Atlas / MCP servers / bethington / Cheat Engine

Cheat EngineSAFE

mcp/bethington/cheat-engine

MCP Cheat Engine Server — provides safe, structured read-only access to memory analysis and debugging functionality through the Model Context Protocol (MCP). For developers, security researchers, and game modders.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
59 45r · 10w · 4d
Transport
—
License
MIT
Stars
66
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

If you find this useful, please ⭐ star the repo — it helps others discover it!

📋 Table of Contents

  1. Overview
  2. Quick Start Guide
  3. Installation
  4. Configuration
  5. Using the Tools
  6. Safety & Security
  7. Troubleshooting
  8. Advanced Usage
  9. API Reference
  10. FAQ

🎯 Overview

The MCP Cheat Engine Server provides safe, structured access to memory analysis and debugging functionality through the Model Context Protocol (MCP). This tool is designed for:

  • Software developers debugging applications
  • Security researchers analyzing programs
  • Students learning about computer memory and reverse engineering
  • Game modders understanding game mechanics

⚠️ Important Safety Notice

This server operates in READ-ONLY mode for safety. It can read and analyze memory but cannot modify it. All operations are logged for security auditing.

🔧 Key Features

  • ✅ Process enumeration and attachment
  • ✅ Memory reading with multiple data types
  • ✅ Pattern scanning and searching
  • ✅ Assembly code disassembly
  • ✅ Pointer chain resolution
  • ✅ Cheat Engine table (.CT) import
  • ✅ Safe Lua script analysis
  • ✅ Comprehensive security controls

🚀 Quick Start Guide

Prerequisites

  • Windows 10/11 (64-bit recommended)
  • Python 3.9 or higher
  • Administrator privileges (for memory access)
  • Claude Desktop or compatible MCP client

30-Second Setup

  1. Download the server files to your computer
  2. Open PowerShell as Administrator
  3. Navigate to the server directory
  4. Install dependencies: pip install -r requirements.txt
  5. Start the server: python server/main.py

First Use

  1. List processes: Use the list_processes tool to see available programs
  2. Attach to a process: Use `att
Read from source at commit 4bb7f0bdafe9OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add cheat-engine-server-python -- uvx cheat-engine-server-python
claude-desktop
{
  "mcpServers": {
    "cheat-engine-server-python": {
      "command": "uvx",
      "args": [
        "cheat-engine-server-python"
      ]
    }
  }
}
03

Exposed tools (59)

