Atlas / MCP servers / 0xhackerfren / Frida Game Hacking

Frida Game HackingBLOCK

mcp/0xhackerfren/frida-game-hacking

A MCP implementation of Frida that seeks to emulate Cheat Engine functionally to allow for seamless Game Hacking by AI agents

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
42 37r · 3w · 2d
Transport
—
License
MIT
Stars
77
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides Cheat Engine-like capabilities for game hacking through Frida. Enables AI assistants and automation tools to perform memory scanning, value modification, pattern matching, function hooking, and code injection.

Features

Memory Operations (Cheat Engine Style)

  • Value Scanning: Find values in memory by type (int8-64, float, double, string)
  • Scan Refinement: Narrow results with scan_next, scan_changed, scan_unchanged
  • Pattern Scanning: Array of Bytes (AoB) with wildcard support (??)
  • Memory Read/Write: Read and modify memory with type awareness

Function Hooking & Code Injection

  • Intercept Functions: Hook with onEnter/onLeave JavaScript callbacks
  • Replace Functions: Make functions return custom values
  • Module Hooking: Hook by module!function name
  • Symbol Resolution: Resolve exports to addresses

Process Management

  • Process Enumeration: List and filter running processes
  • Attach/Detach: Connect to running processes
  • Spawn & Resume: Start processes suspended for early hooking

Debugging

  • Breakpoints: Software breakpoints via hooks
  • Register Access: Read CPU registers at breakpoints
  • Module Analysis: List modules, exports, imports

Window Interaction (Windows)

  • Screenshot Capture: Take screenshots of game windows
  • Keyboard Input: Send keystrokes to game windows
  • Window Management: List, focus, and interact with windows

Installation

# Install from PyPI (coming soon)
pip install frida-game-hacking-mcp

# Or install from source
git clone https://github.com/0xhackerfren/frida-game-hacking-mcp.git
cd frida-game-ha
Read from source at commit 0c827552e306OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add frida-game-hacking-mcp -- uvx frida-game-hacking-mcp
claude-desktop
{
  "mcpServers": {
    "frida-game-hacking-mcp": {
      "command": "uvx",
      "args": [
        "frida-game-hacking-mcp"
      ]
    }
  }
}
03

Exposed tools (42)

37 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
attachread
call_rpcread
check_installationread
clear_scandestructive
detachread
focus_windowread
get_documentationread
get_module_exportsread
get_module_importsread
get_module_inforead
get_scan_resultsread
get_session_inforead
hook_functionread
hook_native_functionread
intercept_module_functionread
list_breakpointsreadList all active breakpoints.
list_capabilitiesread
list_hooksread
list_memory_regionsread
list_modulesread
list_processesread
list_windowsread
load_scriptread
read_memoryread
read_registersread
remove_breakpointdestructive
replace_functionread
resolve_symbolread
resumeread
scan_changedread
scan_nextread
scan_patternread
scan_unchangedread
scan_valueread
screenshot_screenread
screenshot_windowread
send_key_to_windowwrite
set_breakpointwrite
spawnread
unhook_functionread
unload_scriptread
write_memorywrite
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (11)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
examples/custom_script_rpc.md:42
// Set health address for god mode
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
examples/custom_script_rpc.md:48
// Toggle god mode
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
examples/custom_script_rpc.md:87
# Toggle god mode on
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_scan, remove_breakpoint
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/frida_game_hacking_mcp/server.py:614
raw_bytes = bytes.fromhex(response['hex'])
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/frida_game_hacking_mcp/server.py:660
write_bytes = bytes.fromhex(data.replace(" ", ""))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/frida_game_hacking_mcp/server.py:668
write_bytes = bytes.fromhex(data.replace(" ", ""))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/frida_game_hacking_mcp/server.py:990
current_value = _unpack_value(bytes.fromhex(c['hex']), value_type)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/frida_game_hacking_mcp/server.py:1082
current_value = _unpack_value(bytes.fromhex(c['hex']), value_type)
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
examples/custom_script_rpc.md:7
You want to create a reusable "god mode" script that can be toggled on/off.
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
examples/custom_script_rpc.md:51
return "God mode: " + (godModeEnabled ? "ON" : "OFF");
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0c827552e306full audit observations/trust-audit/mcp-server/0xhackerfren__frida-game-hacking.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070c827552e306BLOCKD69first audit
06

Questions

What is the Frida Game Hacking MCP server?

A MCP implementation of Frida that seeks to emulate Cheat Engine functionally to allow for seamless Game Hacking by AI agents

What tools does Frida Game Hacking expose?

42 in total: 37 read-only, 3 that write, and 2 that can delete or overwrite (clear_scan, remove_breakpoint). Every one is listed on this page with its risk.

Is Frida Game Hacking safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Frida Game Hacking need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (0c827552e306), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement