Rosh Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Rosh Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- mcp-name: io.github.rosh-studio/rosh-mcp -->
Give any AI the power to create and publish interactive web apps, games, and 3D scenes using Rosh — a plain-English programming language.
Rosh lets you write programs in plain English:
create box called player at 400 300
set player color "blue"
on key "ArrowRight" then set player x to player x + 5This compiles to a runnable HTML5 canvas app, a Phaser game, or a Three.js 3D scene — depending on the target.
Add to your MCP config (~/.claude/mcp.json or Claude Desktop settings):
{
"mcpServers": {
"rosh": {
"command": "uvx",
"args": ["rosh-mcp"],
"env": {
"ROSH_API_KEY": "rosh_k1_your_key_here"
}
}
}
}Same config format — add to your MCP settings file.
read,write scopesNote:rosh_docsandrosh_compilework without an API key. You only need a key for publishing.
| Tool | Description | Auth Required |
|---|---|---|
rosh_docs | Get the full Rosh language reference | No |
rosh_compile | Compile Rosh code to HTML | No |
rosh_publish | Publish a program to rosh.cloud | Yes (write) |
rosh_list_programs | List your programs | Yes (read) |
rosh_get_program | Get program details by ID | Yes (read) |
rosh_update_program | Update an existing program | Yes (write) |
rosh_delete_program | Delete a program | Yes (write) |
rosh_hide_program | Hide a program (moderation) | Yes (moderate) |
rosh_show_program | Unhide a program | Yes (moderate) |
Try these with any MCP-capable AI:
rosh_docs and explores| Variable | Required | Default | Description |
|---|---|---|---|
ROSH_API_KEY | For publishing | — | Your rosh.cloud API key |
ROSH_API_BASE | No | https://rosh.cloud | API base URL |
git clone https://github.com/rosh-studio/rosh-mcp.git
cd rosh-mcp
pip install -e .
rosh-mcp # runs the stdio serverMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.