Never let an LLM’s raw text run as code. Have the model return structured output (a function call or JSON matching a schema), validate it against a whitelist of allowed actions and parameters, then let your game code – not the model – execute the action.
At a glance
| Fact | Value | Source |
|---|---|---|
| Safe pattern for LLM-driven actions | structured output + whitelist | |
| GPT-4o context window size | 128,000 tokens | developers.openai.com |
| In-browser LLM inference option | WebLLM via WebGPU | llm.mlc.ai |
Treat the LLM as an untrusted client. Never eval() its text, never let it write to game state directly, and never pass its output straight to a scripting API. Instead, ask the model for structured output – a JSON object or a function call with a fixed schema (action name plus typed parameters) – then validate that object in your own code before anything happens in the game. If the action name or a parameter isn’t on your whitelist, reject it and display plain dialogue text instead.
If you’re building the game with an AI coding agent, the same ‘agent proposes, code executes’ split applies to your tooling. Playgama MCP gives an agent (Claude Code, Cursor, Codex, VS Code) the developer-cabinet actions – creating the game, uploading builds and covers, editing leaderboards and items, publishing a sandbox link – while the agent itself still writes all the game code, including your LLM action handlers.
What to check, in order
- Define a closed list of actions the game can perform (open_door, give_item, start_quest) with typed parameters – never a free string the LLM can turn into a command.
- Use the model’s structured/function-calling output rather than parsing free text; if the API rejects the schema, treat that as no action, not a crash.
- Validate ranges and ids server-side or in a trusted module (item exists, door is in range) before mutating state.
- Rate-limit and log every accepted action so a runaway loop can’t spam triggers.
- If running a model in-browser (WebGPU-based engines), the same validation step still applies locally – client-side execution isn’t a substitute for it.
- Keep any API key server-side; a browser game calling an LLM directly exposes the key to anyone who opens devtools.
Next step: prototype the action schema against a few adversarial prompts (players trying to get free items or skip quests) before wiring it into real game state.
Sources
- GPT-4o Model | OpenAI API
- WebLLM Javascript SDK โ mlc-llm documentation
- LLM for Unity (LLMUnity-WWFork)
- Model Context Protocol docs
- Playgama Bridge SDK docs
Related questions
Should the LLM ever call game functions directly?
No. The model should only propose a structured action; your game code decides whether to run it after validating the action name and parameters against a whitelist.
How do I stop a player from tricking the LLM into cheating?
Validate every proposed action against real game state server-side or in trusted code, not just against the schema – the schema stops malformed calls, not unfair ones.
Can I run the LLM fully in the browser to avoid API key exposure?
Yes, engines like WebLLM run inference locally via WebGPU, but you still need to validate any action the model proposes before executing it.
Last updated: 30 September 2026