Cheat Engine BridgeSAFE
Connect your favorite AI agents directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using natural language.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Let multibillion $ AI datacenters analyze the program memory for you.
Create mods, trainers, security audits, game bots, accelerate RE, or do anything else with any program and game in a fraction of a time.
[](#) [](https://python.org)
[!NOTE] Thanks everyone for the stars, much appreciated! <3 Specially a big thank you to all the contributors!! @libangli218, @lauralex, @iamtyroon, @HachiroSan, @Attacktive
The Problem
You're staring at gigabytes of memory. Millions of addresses. Thousands of functions. Finding that one pointer, that one structure takes days or weeks of manual work.
What if you could just ask?
"Find the packet decryptor hook." "Find the OPcode of character coordinates." "Find the OPcode of health values." "Find the unique AOB pattern to make my trainer reliable after game updates."
That's exactly what this does.
- Stop clicking through hex dumps and start having conversations with the memory.
What You Get:
Your AI can now:
- Read any memory instantly (integers, floats, strings, pointers)
- Follow poin
89bd885485eeOBSERVED · 2026-09-25Exposed tools (175)
113 read · 50 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_element_to_structure | write | Add a new element to an existing CE structure. |
allocate_kernel_memory | read | Allocate non-paged kernel memory via the DBK driver. |
allocate_memory | read | Allocate memory in the target process. |
allocate_shared_memory | write | Create and map a shared memory region in the target process. |
analyze_function | read | Analyze a function to find all CALL instructions output (calls made by this function). |
analyze_pointer_access | read | Parse a captured memory access (instruction + register snapshot from a breakpoint/DBVM hit) into base register, displacement, and the concrete struct-base address for pointer-chain walk-back. Pure analysis; no process access. next_scan_value is the address to scan for (as a pointer) to find the next |
aob_scan | read | Scan for an Array of Bytes (AOB) pattern. Example: |
aob_scan_module | read | Scan for an AOB pattern restricted to a specific module |
aob_scan_module_unique | read | Scan for an AOB pattern in a specific module that must match exactly once. |
aob_scan_unique | read | Scan for an AOB pattern that must match exactly once. Returns {success, address} or error with count. |
assemble_instruction | read | Assemble a single x86/x64 instruction into bytes. |
auto_assemble | write | Run an AutoAssembler script (injection, code caves, etc). |
auto_assemble_check | read | Validate an Auto Assembler script for syntax errors without executing it. |
beep | read | Play a simple system beep sound. |
check_synchronize | read | Process queued main-thread calls (checkSynchronize). |
checksum_memory | read | Calculate MD5 checksum of a memory region to detect changes. |
clear_all_breakpoints | destructive | Remove ALL breakpoints. |
compare_memory | read | Compare two memory regions. Methods: 0=target/target, 1=addr1=target addr2=CE, 2=both CE. Returns equal flag and first_diff byte index (-1 if equal). |
compile_c_code | read | Compile C source code using CE |
compile_cs_code | read | Compile C# source code using CE |
copy_memory | read | Copy memory between addresses. Methods: 0=target→target, 1=target→CE, 2=CE→target, 3=CE→CE. Returns dest_address allocated by CE if dest is None. |
create_memory_record | write | Create a new memory record in the cheat table address list. |
create_persistent_scan | write | Create a named, stateful memory scan session. Use the name with persistent_scan_* tools. |
create_process | write | Create and optionally debug a new process. |
create_section | write | Create a Windows section (shared memory) of the given size. Returns a handle as a hex string. |
create_structure | write | Create a new empty CE structure definition and add it to the global list. |
create_thread | write | Execute Lua code in a new CE thread. |
dbk_get_cr0 | read | Read Control Register 0 (CR0) via the DBK kernel driver. |
dbk_get_cr3 | read | Read Control Register 3 (CR3 — page-table base) via DBK or DBVM. |
dbk_get_cr4 | read | Read Control Register 4 (CR4) via the DBK kernel driver. |
dbk_writes_ignore_write_protection | write | Toggle whether DBK memory writes bypass copy-on-write (CoW) protection. |
debug_break_thread | read | Break a specific thread by its thread ID. |
debug_continue | read | Continue execution from a breakpoint. |
debug_detach | read | Detach the debugger from the target process if possible. |
debug_get_context | read | Get the current thread |
debug_get_current_debugger_interface | read | Return the active debugger interface used by CE. |
debug_get_last_branch_record | read | Get the from/to addresses of a Last Branch Record entry at the given index. |
debug_get_xmm_pointer | read | Return the CE-local memory address of an XMM register (0-15) for the currently broken thread. |
debug_is_debugging | read | Check whether the CE debugger has been started. |
debug_process | write | Start the CE debugger for the currently opened process. |
debug_remove_breakpoint_for_thread | destructive | Remove a per-thread breakpoint at the given address for the given thread. |
debug_set_breakpoint_for_thread | write | Set a breakpoint that fires only on a specific thread. trigger: execute|write|read|access. |
debug_set_context | write | Set CPU register values in the paused thread. Pass a dict like {\ |
debug_set_last_branch_recording | write | Enable or disable Intel LBR (Last Branch Recording). Requires kernel-mode debugger. |
delete_all_registered_symbols | destructive | Delete every user-registered symbol (both AA and Lua). |
delete_file | destructive | Delete a file at the given path. Returns {success}. |
delete_memory_record | destructive | Delete a memory record from the cheat table address list by ID. |
delete_structure | destructive | Delete a CE structure from the global list and free it. |
disassemble | read | Disassemble instructions starting at an address. |
dissect_structure | read | Use CE |
do_key_press | read | Simulate a full key press (down + up) for the given key. |
enable_kernel_symbols | write | Enable kernel-mode symbol resolution (requires DBK driver). |
enable_windows_symbols | write | Trigger download and load of Windows PDB symbol files. |
enum_memory_regions_full | read | Enumerate ALL memory regions in the process (Native EnumMemoryRegions). |
enum_modules | read | List all loaded modules (DLLs) with their base addresses and sizes. |
enum_registered_symbols | read | List all user-registered symbols. |
evaluate_lua | write | Execute arbitrary Lua code in Cheat Engine. |
execute_code | write | Call a stdcall function with one argument at the given address in the target process. |
execute_code_ex | write | Call a function with an explicit calling convention and multiple arguments. |
execute_code_local | write | Call a stdcall function inside Cheat Engine |
execute_code_local_ex | write | Call a function inside Cheat Engine |
execute_method | write | Call a C++ instance method with an implicit |
export_structure_to_xml | read | Export a CE structure definition as XML. |
file_exists | read | Check whether a file exists at the given path. Returns {success, exists: bool}. |
find_call_references | read | Find all locations that CALL this function. |
find_function_boundaries | write | Attempt to find the start and end of a function containing the address. |
find_references | read | Find instructions that access (reference) this address. |
find_window | read | Find a top-level window by title and/or class name (system-wide, no process required). |
free_memory | read | Free memory previously allocated in the target process. |
full_access | write | Grant full read-write-execute access to a memory region (convenience wrapper). |
generate_api_hook_script | read | Generate an Auto Assembler script that hooks a function and redirects it. |
generate_code_injection_script | read | Generate a boilerplate code-injection Auto Assembler script for an address. |
generate_signature | read | Generate a unique AOB signature that can find this specific address again. |
get_address_info | read | Get symbolic name and module info for an address (Reverse of get_symbol_address). |
get_address_list | read | List memory records in the current cheat table |
get_breakpoint_hits | destructive | Get hits for a specific breakpoint ID (or all if None). Set clear=True to flush buffer. |
get_directory_list | read | List subdirectories in the given directory path. Returns {success, count, directories: [str]}. |
get_file_list | read | List files in the given directory path. Returns {success, count, files: [str]}. |
get_file_version | read | Get the version info of a file (major, minor, release, build). Returns {success, major, minor, release, build, version_string}. |
get_foreground_process | read | Get the PID and window handle of the process currently in the foreground. |
get_global_variable | read | Read a global variable from CE |
get_instruction_info | read | Get detailed info about a single instruction (size, bytes, opcode). |
get_memory_protection | read | Query the protection flags of a memory page in the target process. |
get_memory_record | read | Retrieve a single memory record by ID or description. |
get_memory_record_value | read | Read the current value of a memory record as a string. |
get_memory_regions | read | Get list of valid memory regions nearby common bases. |
get_module_size | read | Get the in-memory size of a loaded module. |
get_mouse_pos | read | Get the current mouse cursor position. Returns x and y screen coordinates. |
get_opened_process_handle | read | Get the OS handle of the process currently attached to Cheat Engine as a hex string. |
get_opened_process_id | read | Get the PID of the process currently attached to Cheat Engine. |
get_physical_address | read | Translate Virtual Address to Physical Address (requires DBVM). |
get_physical_address_cr3 | read | Translate a virtual address to its physical address using an explicit CR3. |
get_pixel | read | Get the colour of a screen pixel at (x, y). Returns r, g, b channels and the raw COLORREF integer. |
get_process_info | read | Get current process ID, name, modules count and architecture. |
get_process_list | read | Get the list of running processes on the system. |
get_processid_from_name | read | Look up the PID of a process by its executable name. |
get_rtti_classname | write | Try to identify the class name of an object at address using Run-Time Type Information. |
get_scan_results | read | Get results from the last |
get_screen_info | read | Get the primary screen dimensions and DPI. Returns width, height (pixels) and dpi. |
get_structure_by_name | read | Find a CE structure by name in the global structure list. |
get_structure_elements | read | Get all elements of a CE structure. |
get_symbol_address | read | Resolve a symbol name (e.g., |
get_symbol_info | read | Retrieve detailed information about a known symbol. |
get_temp_folder | read | Return the path to the system temp folder. Returns {success, path: str}. |
get_thread_list | read | Get list of threads in the attached process. |
get_window_caption | read | Return the caption (title bar text) of a window given its handle (hex string). |
get_window_class_name | read | Return the window class name of a window given its handle (hex string). |
get_window_process_id | read | Return the process ID that owns a window given its handle (hex string). |
in_main_thread | read | Check whether the current code is running in CE |
inject_dll | read | Inject a DLL into the currently attached target process. |
inject_dotnet_dll | write | Inject a .NET DLL and invoke a static method in the target process. |
input_query | read | Show a modal text-input dialog in Cheat Engine and return what the user typed. |
is_key_pressed | read | Check whether a key is currently held down. |
key_down | read | Simulate pressing a key down (does NOT release it automatically). |
key_up | read | Release a key that was pressed with key_down. |
list_breakpoints | read | List all active breakpoints. |
load_new_symbols | write | Scan for newly loaded modules and import their symbols. |
load_table | read | Load a Cheat Engine table (.ct) file into the current session. |
map_memory | read | Map a kernel/physical address range into the CE usermode context via DBK. |
map_view_of_section | read | Map a section into the target process. |
md5_file | read | Calculate the MD5 hash of a file on the CE host. Filename must not contain |
md5_memory | read | Calculate the MD5 hash of a memory region. Returns the hash as a hex string. |
next_scan | read | Next scan to filter results from the last |
open_process | read | Open a process by PID or name and attach Cheat Engine to it. |
output_debug_string | write | Post a message to the Windows debugger via OutputDebugString (readable with tools like DebugView). |
pause_process | read | Pause (freeze) the currently opened process using CE |
persistent_scan_destroy | destructive | Destroy a named persistent scan session and free its memory. |
persistent_scan_first_scan | write | Run the first scan on a named persistent scan session. |
persistent_scan_get_results | read | Get paginated results from a named persistent scan session. |
persistent_scan_next_scan | read | Narrow down results with a next scan on a named persistent scan session. |
ping | read | Check connectivity and get version info. |
play_sound | read | Play a WAV sound file by filename. Path must not contain |
pointer_rescan | read | Re-scan an existing pointer scan for a new value. Requires a prior pointer scan in CE. |
poll_dbvm_watch | read | Poll DBVM watch logs WITHOUT stopping. Returns register state at each execution hit. |
queue_to_main_thread | write | Queue Lua code to run on CE |
read_clipboard | read | Read text from the system clipboard. Returns {success, text: str}. |
read_integer | read | Read a number from memory. Types: byte, word, dword, qword, float, double. |
read_memory | read | Read raw bytes from memory. |
read_pointer | read | Read a pointer chain. Returns the final address and value. |
read_pointer_chain | read | Follow a multi-level pointer chain and return analysis of every step. |
read_process_memory_cr3 | read | Read virtual memory using an explicit CR3 page-table base via DBK/DBVM. |
read_region_from_file | read | Read a file into memory at the given destination address. Filename must be an absolute path and must not contain |
read_string | read | Read a string from memory. |
register_symbol | read | Register a user-defined symbol with a given name and address. |
reinitialize_symbol_handler | destructive | Perform a full reset and reload of the Cheat Engine symbol handler. |
remove_breakpoint | destructive | Remove a breakpoint by its ID. |
run_command | write | Execute a shell command in the host OS. SECURITY: Arbitrary code execution. |
save_table | write | Save the current cheat table to a file. |
scan_all | read | Unified Memory Scanner (first scan). |
search_string | read | Quickly search for a text string in memory. |
send_window_message | write | Send a Windows message (WM_*) to a window. |
set_breakpoint | write | Set a hardware execution breakpoint. Non-breaking/Logging only. |
set_data_breakpoint | write | Set a hardware data breakpoint (watchpoint). Types: |
set_global_variable | write | Write a global variable in CE |
set_memory_protection | write | Change the protection flags of a memory region in the target process. |
set_memory_record_value | write | Write a value to a memory record (and therefore to the target process memory). |
set_mouse_pos | write | Move the mouse cursor to screen position (x, y). |
set_progress_state | write | Set the Cheat Engine taskbar progress state. Valid states: none, normal, paused, error, indeterminate. |
set_progress_value | write | Set the Cheat Engine taskbar progress bar position. Provide current value and maximum value. |
shell_execute | write | Invoke Windows ShellExecute. SECURITY: Arbitrary code execution. |
show_message | read | Show a modal message dialog in Cheat Engine. |
show_selection_list | read | Show a modal list-selection dialog in Cheat Engine. |
speak_text | destructive | Speak text via Windows SAPI text-to-speech. Set english_only=True to force the English voice. |
start_dbvm_watch | write | Start invisible DBVM hypervisor watch. Modes: |
stop_dbvm_watch | write | Stop DBVM watch and return results. |
unmap_memory | read | Release a memory mapping created by map_memory(). |
unpause_process | read | Resume (unfreeze) the currently opened process using CE |
unregister_symbol | destructive | Remove a previously registered user-defined symbol. |
validate_pointer_chains | read | Resolve a list of candidate pointer chains and report which currently land on `target`. Each chain is { |
write_clipboard | write | Write text to the system clipboard. Returns {success}. |
write_integer | write | Write a number to memory. Types: byte, word, dword, qword, float, double. |
write_memory | write | Write raw bytes to memory. |
write_process_memory_cr3 | write | Write to virtual memory using an explicit CR3 page-table base via DBK/DBVM. |
write_region_to_file | write | Write a memory region to a file. Filename must be an absolute path and must not contain |
write_string | write | Write a string to memory (ASCII or Wide/UTF-16). |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
clear_all_breakpoints, debug_remove_breakpoint_for_thread, delete_all_registered_symbols, delete_file, delete_memory_record, delete_structure, get_breakpoint_hits, persistent_scan_destroy, reinitializ
mcp, pywin32
Gates applied: no_behavioural_pass.
89bd885485eefull audit observations/trust-audit/mcp-server/miscusi-peek__cheat-engine-bridge.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | 89bd885485ee | SAFE | B | 89 | first audit |
Questions
What is the Cheat Engine Bridge MCP server?
Connect your favorite AI agents directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using natural language.
What tools does Cheat Engine Bridge expose?
175 in total: 113 read-only, 50 that write, and 12 that can delete or overwrite (clear_all_breakpoints, debug_remove_breakpoint_for_thread, delete_all_registered_symbols, delete_file, delete_memory_record). Every one is listed on this page with its risk.
Is Cheat Engine Bridge safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Cheat Engine Bridge need?
No credential environment variables were found in its source, so it appears to need none.
How does Cheat Engine Bridge run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (89bd885485ee), read on 2026-09-25. The repository is watched and re-audited when it changes.