MuJoCo
Fast and accurate physics engine for robotics, biomechanics, and RL research, now open-sourced by DeepMind.
MuJoCo
MuJoCo (Multi-Joint dynamics with Contact) is a fast, accurate physics engine originally developed by Emo Todorov and now maintained by Google DeepMind as free open-source software. It is the de-facto standard simulator for robotics and reinforcement learning research, used in thousands of published works.
Key Features
- Generalised-coordinate articulated body simulation with contacts and friction
- Native Python bindings (
mujocopackage on PyPI) with NumPy integration - Full access to forward/inverse dynamics, Jacobians, and analytical gradients
- Passive viewer, offscreen rendering (OpenGL), and MJX GPU-accelerated backend (JAX)
- XML-based MJCF model format with extensive robot library (humanoids, arms, hands, legged robots)
Quick Start
pip install mujoco
import mujoco
import numpy as np
model = mujoco.MjModel.from_xml_string('<mujoco><worldbody><body><joint/><geom size=".1"/></body></worldbody></mujoco>')
data = mujoco.MjData(model)
for _ in range(100):
mujoco.mj_step(model, data)
print(data.qpos)
npx ai-supply add mujoco-physics-engine
Curated mirror of the open-source MuJoCo (Apache-2.0). Get it from the source.
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
The same gate an agent runs before installing (POST /api/v1/trust/mujoco-physics-engine/check). Click a policy:
Consume MuJoCo programmatically. Authenticate with an API key or session — see Authorize an agent.
# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/mujoco-physics-engine
# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/mujoco-physics-engine/check \
-H "Content-Type: application/json" \
-d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'
# CLI
npx ai-supply add mujoco-physics-engine
# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/mujoco-physics-engine/install \
-H "Authorization: Bearer $AIM_KEY"
# MCP tool
install_listing({ "slug": "mujoco-physics-engine" })OpenAPI spec →Curated mirror — latest upstream source. See the repository for tagged releases.