C64 BridgeCAUTION
MCP server to control and program the Commodore 64 Ultimate, Ultimate 64, Ultimate II, or VICE.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Your AI Command Bridge for the Commodore 64.
[](https://www.npmjs.com/package/c64bridge) [](https://github.com/chrisgleissner/c64bridge/actions/workflows/ci.yaml) [](https://codecov.io/github/chrisgleissner/c64bridge) [](https://www.gnu.org/licenses/old-licenses/gpl-2.0.en.html) [](doc/developer.md)
[](https://vscode.dev/redirect/mcp/install?name=io.github.chrisgleissner%2Fc64bridge&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22c64bridge%22%5D%2C%22env%22%3A%7B%22C64MODE%22%3A%22c64u%22%2C%22C64UHOST%22%3A%22c64u%22%2C%22VICEBINARY%22%3A%22%2Fusr%2Flocal%2Fbin%2Fx64sc%22%2C%22VICEDIRECTORY%22%3A%22%2Fusr%2Flocal%2Fshare%2Fvice%22%2C%22VICEVISIBLE%22%3A%22true%22%2C%22VICEWARP%22%3A%22false%22%7D%7D) [](https://insiders.vscode.dev/redirect/mcp/install?name=io.github.chrisgleissner%2Fc64bridge&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22c64bridge%22%5D%2C%22env%22%3A%7B%22C64MODE%22%3A%22c64u%22%2C%22C64UHOST%22%3A%22c64u%22%2C%22VICEBINARY%22%3A%22%2Fusr%2Flocal%2Fbin%2Fx64sc%22%2C%22VICEDIRECTORY%22%3A%22%2Fusr%2Flocal%2Fshare%2Fvice%22%2C%22VICEVISIBLE%22%3A%22true%22%2C%22VICEWARP%22%3A%22false%22%7D%7D&quality=insiders) [
86 read · 34 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Example | read | desc |
Healthcheck | read | Basic firmware readiness |
Menu | read | Toggle menu |
Pause | read | Halt CPU |
Resume | read | Continue CPU |
Silence | write | Stop all voices |
alpha | read | Alpha |
analyze_audio | read | Automatically analyze SID playback when the user requests verification feedback. |
assembly-program | read | Route 6502/6510 routine requests to the canonical assembly skill. |
basic-program | read | Route bespoke Commodore BASIC v2 requests to the canonical BASIC skill. |
batch_run_with_assertions | write | Run multiple programs with post-condition assertions; produce junit-like results. |
beta | read | Beta |
bundle_run_artifacts | write | Gather screen capture, memory snapshots, and debugreg into a structured bundle for a run. |
c64_batch | write | Execute multiple c64bridge tool calls in a single request. Reduces latency for multi-step workflows. |
c64_config | read | Grouped entry point for configuration reads/writes, diagnostics, and snapshots. |
c64_custom | read | Custom grouped tool. |
c64_debug | read | Grouped entry point for VICE debugger operations (breakpoints, registers, stepping). |
c64_disk | read | Grouped entry point for disk mounts, listings, image creation, and program discovery. |
c64_drive | destructive | Grouped entry point for drive power, mode, reset, and ROM operations. |
c64_empty | read | Ungrouped placeholder. |
c64_extract | read | Grouped entry point for sprite/charset extraction, memory dumps, filesystem stats, and firmware health checks. |
c64_flattened | read | Flattened grouped tool. |
c64_flattened_metadata | read | Flattened grouped tool with operation metadata. |
c64_input | read | Cross-platform PETSCII typing plus native Ultimate keyboard and joystick events. |
c64_memory | read | Grouped entry point for memory I/O, screen reads, and screen polling. |
c64_printer | read | Grouped entry point for Commodore and Epson printing helpers. |
c64_program | write | Grouped entry point for program upload, execution, and batch workflows. |
c64_rag | read | Grouped entry point for BASIC and assembly RAG lookups. |
c64_select_backend | read | Switch the active backend between C64U/U64 hardware, U2-family cartridges, and the VICE emulator at runtime. |
c64_sound | read | Grouped entry point for SID control, playback, composition, and analysis workflows. |
c64_stream | read | Grouped entry point for starting and stopping Ultimate streaming sessions. |
c64_system | destructive | Grouped entry point for power, reset, menu, and background task control. |
c64_test | read | test grouped tool |
c64_vice | read | Grouped entry point for reading and updating selected VICE resources. |
compile_run_verify_cycle | write | Compile source (BASIC/ASM/SIDWAVE), run, verify via screen/audio, and archive artifacts. |
config_batch_update | write | Apply multiple configuration changes in a single request. |
config_get | read | Read a configuration category or specific item. |
config_list | read | List configuration categories available on the Ultimate firmware. |
config_load_from_flash | read | Load configuration settings from flash storage. |
config_reset_to_default | destructive | Reset configuration categories to their factory defaults. |
config_save_to_flash | write | Persist current configuration settings to flash storage. |
config_set | write | Set a configuration value within a category. |
config_snapshot_and_restore | write | Read all configuration categories and write a versioned snapshot, or restore from a snapshot; supports diff mode. |
create_d64 | write | Create a blank D64 disk image on the Ultimate filesystem. |
create_d71 | write | Create a blank D71 disk image on the Ultimate filesystem. |
create_d81 | write | Create a blank D81 disk image on the Ultimate filesystem. |
create_dnp | write | Create a blank DNP disk image on the Ultimate filesystem. |
cross-platform-demo | read | Route quick visible demo requests to the cross-platform demo skill. |
cross_platform_greeting | read | Render a customized greeting on VICE and/or C64U, capture screenshots, and verify both results in one workflow. |
debugreg_read | read | Read the Ultimate debug register ($D7FF). |
debugreg_write | write | Write a value into the Ultimate debug register ($D7FF). |
define_printer_chars | read | Define custom characters on Commodore MPS printers using DLL mode. |
drive-manager | read | Route disk-image and drive-state requests to the canonical drive skill. |
drive_load_rom | read | Temporarily load a custom ROM into an Ultimate drive slot. |
drive_mode | write | Set the emulation mode for an Ultimate drive slot (1541/1571/1581). |
drive_mount | read | Mount a disk image onto a specific Ultimate drive slot. |
drive_mount_and_verify | read | Mount a disk image with retry logic and verification. Powers on drive if needed, mounts image, resets drive, and verifies state. |
drive_off | read | Power off a specific Ultimate drive slot. |
drive_on | read | Power on a specific Ultimate drive slot. |
drive_remove | destructive | Remove the currently mounted disk image from an Ultimate drive slot. |
drive_reset | destructive | Reset the selected Ultimate drive slot. |
drives_list | read | List Ultimate drive slots and their currently mounted images. Read c64://guide/bootstrap for drive safety. |
extract_sprites_from_ram | write | Scan a RAM region, detect sprite blobs, and optionally save them as .spr files. |
file_info | read | Inspect metadata for a file on the Ultimate filesystem. |
filesystem_stats_by_extension | read | Walk the filesystem (and container contents) under a root and compute counts plus size statistics grouped by extension. |
find_and_run_program_by_name | write | Search under a root for the first PRG/CRT whose name contains a substring and run it. |
find_paths_by_name | read | Return device paths whose names contain a substring; supports simple extension filters and wildcard-aware firmware search. |
firmware_info_and_healthcheck | read | Fetch firmware version and info, probe zero-page read, and return readiness with latencies. |
graphics-demo | read | Route graphics requests to the canonical graphics skill. |
hardware | read | Optional focus area for the routine (sid, vic, cia, or multi for combined work). |
hello-world | read | Route ultra-fast hello-world and smoke-test requests to the canonical greeting skill. |
info | read | Retrieve hardware or emulator information and status. |
known_tool | read | known |
list_background_tasks | read | List known background tasks and their status. |
load_prg | read | Load a PRG into C64 memory without executing it. |
memory-debug | read | Route reversible memory inspection or patching work to the canonical memory skill. |
memory_dump_to_file | read | Chunked memory dump with retries; optional pause/resume; writes hex or binary and a manifest. |
menu_button | read | Toggle the Ultimate 64 menu button. |
mode | read | Target VIC-II technique (text, multicolour, bitmap, or sprite). |
modplay_file | read | Play a MOD tracker module stored on the Ultimate filesystem. |
music_compile_and_play | read | Compile a SIDWAVE composition to PRG or SID and optionally play it immediately. |
music_compile_play_analyze | read | Compile a SIDWAVE score, play it on the C64, capture the output, and analyze the recording. |
music_generate | write | Generate a lightweight arpeggio and schedule playback on SID voice 1. |
music_play_preset | read | Compile and play a built-in SID preset, with optional multi-backend routing and verification. |
pause | read | Pause the machine on Ultimate hardware. See memory safety checklist in c64://guide/bootstrap. |
performance_report | read | Summarize MCP session timings, span hot spots, and tool latencies from diagnostics logs. |
power_cycle | read | Return the active system to a fresh state: C64U/U64 uses verified Tool Menu navigation, U2-family reboots through REST, and managed VICE restarts. |
poweroff | read | Power off the machine via Ultimate firmware. See safety notes in c64://guide/bootstrap. |
preset-music-demo | read | Route quick recognizable tune requests to the SID music skill. |
print_bitmap_commodore | read | Print a Commodore MPS bit-image row using BIM BASIC helpers. |
print_bitmap_epson | read | Print an Epson FX bit-image row using ESC/P commands. |
print_text | read | Print text on device 4 using Commodore or Epson workflows. See c64://printer/spec. |
printer-job | read | Route printer work to the canonical printer skill. |
printerType | read | Select Commodore (device 4) or Epson FX workflow helpers. |
program_shuffle | destructive | Discover and run PRG/CRT programs under a root path, capturing screens and resetting between runs. |
read | read | Read a range of bytes from main memory and return the data as hexadecimal. Consult c64://assembly/6510-spec and docs index. |
read_menu_screen | read | Read the raw character and colour matrix for the currently visible Ultimate menu screen. |
read_screen | read | Read the current text screen (40x25) and return its ASCII representation. For PETSCII details, see c64://basic/spec. |
reboot_c64 | read | Reboot the Ultimate firmware and C64. See c64://guide/bootstrap. |
record_and_analyze_audio | read | Record audio and analyze SID playback characteristics. On the c64u backend the audio comes from the Ultimate audio stream; on other backends it is recorded from the host default input device (microphone). |
render_bitmap | write | Import an image file, convert it to a VIC-II bitmap, write it into RAM, and display it. |
render_petscii_art | write | Create PETSCII art from prompts, text, or bitmap input, and optionally display it on the C64. Returns metadata including PETSCII codes and glyphs. See c64://basic/spec, c64://graphics/vic/spec, and c64://graphics/character-set. |
render_petscii_text | read | Display PETSCII text with optional border and background colours. See c64://basic/spec. |
render_sprite | read | Display supplied 63-byte sprite data at the requested position and colour by writing memory and patching VIC-II registers directly. See c64://graphics/vic/spec for registers. |
reset_c64 | destructive | Reset the C64 via Ultimate firmware. Review c64://guide/bootstrap safety rules. |
resume | read | Resume the machine after an Ultimate hardware pause. |
rip_charset_from_ram | read | Locate and extract 2KB character sets from RAM by structure and entropy checks. Exports as binary. |
run_crt | write | Run a cartridge image stored on the Ultimate filesystem. |
run_prg | write | Run a PRG located on the Ultimate filesystem without uploading source. |
sid-music | read | Route SID playback and composition work to the canonical SID skill. |
sid_note_off | read | Release a SID voice by clearing its GATE bit. |
sid_note_on | write | Trigger a SID voice with configurable waveform, pulse width, and ADSR envelope. See c64://sound/sid/spec. |
