Install
$ agentstack add skill-tomleelive-openclaw-unreal-skill-openclaw-unreal-skill ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
OpenClaw Unreal Plugin
MCP skill for controlling Unreal Engine Editor via OpenClaw.
Connection Modes
Mode A: OpenClaw Gateway (Remote)
The plugin connects to OpenClaw Gateway via HTTP polling. Works automatically when Gateway is running.
Mode B: MCP Direct (Claude Code / Cursor)
The plugin runs an embedded HTTP server on port 27184. Use the included MCP bridge:
# Claude Code
claude mcp add unreal -- node /path/to/Plugins/OpenClaw/MCP~/index.js
# Cursor — add to .cursor/mcp.json
{"mcpServers":{"unreal":{"command":"node","args":["/path/to/Plugins/OpenClaw/MCP~/index.js"]}}}
Both modes run simultaneously.
Editor Panel
Window → OpenClaw Unreal Plugin — opens a dockable tab with:
- Connection status indicator
- MCP server info (address, protocol)
- Connect / Disconnect buttons
- Live log of tool calls and messages
Tools
Level
level.getCurrent— current level namelevel.list— all levels in projectlevel.open— open level by namelevel.save— save current level
Actor
actor.find— find by name/classactor.getAll— list all actorsactor.create— create actors: StaticMeshActor (Cube, Sphere, Cylinder, Cone), PointLight, Cameraactor.delete— delete by nameactor.getData— detailed actor infoactor.setProperty— set properties via UE reflection system
Transform
transform.getPosition/transform.setPositiontransform.getRotation/transform.setRotationtransform.getScale/transform.setScale
> Transform tools require a valid RootComponent (works on StaticMeshActor, PointLight, etc. — not on bare Actor).
Component
component.get— get component datacomponent.add— add component (not yet implemented)component.remove— remove component (not yet implemented)
Editor
editor.play— start PIE (uses RequestPlaySession)editor.stop— stop PIEeditor.pause/editor.resume— pause/resume PIEeditor.getState— current editor state
Debug
debug.hierarchy— actor hierarchy treedebug.screenshot— capture editor viewportdebug.log— write to output log
Input
input.simulateKey— simulate key pressinput.simulateMouse— simulate mouseinput.simulateAxis— simulate axis
Asset
asset.list— list assets at pathasset.import— import asset (not yet implemented)
Console
console.execute— run console commandconsole.getLogs— read project log file; params:count(number of lines),filter(text filter)
Blueprint
blueprint.list— list blueprintsblueprint.open— open blueprint (not yet implemented)
Troubleshooting
Stale binaries / plugin not loading
Clear the build cache and restart the editor:
rm -rf YourProject/Plugins/OpenClaw/Binaries YourProject/Plugins/OpenClaw/Intermediate
Connection issues
- Ensure OpenClaw Gateway is running:
openclaw gateway status - Check the Editor Panel log for errors
- Verify the MCP port is not blocked by firewall
Security & Privacy Disclosure
This skill drives a live Unreal Editor. Full disclosure of capabilities and current limitations:
- Local HTTP server hardening (plugin v1.3.1+): the embedded server (port 27184) rejects browser-originated requests (any
Originheader → 403) and supports optional shared-secret auth — setOPENCLAW_BRIDGE_TOKENfor both the Unreal Editor process and the MCP client to requireX-OpenClaw-Tokenon every request. Without the token set, keep the port on trusted machines only — any local process can send editor commands. - Destructive operations — confirm with the user before: deleting actors, saving levels, importing assets, running console commands (
console.execute), and simulating keyboard/mouse input. None of these should run implicitly from a vague request. - Data visibility:
debug.screenshotandconsole.getLogscan capture whatever is on screen or in project logs — including credentials, tokens, or source paths if present. Review before sharing captures outside the machine. - Trigger scope: routine-sounding requests ("clean up the level", "save everything", "just run it") map to state-changing Editor operations — confirm once before the first state-changing call in a session.
- Safety defaults:
disableModelInvocation: trueis set — the model cannot auto-invoke this skill; it runs only on explicit user request. Keep the project under source control before automation sessions. The KoreanSKILL_KO.mdstates the same recommendation; if the two ever disagree, this file governs.
License
Apache-2.0 — See LICENSE.md
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: TomLeeLive
- Source: TomLeeLive/openclaw-unreal-skill
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.