Atlas / MCP servers / miscusi-peek / Cheat Engine Bridge

Cheat Engine BridgeSAFE

mcp/miscusi-peek/cheat-engine-bridge

Connect your favorite AI agents directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using natural language.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
175 113r · 50w · 12d
Transport
stdio
License
MIT
Stars
1,514
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Demo

Let multibillion $ AI datacenters analyze the program memory for you.

Create mods, trainers, security audits, game bots, accelerate RE, or do anything else with any program and game in a fraction of a time.

[](#) [](https://python.org)

[!NOTE] Thanks everyone for the stars, much appreciated! <3 Specially a big thank you to all the contributors!! @libangli218, @lauralex, @iamtyroon, @HachiroSan, @Attacktive

The Problem

You're staring at gigabytes of memory. Millions of addresses. Thousands of functions. Finding that one pointer, that one structure takes days or weeks of manual work.

What if you could just ask?

"Find the packet decryptor hook." "Find the OPcode of character coordinates." "Find the OPcode of health values." "Find the unique AOB pattern to make my trainer reliable after game updates."

That's exactly what this does.

- Stop clicking through hex dumps and start having conversations with the memory.

What You Get:

Your AI can now:

  • Read any memory instantly (integers, floats, strings, pointers)
  • Follow poin
Read from source at commit 89bd885485eeOBSERVED · 2026-09-25
02

Exposed tools (175)

113 read · 50 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_element_to_structurewriteAdd a new element to an existing CE structure.
allocate_kernel_memoryreadAllocate non-paged kernel memory via the DBK driver.
allocate_memoryreadAllocate memory in the target process.
allocate_shared_memorywriteCreate and map a shared memory region in the target process.
analyze_functionreadAnalyze a function to find all CALL instructions output (calls made by this function).
analyze_pointer_accessreadParse a captured memory access (instruction + register snapshot from a breakpoint/DBVM hit) into base register, displacement, and the concrete struct-base address for pointer-chain walk-back. Pure analysis; no process access. next_scan_value is the address to scan for (as a pointer) to find the next
aob_scanreadScan for an Array of Bytes (AOB) pattern. Example:
aob_scan_modulereadScan for an AOB pattern restricted to a specific module
aob_scan_module_uniquereadScan for an AOB pattern in a specific module that must match exactly once.
aob_scan_uniquereadScan for an AOB pattern that must match exactly once. Returns {success, address} or error with count.
assemble_instructionreadAssemble a single x86/x64 instruction into bytes.
auto_assemblewriteRun an AutoAssembler script (injection, code caves, etc).
auto_assemble_checkreadValidate an Auto Assembler script for syntax errors without executing it.
beepreadPlay a simple system beep sound.
check_synchronizereadProcess queued main-thread calls (checkSynchronize).
checksum_memoryreadCalculate MD5 checksum of a memory region to detect changes.
clear_all_breakpointsdestructiveRemove ALL breakpoints.
compare_memoryreadCompare two memory regions. Methods: 0=target/target, 1=addr1=target addr2=CE, 2=both CE. Returns equal flag and first_diff byte index (-1 if equal).
compile_c_codereadCompile C source code using CE
compile_cs_codereadCompile C# source code using CE
copy_memoryreadCopy memory between addresses. Methods: 0=target→target, 1=target→CE, 2=CE→target, 3=CE→CE. Returns dest_address allocated by CE if dest is None.
create_memory_recordwriteCreate a new memory record in the cheat table address list.
create_persistent_scanwriteCreate a named, stateful memory scan session. Use the name with persistent_scan_* tools.
create_processwriteCreate and optionally debug a new process.
create_sectionwriteCreate a Windows section (shared memory) of the given size. Returns a handle as a hex string.
create_structurewriteCreate a new empty CE structure definition and add it to the global list.
create_threadwriteExecute Lua code in a new CE thread.
dbk_get_cr0readRead Control Register 0 (CR0) via the DBK kernel driver.
dbk_get_cr3readRead Control Register 3 (CR3 — page-table base) via DBK or DBVM.
dbk_get_cr4readRead Control Register 4 (CR4) via the DBK kernel driver.
dbk_writes_ignore_write_protectionwriteToggle whether DBK memory writes bypass copy-on-write (CoW) protection.
debug_break_threadreadBreak a specific thread by its thread ID.
debug_continuereadContinue execution from a breakpoint.
debug_detachreadDetach the debugger from the target process if possible.
debug_get_contextreadGet the current thread
debug_get_current_debugger_interfacereadReturn the active debugger interface used by CE.
debug_get_last_branch_recordreadGet the from/to addresses of a Last Branch Record entry at the given index.
debug_get_xmm_pointerreadReturn the CE-local memory address of an XMM register (0-15) for the currently broken thread.
debug_is_debuggingreadCheck whether the CE debugger has been started.
debug_processwriteStart the CE debugger for the currently opened process.
debug_remove_breakpoint_for_threaddestructiveRemove a per-thread breakpoint at the given address for the given thread.
debug_set_breakpoint_for_threadwriteSet a breakpoint that fires only on a specific thread. trigger: execute|write|read|access.
debug_set_contextwriteSet CPU register values in the paused thread. Pass a dict like {\
debug_set_last_branch_recordingwriteEnable or disable Intel LBR (Last Branch Recording). Requires kernel-mode debugger.
delete_all_registered_symbolsdestructiveDelete every user-registered symbol (both AA and Lua).
delete_filedestructiveDelete a file at the given path. Returns {success}.
delete_memory_recorddestructiveDelete a memory record from the cheat table address list by ID.
delete_structuredestructiveDelete a CE structure from the global list and free it.
disassemblereadDisassemble instructions starting at an address.
dissect_structurereadUse CE
do_key_pressreadSimulate a full key press (down + up) for the given key.
enable_kernel_symbolswriteEnable kernel-mode symbol resolution (requires DBK driver).
enable_windows_symbolswriteTrigger download and load of Windows PDB symbol files.
enum_memory_regions_fullreadEnumerate ALL memory regions in the process (Native EnumMemoryRegions).
enum_modulesreadList all loaded modules (DLLs) with their base addresses and sizes.
enum_registered_symbolsreadList all user-registered symbols.
evaluate_luawriteExecute arbitrary Lua code in Cheat Engine.
execute_codewriteCall a stdcall function with one argument at the given address in the target process.
execute_code_exwriteCall a function with an explicit calling convention and multiple arguments.
execute_code_localwriteCall a stdcall function inside Cheat Engine
execute_code_local_exwriteCall a function inside Cheat Engine
execute_methodwriteCall a C++ instance method with an implicit