sid_reset | destructive | Reset the SID chip either softly (silence) or with a full register scrub. |
sid_silence_all | read | Silence all SID voices by clearing control and envelope registers. |
sid_volume | write | Set the SID master volume register at $D418. See c64://sound/sid/spec. |
sidplay_file | read | Play a SID file stored on the Ultimate filesystem via the firmware player. |
silence_and_verify | read | Silence all SID voices, capture a short sample, and ensure the output is below an RMS threshold. |
start_background_task | write | Start a background task that runs an operation at a fixed interval for N iterations or indefinitely. |
stop_all_background_tasks | write | Stop all active background tasks. |
stop_background_task | write | Stop a named background task. |
stream_start | write | Start an Ultimate streaming session (video/audio/debug) targeting a host:port destination. See c64://guide/index for usage notes. |
stream_stop | write | Stop an Ultimate streaming session (video/audio/debug). |
upload_run_asm | write | Assemble 6502/6510 source code, upload the PRG, and run it immediately. See c64://assembly/6510-spec. |
upload_run_basic | write | Upload a BASIC program to the C64 and execute it immediately. Refer to c64://basic/spec for syntax and device I/O. |
verify_and_write_memory | write | Pause → read → verify (optional) → write → read-back → resume. Aborts on mismatch unless override. |
version | read | Retrieve firmware or emulator version information. |
wait_for_screen_text | read | Poll screen until a regex or substring matches, within a timeout. |
write | write | Write a hexadecimal byte sequence into main memory at the specified address. See c64://guide/bootstrap for safety rules. |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (13 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
const REAL_BASE = process.env.C64_REAL_BASE ?? "http://192.168.1.13";
baseUrl: `http://127.0.0.1:${address.port}`,console.error(`c64bridge MCP server running on HTTP at http://127.0.0.1:${port}/mcp`);c64_drive, c64_system, config_reset_to_default, drive_remove, drive_reset, program_shuffle, reset_c64, sid_reset
Biosphere.sid
.c8rc.json
.codecov.yml
return crypto.createHash('sha1').update(input).digest('hex');import { ViceClient } from "../../src/vice/viceClient.ts";import { buildReadyPattern, waitForBasicReady, waitForScreenPattern, asciiToScreenCodes, type TimingSink } from "../../src/vice/readiness.ts";const packageJson = readJsonFile<PackageJsonMetadata>(new URL("../../package.json", import.meta.url));const manifestJson = readJsonFile<ManifestMetadata>(new URL("../../mcp.json", import.meta.url));import { getPlatformStatus } from "../../platform.js";curl -s http://192.168.1.13/v1/info
const client = new C64Client("http://127.0.0.1:65535");[](https://cursor.com/en/install-mcp?name=io.github.chrisgleissner%2Fc64bridge&config=eyJjb
@modelcontextprotocol/sdk, axios, date-fns, fastify, jimp, meyda, octokit, pitchfinder
Gates applied: no_behavioural_pass.
4b9fb918def5full audit observations/trust-audit/mcp-server/chrisgleissner__c64-bridge.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4b9fb918def5 | CAUTION | B | 86 | first audit |
Questions
What is the C64 Bridge MCP server?
MCP server to control and program the Commodore 64 Ultimate, Ultimate 64, Ultimate II, or VICE.
What tools does C64 Bridge expose?
128 in total: 86 read-only, 34 that write, and 8 that can delete or overwrite (c64_drive, c64_system, config_reset_to_default, drive_remove, drive_reset). Every one is listed on this page with its risk.
Is C64 Bridge safe to connect to an agent?
With care. The audit graded it B (86/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does C64 Bridge need?
It reads C64U_PASSWORD, GITHUB_TOKEN and U2_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does C64 Bridge run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as c64bridge at 1.0.4.
How current is this page?
The grade is for one exact copy of the source (4b9fb918def5), read on 2026-10-08. The repository is watched and re-audited when it changes.