Atlas / MCP servers / bromoket / x64dbg

x64dbgSAFE

mcp/bromoket/x64dbg-1

Drive x64dbg with your AI. MCP server: 23 mega-tools / 153 endpoints for breakpoints, memory, disasm, tracing, anti-debug & PE dumping. Claude/Cursor/Windsurf/Cline. All local.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
23 15r · 8w · 0d
Transport
stdio
License
MIT
Stars
131
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/x64dbg-mcp-server) [](https://registry.modelcontextprotocol.io) [](https://opensource.org/licenses/MIT)

Drive [x64dbg](https://x64dbg.com/) with your AI. Talk to Claude, Cursor, Windsurf, Cline, or any MCP client in plain English and it sets breakpoints, reads memory, disassembles, traces, dumps PEs, and bypasses anti-debug — live, inside the debugger.

23 mega-tools over 153 REST endpoints, fully typed with Zod. A C++ plugin runs inside x64dbg; a tiny TypeScript server bridges it to your client over stdio. Everything stays on 127.0.0.1 — nothing leaves your machine.

Latest — v2.3.0 - Hardened & crash-proof. A malformed HTTP request can no longer crash x64dbg; the plugin server drains connections cleanly on stop and ships an optional auth token (CORS is locked down). - Real data from more tools. imports/exports, symbols search/list, patches list, and strings now return actual parsed results instead of pointing you at a GUI view. - Live trace status. New /api/trace/status (+ tracing status) reports whether a trace is running, and the exception/trace tools now honor every parameter they accept. - Plus the v2.2.x fixes: x32dbg loads on current snapshots, and requests no longer time out on long operations. Download the v2.3.0 plugins →

What it looks like

"Set a breakpoint on CreateFileW and run the program"
"Disassemble the current function and explain what it does"
"Search for 48 8B ?? 48 85 C0 in the main module and disassemble the hits"
"Hide the debugger and bypass the anti-debug checks"
"Trace into the VM dispatcher and log every instruction to a file"
"Dump the main mo
Read from source at commit 535c15a69abbOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add x64dbg-mcp-server -- npx -y [email protected]
03

Exposed tools (23)

15 read · 8 write · 0 destructive.

ToolRiskDescription
x64dbg_address_convertreadConvert Virtual Address (VA) to File Offset, or File Offset to VA
x64dbg_analysisreadGet function info, xrefs, basic blocks or source location for an address
x64dbg_antidebugreadAnti-debugging analysis: Read PEB/TEB/DEP, or hide debugger
x64dbg_breakpointswriteUnified tool for all breakpoint operations (set, get, list, configure, toggle, remove)
x64dbg_commandwriteExecute x64dbg commands, scripts, eval expressions, or manage debug session
x64dbg_control_flowreadGet CFG/branch/loop info or manage function definitions
x64dbg_databasereadList known constants, error codes, defined structs, or search strings in a module
x64dbg_debugwriteExecute core debugger actions (run, pause, step, state, etc.)
x64dbg_disassemblyreadDisassemble or assemble instructions (at address, function, info, assemble)
x64dbg_dumpingreadDump modules, fix IAT, or get PE header/sections/imports/exports
x64dbg_exceptionsreadManage exception breakpoints, list Windows exception codes, or skip exceptions
x64dbg_handlesreadList handles/tcp/windows/heaps, get handle name, or close a handle
x64dbg_memorywriteCore memory operations: read, write, info, allocate, free, protect, map
x64dbg_modulesreadList modules or get info (base, section, party) for a specific module
x64dbg_patcheswriteList, apply, restore patches or export patched module
x64dbg_processwriteGet process info (basic, detailed, cmdline, elevated, dbversion) or set cmdline
x64dbg_registerswriteGet or set CPU register values (all, specific, flags, avx512, set)
x64dbg_searchreadPattern/string search, symbol autocomplete, or get string at address
x64dbg_stackreadStack operations: call stack, read raw, get pointers/SEH/comments
x64dbg_symbolsreadSymbol, label, comment, and bookmark operations
x64dbg_threadsreadThread operations: list, get current/specific/teb/name, or switch/suspend/resume
x64dbg_tracingwriteExecution tracing operations: step into/over, run, animate, get trace info
x64dbg_watchdogreadCheck if a watch expression watchdog has been triggered
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/REFERENCE.md:369
4. Test manually: `curl http://127.0.0.1:27042/api/health`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
server/package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 535c15a69abbfull audit observations/trust-audit/mcp-server/bromoket__x64dbg-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07535c15a69abbSAFEB89first audit
06

Questions

What is the x64dbg MCP server?

Drive x64dbg with your AI. MCP server: 23 mega-tools / 153 endpoints for breakpoints, memory, disasm, tracing, anti-debug & PE dumping. Claude/Cursor/Windsurf/Cline. All local.

What tools does x64dbg expose?

23 in total: 15 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is x64dbg safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does x64dbg need?

It reads X64DBG_MCP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does x64dbg run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as x64dbg-mcp-server at 2.3.0.

How current is this page?

The grade is for one exact copy of the source (535c15a69abb), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement