Cheat EngineSAFE
MCP Cheat Engine Server — provides safe, structured read-only access to memory analysis and debugging functionality through the Model Context Protocol (MCP). For developers, security researchers, and game modders.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
If you find this useful, please ⭐ star the repo — it helps others discover it!
📋 Table of Contents
- Overview
- Quick Start Guide
- Installation
- Configuration
- Using the Tools
- Safety & Security
- Troubleshooting
- Advanced Usage
- API Reference
- FAQ
🎯 Overview
The MCP Cheat Engine Server provides safe, structured access to memory analysis and debugging functionality through the Model Context Protocol (MCP). This tool is designed for:
- Software developers debugging applications
- Security researchers analyzing programs
- Students learning about computer memory and reverse engineering
- Game modders understanding game mechanics
⚠️ Important Safety Notice
This server operates in READ-ONLY mode for safety. It can read and analyze memory but cannot modify it. All operations are logged for security auditing.
🔧 Key Features
- ✅ Process enumeration and attachment
- ✅ Memory reading with multiple data types
- ✅ Pattern scanning and searching
- ✅ Assembly code disassembly
- ✅ Pointer chain resolution
- ✅ Cheat Engine table (.CT) import
- ✅ Safe Lua script analysis
- ✅ Comprehensive security controls
🚀 Quick Start Guide
Prerequisites
- Windows 10/11 (64-bit recommended)
- Python 3.9 or higher
- Administrator privileges (for memory access)
- Claude Desktop or compatible MCP client
30-Second Setup
- Download the server files to your computer
- Open PowerShell as Administrator
- Navigate to the server directory
- Install dependencies:
pip install -r requirements.txt - Start the server:
python server/main.py
First Use
- List processes: Use the
list_processestool to see available programs - Attach to a process: Use `att
4bb7f0bdafe9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add cheat-engine-server-python -- uvx cheat-engine-server-python
{
"mcpServers": {
"cheat-engine-server-python": {
"command": "uvx",
"args": [
"cheat-engine-server-python"
]
}
}
}Exposed tools (59)
45 read · 10 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_address_to_cheat_table | write | Add a new address entry to a cheat table |
attach_to_process | read | Attach debugger to specified process |
browse_cheat_tables_directory | read | Browse and get detailed information about cheat tables directory |
cleanup_terminated_applications | destructive | Remove terminated applications from tracking |
comprehensive_cheat_table_analysis | read | Perform comprehensive analysis of all cheat table components |
create_cheat_table_backup | write | Create a backup of a cheat table file |
create_new_cheat_table | write | Create a new empty cheat table file |
detach_process | read | Safely detach from current process |
extract_cheat_table_addresses | read | Extract and format addresses from a cheat table file |
extract_cheat_table_disassembler_comments | read | Extract disassembler comments from a cheat table file |
extract_cheat_table_lua_script | read | Extract Lua script from a cheat table file |
extract_cheat_table_structures | read | Extract structure definitions from a cheat table file |
extract_unitplayer_structure | read | Extract the UnitPlayer structure definition from a cheat table |
get_application_info | read | Get detailed information about a specific launched application |
get_cheat_engine_basic_version | read | Get just the basic Cheat Engine version string |
get_cheat_engine_version | read | Get Cheat Engine version information directly from the system |
get_file_info | read | Get information about a file |
get_launched_applications | read | Get list of applications launched in this session |
get_process_info | read | Get detailed information about currently attached process |
get_whitelisted_applications | read | Get list of applications that can be launched |
launch_application | read | Launch a whitelisted application |
list_cheat_tables | read | List all .CT (Cheat Table) files in the specified directory |
list_processes | read | Enumerate running processes available for attachment |
load_cheat_table | read | Load and parse a .CT (Cheat Table) file to extract address information |
modify_address_in_cheat_table | write | Modify an existing address entry in a cheat table |
pyautogui_batch_clicks | read | Perform multiple click operations in sequence |
pyautogui_batch_keys | read | Perform multiple keyboard operations in sequence |
pyautogui_click_mouse | read | Click the mouse at specific coordinates or current position |
pyautogui_create_image_template | write | Create an image template from a screen region for future recognition |
pyautogui_drag_mouse | write | Drag the mouse from start coordinates to end coordinates |
pyautogui_find_all_images | read | Find all instances of an image on the screen |
pyautogui_find_image | read | Find an image on the screen using template matching |
pyautogui_find_template | read | Find a previously created image template on the screen |
pyautogui_get_available_keys | read | Get a list of all available keyboard keys that can be used with PyAutoGUI |
pyautogui_get_mouse_position | read | Get the current mouse cursor position |
pyautogui_get_pixel_color | read | Get the RGB color value of a pixel at specific screen coordinates |
pyautogui_get_screen_info | read | Get detailed information about the screen (resolution, size) |
pyautogui_hold_key | read | Hold a key down for a specified duration |
pyautogui_is_on_screen | read | Check if given coordinates are within screen bounds |
pyautogui_key_combination | read | Press a combination of keys simultaneously (hotkeys) |
pyautogui_move_mouse | write | Move the mouse cursor to specific coordinates |
pyautogui_press_key | read | Press a specific key one or more times |
pyautogui_screenshot | read | Take a screenshot of the entire screen or a specific region |
pyautogui_scroll_mouse | read | Scroll the mouse wheel at specific coordinates or current position |
pyautogui_set_failsafe | write | Enable or disable PyAutoGUI failsafe (emergency stop by moving mouse to corner) |
pyautogui_set_pause | write | Set the pause duration between PyAutoGUI actions |
pyautogui_type_text | read | Type text with optional interval between characters |
pywinauto_click_element | read | Click on a UI element in a Windows application |
pywinauto_close_application | read | Close a connected Windows application |
pywinauto_connect_application | read | Connect to an existing Windows application using PyWinAuto |
pywinauto_find_element | read | Find UI elements within a Windows application |
pywinauto_find_windows | read | Find Windows desktop windows by various criteria |
pywinauto_get_window_hierarchy | read | Get the UI element hierarchy tree for a window |
pywinauto_launch_application | read | Launch and connect to a Windows application using PyWinAuto |
pywinauto_type_text | read | Type text into a UI element in a Windows application |
remove_address_from_cheat_table | destructive | Remove an address entry from a cheat table |
terminate_all_launched_applications | destructive | Terminate all applications launched in this session |
terminate_application | destructive | Terminate a running application |
write_cheat_table_to_file | write | Copy/write a cheat table to a new location |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
cleanup_terminated_applications, remove_address_from_cheat_table, terminate_all_launched_applications, terminate_application
__import__(dep)
__import__(dep)
class ValidationResult:
mcp, trio, psutil, capstone, pyautogui, pillow, opencv-python, pywinauto
A: Windows requires elevated privileges to read memory from other processes for security reasons.
- **Launch Method:** Elevated privileges (UAC)
- 💡 Operations require elevated privileges
- ✅ Elevated privilege handling
- DBEngine requires elevated privileges
1. Reinstall Python and check "Add to PATH" during installation
2. Reinstall Python, making sure to check "Add to PATH"
Gates applied: no_behavioural_pass.
4bb7f0bdafe9full audit observations/trust-audit/mcp-server/bethington__cheat-engine.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4bb7f0bdafe9 | SAFE | B | 89 | first audit |
Questions
What is the Cheat Engine MCP server?
MCP Cheat Engine Server — provides safe, structured read-only access to memory analysis and debugging functionality through the Model Context Protocol (MCP). For developers, security researchers, and game modders.
What tools does Cheat Engine expose?
59 in total: 45 read-only, 10 that write, and 4 that can delete or overwrite (cleanup_terminated_applications, remove_address_from_cheat_table, terminate_all_launched_applications, terminate_application). Every one is listed on this page with its risk.
Is Cheat Engine safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Cheat Engine need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (4bb7f0bdafe9), read on 2026-10-08. The repository is watched and re-audited when it changes.