export_structure_to_xmlreadExport a CE structure definition as XML.
file_existsreadCheck whether a file exists at the given path. Returns {success, exists: bool}.
find_call_referencesreadFind all locations that CALL this function.
find_function_boundarieswriteAttempt to find the start and end of a function containing the address.
find_referencesreadFind instructions that access (reference) this address.
find_windowreadFind a top-level window by title and/or class name (system-wide, no process required).
free_memoryreadFree memory previously allocated in the target process.
full_accesswriteGrant full read-write-execute access to a memory region (convenience wrapper).
generate_api_hook_scriptreadGenerate an Auto Assembler script that hooks a function and redirects it.
generate_code_injection_scriptreadGenerate a boilerplate code-injection Auto Assembler script for an address.
generate_signaturereadGenerate a unique AOB signature that can find this specific address again.
get_address_inforeadGet symbolic name and module info for an address (Reverse of get_symbol_address).
get_address_listreadList memory records in the current cheat table
get_breakpoint_hitsdestructiveGet hits for a specific breakpoint ID (or all if None). Set clear=True to flush buffer.
get_directory_listreadList subdirectories in the given directory path. Returns {success, count, directories: [str]}.
get_file_listreadList files in the given directory path. Returns {success, count, files: [str]}.
get_file_versionreadGet the version info of a file (major, minor, release, build). Returns {success, major, minor, release, build, version_string}.
get_foreground_processreadGet the PID and window handle of the process currently in the foreground.
get_global_variablereadRead a global variable from CE
get_instruction_inforeadGet detailed info about a single instruction (size, bytes, opcode).
get_memory_protectionreadQuery the protection flags of a memory page in the target process.
get_memory_recordreadRetrieve a single memory record by ID or description.
get_memory_record_valuereadRead the current value of a memory record as a string.
get_memory_regionsreadGet list of valid memory regions nearby common bases.
get_module_sizereadGet the in-memory size of a loaded module.
get_mouse_posreadGet the current mouse cursor position. Returns x and y screen coordinates.
get_opened_process_handlereadGet the OS handle of the process currently attached to Cheat Engine as a hex string.
get_opened_process_idreadGet the PID of the process currently attached to Cheat Engine.
get_physical_addressreadTranslate Virtual Address to Physical Address (requires DBVM).
get_physical_address_cr3readTranslate a virtual address to its physical address using an explicit CR3.
get_pixelreadGet the colour of a screen pixel at (x, y). Returns r, g, b channels and the raw COLORREF integer.
get_process_inforeadGet current process ID, name, modules count and architecture.
get_process_listreadGet the list of running processes on the system.
get_processid_from_namereadLook up the PID of a process by its executable name.
get_rtti_classnamewriteTry to identify the class name of an object at address using Run-Time Type Information.
get_scan_resultsreadGet results from the last
get_screen_inforeadGet the primary screen dimensions and DPI. Returns width, height (pixels) and dpi.
get_structure_by_namereadFind a CE structure by name in the global structure list.
get_structure_elementsreadGet all elements of a CE structure.
get_symbol_addressreadResolve a symbol name (e.g.,
get_symbol_inforeadRetrieve detailed information about a known symbol.
get_temp_folderreadReturn the path to the system temp folder. Returns {success, path: str}.
get_thread_listreadGet list of threads in the attached process.
get_window_captionreadReturn the caption (title bar text) of a window given its handle (hex string).
get_window_class_namereadReturn the window class name of a window given its handle (hex string).
get_window_process_idreadReturn the process ID that owns a window given its handle (hex string).
in_main_threadreadCheck whether the current code is running in CE
inject_dllreadInject a DLL into the currently attached target process.
inject_dotnet_dllwriteInject a .NET DLL and invoke a static method in the target process.
input_queryreadShow a modal text-input dialog in Cheat Engine and return what the user typed.
is_key_pressedreadCheck whether a key is currently held down.
key_downreadSimulate pressing a key down (does NOT release it automatically).
key_upreadRelease a key that was pressed with key_down.
list_breakpointsreadList all active breakpoints.
load_new_symbolswriteScan for newly loaded modules and import their symbols.
load_tablereadLoad a Cheat Engine table (.ct) file into the current session.
map_memoryreadMap a kernel/physical address range into the CE usermode context via DBK.
map_view_of_sectionreadMap a section into the target process.
md5_filereadCalculate the MD5 hash of a file on the CE host. Filename must not contain
md5_memoryreadCalculate the MD5 hash of a memory region. Returns the hash as a hex string.
next_scanreadNext scan to filter results from the last
open_processreadOpen a process by PID or name and attach Cheat Engine to it.
output_debug_stringwritePost a message to the Windows debugger via OutputDebugString (readable with tools like DebugView).
pause_processreadPause (freeze) the currently opened process using CE
persistent_scan_destroydestructiveDestroy a named persistent scan session and free its memory.
persistent_scan_first_scanwriteRun the first scan on a named persistent scan session.
persistent_scan_get_resultsreadGet paginated results from a named persistent scan session.
persistent_scan_next_scanreadNarrow down results with a next scan on a named persistent scan session.
pingreadCheck connectivity and get version info.
play_soundreadPlay a WAV sound file by filename. Path must not contain
pointer_rescanreadRe-scan an existing pointer scan for a new value. Requires a prior pointer scan in CE.
poll_dbvm_watchreadPoll DBVM watch logs WITHOUT stopping. Returns register state at each execution hit.
queue_to_main_threadwriteQueue Lua code to run on CE
read_clipboardreadRead text from the system clipboard. Returns {success, text: str}.
read_integerreadRead a number from memory. Types: byte, word, dword, qword, float, double.
read_memoryreadRead raw bytes from memory.
read_pointerreadRead a pointer chain. Returns the final address and value.
read_pointer_chainreadFollow a multi-level pointer chain and return analysis of every step.
read_process_memory_cr3readRead virtual memory using an explicit CR3 page-table base via DBK/DBVM.
read_region_from_filereadRead a file into memory at the given destination address. Filename must be an absolute path and must not contain
read_stringreadRead a string from memory.
register_symbolreadRegister a user-defined symbol with a given name and address.
reinitialize_symbol_handlerdestructivePerform a full reset and reload of the Cheat Engine symbol handler.
remove_breakpointdestructiveRemove a breakpoint by its ID.
run_commandwriteExecute a shell command in the host OS. SECURITY: Arbitrary code execution.
save_tablewriteSave the current cheat table to a file.
scan_allreadUnified Memory Scanner (first scan).
search_stringreadQuickly search for a text string in memory.
send_window_messagewriteSend a Windows message (WM_*) to a window.
set_breakpointwriteSet a hardware execution breakpoint. Non-breaking/Logging only.
set_data_breakpointwriteSet a hardware data breakpoint (watchpoint). Types:
set_global_variablewriteWrite a global variable in CE
set_memory_protectionwriteChange the protection flags of a memory region in the target process.
set_memory_record_valuewriteWrite a value to a memory record (and therefore to the target process memory).
set_mouse_poswriteMove the mouse cursor to screen position (x, y).
set_progress_statewriteSet the Cheat Engine taskbar progress state. Valid states: none, normal, paused, error, indeterminate.
set_progress_valuewriteSet the Cheat Engine taskbar progress bar position. Provide current value and maximum value.
shell_executewriteInvoke Windows ShellExecute. SECURITY: Arbitrary code execution.
show_messagereadShow a modal message dialog in Cheat Engine.
show_selection_listreadShow a modal list-selection dialog in Cheat Engine.
speak_textdestructiveSpeak text via Windows SAPI text-to-speech. Set english_only=True to force the English voice.
start_dbvm_watchwriteStart invisible DBVM hypervisor watch. Modes:
stop_dbvm_watchwriteStop DBVM watch and return results.
unmap_memoryreadRelease a memory mapping created by map_memory().
unpause_processreadResume (unfreeze) the currently opened process using CE
unregister_symboldestructiveRemove a previously registered user-defined symbol.
validate_pointer_chainsreadResolve a list of candidate pointer chains and report which currently land on `target`. Each chain is {
write_clipboardwriteWrite text to the system clipboard. Returns {success}.
write_integerwriteWrite a number to memory. Types: byte, word, dword, qword, float, double.
write_memorywriteWrite raw bytes to memory.
write_process_memory_cr3writeWrite to virtual memory using an explicit CR3 page-table base via DBK/DBVM.
write_region_to_filewriteWrite a memory region to a file. Filename must be an absolute path and must not contain
write_stringwriteWrite a string to memory (ASCII or Wide/UTF-16).
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_all_breakpoints, debug_remove_breakpoint_for_thread, delete_all_registered_symbols, delete_file, delete_memory_record, delete_structure, get_breakpoint_hits, persistent_scan_destroy, reinitializ
Why it matters. 12 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
MCP_Server/requirements.txt
mcp, pywin32
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 89bd885485eefull audit observations/trust-audit/mcp-server/miscusi-peek__cheat-engine-bridge.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2589bd885485eeSAFEB89first audit
05

Questions

What is the Cheat Engine Bridge MCP server?

Connect your favorite AI agents directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using natural language.

What tools does Cheat Engine Bridge expose?

175 in total: 113 read-only, 50 that write, and 12 that can delete or overwrite (clear_all_breakpoints, debug_remove_breakpoint_for_thread, delete_all_registered_symbols, delete_file, delete_memory_record). Every one is listed on this page with its risk.

Is Cheat Engine Bridge safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Cheat Engine Bridge need?

No credential environment variables were found in its source, so it appears to need none.

How does Cheat Engine Bridge run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (89bd885485ee), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement