runs anywhere Node does.
Once configured, drive your project in natural language:
a.mat * 4 - b.mdf * 2 to one enemy."npm run build # Compile TypeScript to dist/
npm run typecheck # Type-check without emitting (tsc --noEmit)
npm run dev # Compile in watch mode
npm run lint # ESLint
npm run lint:fix # ESLint with autofix
npm run format # Format with Prettier
npm run format:check # Check formatting (used in CI)
npm test # Vitest
npm run sync:tools # Re-stamp the tool count into the README + SVGs (see below)
npm run sync:version # Re-stamp package.json's version into the packaging manifests
npm run bundle:mcpb # Build the one-click Claude Desktop bundle (rpgmaker-mz-mcp.mcpb)
During development you can skip the build entirely by running the server from source with tsx: point your MCP client's command at node_modules/.bin/tsx with src/index.ts as the argument. Since tsx doesn't type-check, run npm run typecheck alongside lint and tests before committing.
CI runs lint, format check, tool-count sync check, tests, and build on every push and pull request (see .github/workflows/ci.yml).
The advertised tool count lives in a few human-facing spots — the README prose and badge, and the two SVGs in assets/. npm run sync:tools counts the real tools from src/tools/ and re-stamps all of them, so bumping the number after adding a tool is one command. npm run sync:tools:check (run in CI) fails if any spot is stale.
package.json is the source of truth for the version; npm run sync:version stamps it into the plugin manifest (.claude-plugin/plugin.json), the MCP-registry metadata (server.json), and the MCPB manifest (mcpb/manifest.json). CI and prepublishOnly fail if they drift. A release is:
npm version minor --no-git-tag-version # or patch/major — bumps package.json only
npm run sync:version # stamp it into the other three manifests
git commit -am vX.Y.Z # one commit, with every manifest already correct
git tag vX.Y.Z # tag it afterwards, so nothing rewrites it
git push && git push origin vX.Y.Z
npm publish # publish to npm (runs the full gate via prepublishOnly)
mcp-publisher publish # update the MCP registry listing (server.json; login: mcp-publisher login github)
npm run bundle:mcpb # build rpgmaker-mz-mcp.mcpb
gh release create vX.Y.Z rpgmaker-mz-mcp.mcpb --title vX.Y.Z --notes "..." # publish the GitHub release + attach the bundle
The Claude Code plugin needs no separate publish — users' installs update from this repo (the plugin runs the npm package via npx rpgmaker-mz-mcp@latest, so bumping npm is what ships new tools).
Tag last, and never amend a tagged commit. npm version on its own commits and tags before sync:version has stamped the other manifests, so the old recipe amended afterwards — which left the tag pointing at the pre-amend commit, with stale manifests and off the branch entirely. --no-git-tag-version avoids the whole problem: one commit, then the tag. Push the tag by name (--follow-tags is easy to get wrong here), and don't skip gh release create — nothing before it creates the GitHub release.
rpgmaker-mz-mcp/
├── src/
│ ├── index.ts # McpServer bootstrap: registers every tool, dispatch + dry-run
│ ├── registry.ts # ToolDefinition shape + shared dryRun schema
│ ├── tools/ # One module per area (actors, items, skills, maps, battle,
│ │ # classes, states, common events, moves, plugins, tiles,
│ │ # catalog, paint, objects, tilesets, system, assets,
│ │ # event-command builders, event pages, list, validation)
│ ├── events/ # Pure event-command builders (no I/O)
│ ├── tiles/ # Tile subsystem: codec, autotile solver, paint core,
│ │ # flag codec, and the semantic catalog
│ ├── validation/ # Known-command tables + event/move/plugin/reference validators
│ └── utils/ # File I/O, the commit choke point, and RPG Maker MZ types
├── test/ # Vitest suite
├── scripts/
│ └── sync-tool-count.mjs # Re-stamps the tool count into the README + SVGs
├── assets/ # Banner + architecture SVGs
├── .claude/skills/
│ └── tileset-catalog/ # Vision catalog-bootstrap skill for custom tilesets
├── dist/ # Compiled JavaScript (gitignored)
└── README.md
dryRun: true before committing them.scan_plugins parses their @command/@arg annotations), falling back to a small built-in allowlist. Since RPG Maker MZ has no "required argument" annotation, scanned args are checked for unknown names only, never for missing ones; a plugin with no annotation block passes through unchecked.Animations.json, Effekseer-based) are not edited by this server.This project started life as a fork of k4zuki0539/-rpgmaker-mz-mcp (MIT), which provided the original CRUD scaffolding. It has since grown well beyond that starting point — into full vanilla level-design and game-logic authoring (see Capabilities) — and is now maintained as its own project. Thanks to the original author for the foundation.
FAQs
High-quality MCP server for RPG Maker MZ integration - manage game data, maps, events, and plugins
We found that rpgmaker-mz-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.