45 read · 10 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_address_to_cheat_tablewriteAdd a new address entry to a cheat table
attach_to_processreadAttach debugger to specified process
browse_cheat_tables_directoryreadBrowse and get detailed information about cheat tables directory
cleanup_terminated_applicationsdestructiveRemove terminated applications from tracking
comprehensive_cheat_table_analysisreadPerform comprehensive analysis of all cheat table components
create_cheat_table_backupwriteCreate a backup of a cheat table file
create_new_cheat_tablewriteCreate a new empty cheat table file
detach_processreadSafely detach from current process
extract_cheat_table_addressesreadExtract and format addresses from a cheat table file
extract_cheat_table_disassembler_commentsreadExtract disassembler comments from a cheat table file
extract_cheat_table_lua_scriptreadExtract Lua script from a cheat table file
extract_cheat_table_structuresreadExtract structure definitions from a cheat table file
extract_unitplayer_structurereadExtract the UnitPlayer structure definition from a cheat table
get_application_inforeadGet detailed information about a specific launched application
get_cheat_engine_basic_versionreadGet just the basic Cheat Engine version string
get_cheat_engine_versionreadGet Cheat Engine version information directly from the system
get_file_inforeadGet information about a file
get_launched_applicationsreadGet list of applications launched in this session
get_process_inforeadGet detailed information about currently attached process
get_whitelisted_applicationsreadGet list of applications that can be launched
launch_applicationreadLaunch a whitelisted application
list_cheat_tablesreadList all .CT (Cheat Table) files in the specified directory
list_processesreadEnumerate running processes available for attachment
load_cheat_tablereadLoad and parse a .CT (Cheat Table) file to extract address information
modify_address_in_cheat_tablewriteModify an existing address entry in a cheat table
pyautogui_batch_clicksreadPerform multiple click operations in sequence
pyautogui_batch_keysreadPerform multiple keyboard operations in sequence
pyautogui_click_mousereadClick the mouse at specific coordinates or current position
pyautogui_create_image_templatewriteCreate an image template from a screen region for future recognition
pyautogui_drag_mousewriteDrag the mouse from start coordinates to end coordinates
pyautogui_find_all_imagesreadFind all instances of an image on the screen
pyautogui_find_imagereadFind an image on the screen using template matching
pyautogui_find_templatereadFind a previously created image template on the screen
pyautogui_get_available_keysreadGet a list of all available keyboard keys that can be used with PyAutoGUI
pyautogui_get_mouse_positionreadGet the current mouse cursor position
pyautogui_get_pixel_colorreadGet the RGB color value of a pixel at specific screen coordinates
pyautogui_get_screen_inforeadGet detailed information about the screen (resolution, size)
pyautogui_hold_keyreadHold a key down for a specified duration
pyautogui_is_on_screenreadCheck if given coordinates are within screen bounds
pyautogui_key_combinationreadPress a combination of keys simultaneously (hotkeys)
pyautogui_move_mousewriteMove the mouse cursor to specific coordinates
pyautogui_press_keyreadPress a specific key one or more times
pyautogui_screenshotreadTake a screenshot of the entire screen or a specific region
pyautogui_scroll_mousereadScroll the mouse wheel at specific coordinates or current position
pyautogui_set_failsafewriteEnable or disable PyAutoGUI failsafe (emergency stop by moving mouse to corner)
pyautogui_set_pausewriteSet the pause duration between PyAutoGUI actions
pyautogui_type_textreadType text with optional interval between characters
pywinauto_click_elementreadClick on a UI element in a Windows application
pywinauto_close_applicationreadClose a connected Windows application
pywinauto_connect_applicationreadConnect to an existing Windows application using PyWinAuto
pywinauto_find_elementreadFind UI elements within a Windows application
pywinauto_find_windowsreadFind Windows desktop windows by various criteria
pywinauto_get_window_hierarchyreadGet the UI element hierarchy tree for a window
pywinauto_launch_applicationreadLaunch and connect to a Windows application using PyWinAuto
pywinauto_type_textreadType text into a UI element in a Windows application
remove_address_from_cheat_tabledestructiveRemove an address entry from a cheat table
terminate_all_launched_applicationsdestructiveTerminate all applications launched in this session
terminate_applicationdestructiveTerminate a running application
write_cheat_table_to_filewriteCopy/write a cheat table to a new location
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
cleanup_terminated_applications, remove_address_from_cheat_table, terminate_all_launched_applications, terminate_application
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/run_advanced_tests.py:114
__import__(dep)
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/run_advanced_tests.py:123
__import__(dep)
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/automation_demo.py:1
class ValidationResult:
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, trio, psutil, capstone, pyautogui, pillow, opencv-python, pywinauto
Why it matters. 8 requirement(s) not pinned with ==
Fix. pin exact versions
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:477
A: Windows requires elevated privileges to read memory from other processes for security reasons.
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
clients/DBENGINE_COMPLETE_ADDRESS_RESULTS.md:19
- **Launch Method:** Elevated privileges (UAC)
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
clients/DBENGINE_COMPLETE_ADDRESS_RESULTS.md:87
- 💡 Operations require elevated privileges
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
clients/DBENGINE_COMPLETE_ADDRESS_RESULTS.md:106
- ✅ Elevated privilege handling
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
clients/DBENGINE_COMPLETE_ADDRESS_RESULTS.md:120
- DBEngine requires elevated privileges
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/FAQ.md:49
1. Reinstall Python and check "Add to PATH" during installation
Why it matters. instructs the agent to persist itself in the user's environment
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/INSTALLATION.md:181
2. Reinstall Python, making sure to check "Add to PATH"
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4bb7f0bdafe9full audit observations/trust-audit/mcp-server/bethington__cheat-engine.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084bb7f0bdafe9SAFEB89first audit
06

Questions

What is the Cheat Engine MCP server?

MCP Cheat Engine Server — provides safe, structured read-only access to memory analysis and debugging functionality through the Model Context Protocol (MCP). For developers, security researchers, and game modders.

What tools does Cheat Engine expose?

59 in total: 45 read-only, 10 that write, and 4 that can delete or overwrite (cleanup_terminated_applications, remove_address_from_cheat_table, terminate_all_launched_applications, terminate_application). Every one is listed on this page with its risk.

Is Cheat Engine safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Cheat Engine need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (4bb7f0bdafe9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement