‹ The Index

Vrchat

npm

MCP server for VRChat friends, worlds, groups, events, notifications, and VRCX history.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: Security — see all ranked ›

Install (Claude Code):

claude mcp add rchat -- npx -y @basicbit/vrchat-mcp
deep

“Quotes VRChat's guidelines and refuses hosted use; router tools document their params.”

Security audit

scanned 2026-07-30

Every finding is shown in full. A licence adds the detail needed to act on it — which advisory, what the install script does, the version that fixes it.

No known advisoriesclearchecked against OSV for 0.1.8
Handles credentials or secrets · Connects to databases · Makes network requestsfrom declared dependencies
Can carry remote content into your agentunlock detail
Signed build provenancepublished from public CI with an attestation

1 finding here has detail behind a licence. You can see it exists above, free, permanently — Pro tells you what third-party content it can pull into your agent.

Unlock the fix — $6/mo ›or check your whole config free with npx tashan-cli doctor

npm ↗  ·  source ↗  ·  pkg:@basicbit/vrchat-mcp

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›