Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | MCP Unity Editor (Game Engine)MCP100 Selected | Ghidra MCP ServerMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation github:codergamester · Publisher source ↗ | Community implementation github:bethington · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 10, 2026 Package: Not documented | Repo: Aug 14, 2026 Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 1,865 GitHub stars · checked 2026-08-14T18:46:26.000Z | 3,308 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | The WebSocket server defaults to localhost:8090. Remote instructions can bind it to 0.0.0.0; no bearer-token or OAuth mechanism is documented. | HTTP bearer authentication is optional through GHIDRA_MCP_AUTH_TOKEN; without it authentication is disabled. Non-loopback binding is refused without a token. Scripts require GHIDRA_MCP_ALLOW_SCRIPTS. |
| Cost | The publisher describes the MIT-licensed project as free and open source. Unity, Node.js, hosting, client, and model costs are separate. | The Apache-2.0 project lists no MCP fee. Ghidra, Java, Maven, hosting, and shared-server costs are separate. |
| Permissions | Executes Unity menus and controls scenes, GameObjects, components, materials, assets, packages, tests, logs, play mode, and project-state resources through a WebSocket bridge. | Reads and writes binaries and projects, renames and types symbols, adds comments and structures, executes scripts, performs P-code emulation and debugging, and integrates with Ghidra Server. |
| Data handling | Unity scenes, assets, project state, and console logs are read or modified locally and returned through MCP. Remote transmission, retention, and telemetry are not documented. | Operates on local binaries and projects and optionally shared Ghidra Server data; decompilation, memory, debugger, and script results are returned through MCP. Telemetry and retention are not documented. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Can make destructive project changes, install packages, execute menu items, and control play mode. Keep the bridge loopback-only and supervise all writes and deletions in a version-controlled project. | Write access, optional arbitrary Java scripts, debugger control, and shared-server access create substantial integrity and confidentiality risk. Prefer loopback, bearer auth, scopes, scripts disabled, and supervised writes. |
| Evidence date | ||
| Editorial review | 2026-08-11 | 2026-08-11 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →