MCP Cheat Engine Server — provides safe, structured read-only access to memory analysis and debugging functionality through the Model Context Protocol (MCP). For developers, security researchers, and game modders.
Python
66
3 commits
updated Jan 29, 2026
If you find this useful, please ⭐ star the repo — it helps others discover it!
The MCP Cheat Engine Server provides safe, structured access to memory analysis and debugging functionality through the Model Context Protocol (MCP). This tool is designed for:
This server operates in READ-ONLY mode for safety. It can read and analyze memory but cannot modify it. All operations are logged for security auditing.
pip install -r requirements.txtpython server/main.pylist_processes tool to see available programsattach_to_process with a process IDread_memory_region to examine memorydetach_from_process when done📖 For detailed Claude Desktop setup instructions, see MCP_SETUP.md
Quick configuration summary:
%APPDATA%\Claude\claude_desktop_config.json (Windows){
"mcpServers": {
"cheat-engine": {
"command": "python",
"args": ["path\\to\\server\\main.py", "--debug", "--read-only"],
"cwd": "path\\to\\cheat-engine-server-python"
}
}
}
# Clone or download the project
cd C:\your-desired-location
# Extract files if downloaded as ZIP
# Navigate to project directory
cd cheat-engine-server-python
# Verify Python version
python --version
# Install required packages
pip install -r requirements.txt
# Verify installation
python -c "import mcp, trio, psutil, capstone; print('All dependencies installed successfully!')"
# Test the server
python server/main.py --test
# You should see: "MCP Cheat Engine Server initialized successfully"
The server uses configuration files in the server/config/ directory:
settings.json (Auto-created on first run){
"security": {
"read_only_mode": true,
"require_whitelist": true,
"log_all_operations": true
},
"performance": {
"max_memory_read": 1048576,
"scan_timeout": 30,
"max_results": 1000
}
}
whitelist.json (Process Access Control){
"processes": [
{
"name": "notepad.exe",
"allowed": true,
"description": "Text editor for testing"
},
{
"name": "calculator.exe",
"allowed": true,
"description": "Calculator application"
}
]
}
| Setting | Description | Default | Recommendation |
|---|---|---|---|
read_only_mode | Prevents memory writing | true | Keep enabled |
require_whitelist | Only allow whitelisted processes | true | Enable for safety |
log_all_operations | Log every operation | true | Enable for auditing |
max_memory_read | Maximum bytes per read | 1MB | Adjust as needed |
# Find processes you can attach to
result = use_tool("list_processes")
What you'll see:
# Attach to a specific process
result = use_tool("attach_to_process", {
"process_id": 1234
})
Best practices:
# Read 64 bytes starting at address 0x140000000
result = use_tool("read_memory_region", {
"address": "0x140000000",
"size": 64,
"data_type": "bytes"
})
bytes - Raw byte datastring - ASCII/UTF-8 textint32 - 32-bit signed integeruint32 - 32-bit unsigned integerint64 - 64-bit signed integeruint64 - 64-bit unsigned integerfloat - 32-bit floating pointdouble - 64-bit floating point# Find all occurrences of a byte pattern
result = use_tool("scan_memory", {
"pattern": "48 8B 05 ?? ?? ?? ??", # ?? = wildcard
"start_address": "0x140000000",
"end_address": "0x141000000"
})
"41 42 43" - Find bytes 0x41, 0x42, 0x43"48 ?? 05 ?? ?? ?? ??" - Wildcards for unknown bytes"Hello World" - Search for ASCII text"00 00 00 01" - Find integer value 1# Disassemble 100 bytes of code
result = use_tool("disassemble_code", {
"address": "0x140001000",
"size": 100,
"architecture": "x64"
})
# Analyze memory for data structures
result = use_tool("analyze_structure", {
"address": "0x200000000",
"size": 256
})
# Resolve [[base + 0x10] + 0x20] + 0x30
result = use_tool("resolve_pointer_chain", {
"base_address": "0x140000000",
"offsets": [16, 32, 48] # 0x10, 0x20, 0x30 in decimal
})
The server cannot modify memory - it can only read and analyze. This prevents:
Only approved processes can be accessed:
{
"processes": [
{"name": "notepad.exe", "allowed": true},
{"name": "suspicious.exe", "allowed": false}
]
}
All operations are logged to logs/operations.log:
2025-07-30 10:30:15 - INFO - Process attached: notepad.exe (PID: 1234)
2025-07-30 10:30:20 - INFO - Memory read: 0x140000000, size: 64
2025-07-30 10:30:25 - INFO - Process detached: notepad.exe
Problem: Cannot attach to process Solutions:
Problem: Python dependencies missing Solution:
pip install --upgrade -r requirements.txt
Problem: Process ID doesn't exist Solutions:
list_processes to get current IDsProblem: Cannot read memory at address Solutions:
get_memory_regionsEnable detailed logging:
python server/main.py --debug
logs/ directoryserver/config/Import existing .CT files:
result = use_tool("import_cheat_table", {
"file_path": "C:/path/to/table.CT"
})
Analyze Cheat Engine Lua scripts:
result = use_tool("execute_lua_script", {
"script_content": "print('Hello from Lua')",
"safe_mode": true
})
Define specific regions for analysis:
# Get full memory map
regions = use_tool("get_memory_regions")
# Analyze specific region
for region in regions:
if region['protect'] == 'PAGE_EXECUTE_READ':
# Analyze executable memory
pass
# Complete analysis workflow
def analyze_process(process_name):
# 1. Find and attach to process
processes = use_tool("list_processes")
target_pid = find_process_by_name(processes, process_name)
# 2. Attach to process
use_tool("attach_to_process", {"process_id": target_pid})
# 3. Get memory layout
regions = use_tool("get_memory_regions")
# 4. Scan for patterns
for region in regions:
if region['readable']:
scan_results = use_tool("scan_memory", {
"pattern": "48 8B 05",
"start_address": region['base_address'],
"end_address": region['base_address'] + region['size']
})
# 5. Clean up
use_tool("detach_from_process")
| Type | Size | Range | Use Case |
|---|---|---|---|
int8 | 1 byte | -128 to 127 | Small signed numbers |
uint8 | 1 byte | 0 to 255 | Bytes, characters |
int16 | 2 bytes | -32,768 to 32,767 | Short integers |
uint16 | 2 bytes | 0 to 65,535 | Port numbers |
int32 | 4 bytes | ±2.1 billion | Standard integers |
uint32 | 4 bytes | 0 to 4.2 billion | Addresses (32-bit) |
int64 | 8 bytes | ±9.2 quintillion | Large numbers |
uint64 | 8 bytes | 0 to 18.4 quintillion | Addresses (64-bit) |
float | 4 bytes | ±3.4E±38 | Decimal numbers |
double | 8 bytes | ±1.7E±308 | High precision decimals |
Q: Is this tool safe to use? A: Yes, the server operates in read-only mode and cannot modify memory or harm your system.
Q: Can I use this on games? A: Yes, but respect the terms of service of online games. This tool is primarily for educational and debugging purposes.
Q: Do I need Cheat Engine installed? A: No, this is a standalone server that provides similar functionality through MCP.
Q: Why do I need Administrator privileges? A: Windows requires elevated privileges to read memory from other processes for security reasons.
Q: Can I run this on Mac or Linux? A: The server has limited support for Mac/Linux. Some Windows-specific features may not work.
Q: How much memory does the server use? A: Typically 50-100MB, depending on the size of processes being analyzed.
Q: What processes should I start with? A: Begin with simple programs like Notepad, Calculator, or your own test applications.
Q: How do I find the right memory addresses? A: Use memory scanning to find patterns, then analyze the results to identify relevant addresses.
Q: Can I save my analysis results? A: Yes, all tool results can be saved to files for later reference and analysis.
Q: The server won't start - what should I check? A: Verify Python version (3.9+), install dependencies, and run as Administrator.
Q: I can't attach to a process - why? A: Check the process whitelist, verify the process is running, and ensure you have Administrator privileges.
Q: Memory reads are failing - what's wrong?
A: The memory address may be invalid or protected. Use get_memory_regions to find readable areas.
This project is licensed under the MIT License. Built with:
For additional help:
Remember: This tool is for educational and legitimate debugging purposes. Always respect software licenses and terms of service.
591 followers · starred Feb 2026
41 followers · starred May 2026
MCP Cheat Engine Server — provides safe, structured read-only access to memory analysis and debugging functionality through the Model Context Protocol (MCP). For developers, security researchers, and game modders.
Python
66
3 commits
updated Jan 29, 2026
If you find this useful, please ⭐ star the repo — it helps others discover it!
The MCP Cheat Engine Server provides safe, structured access to memory analysis and debugging functionality through the Model Context Protocol (MCP). This tool is designed for:
This server operates in READ-ONLY mode for safety. It can read and analyze memory but cannot modify it. All operations are logged for security auditing.
pip install -r requirements.txtpython server/main.pylist_processes tool to see available programsattach_to_process with a process IDread_memory_region to examine memorydetach_from_process when done📖 For detailed Claude Desktop setup instructions, see MCP_SETUP.md
Quick configuration summary:
%APPDATA%\Claude\claude_desktop_config.json (Windows){
"mcpServers": {
"cheat-engine": {
"command": "python",
"args": ["path\\to\\server\\main.py", "--debug", "--read-only"],
"cwd": "path\\to\\cheat-engine-server-python"
}
}
}
# Clone or download the project
cd C:\your-desired-location
# Extract files if downloaded as ZIP
# Navigate to project directory
cd cheat-engine-server-python
# Verify Python version
python --version
# Install required packages
pip install -r requirements.txt
# Verify installation
python -c "import mcp, trio, psutil, capstone; print('All dependencies installed successfully!')"
# Test the server
python server/main.py --test
# You should see: "MCP Cheat Engine Server initialized successfully"
The server uses configuration files in the server/config/ directory:
settings.json (Auto-created on first run){
"security": {
"read_only_mode": true,
"require_whitelist": true,
"log_all_operations": true
},
"performance": {
"max_memory_read": 1048576,
"scan_timeout": 30,
"max_results": 1000
}
}
whitelist.json (Process Access Control){
"processes": [
{
"name": "notepad.exe",
"allowed": true,
"description": "Text editor for testing"
},
{
"name": "calculator.exe",
"allowed": true,
"description": "Calculator application"
}
]
}
| Setting | Description | Default | Recommendation |
|---|---|---|---|
read_only_mode | Prevents memory writing | true | Keep enabled |
require_whitelist | Only allow whitelisted processes | true | Enable for safety |
log_all_operations | Log every operation | true | Enable for auditing |
max_memory_read | Maximum bytes per read | 1MB | Adjust as needed |
# Find processes you can attach to
result = use_tool("list_processes")
What you'll see:
# Attach to a specific process
result = use_tool("attach_to_process", {
"process_id": 1234
})
Best practices:
# Read 64 bytes starting at address 0x140000000
result = use_tool("read_memory_region", {
"address": "0x140000000",
"size": 64,
"data_type": "bytes"
})
bytes - Raw byte datastring - ASCII/UTF-8 textint32 - 32-bit signed integeruint32 - 32-bit unsigned integerint64 - 64-bit signed integeruint64 - 64-bit unsigned integerfloat - 32-bit floating pointdouble - 64-bit floating point# Find all occurrences of a byte pattern
result = use_tool("scan_memory", {
"pattern": "48 8B 05 ?? ?? ?? ??", # ?? = wildcard
"start_address": "0x140000000",
"end_address": "0x141000000"
})
"41 42 43" - Find bytes 0x41, 0x42, 0x43"48 ?? 05 ?? ?? ?? ??" - Wildcards for unknown bytes"Hello World" - Search for ASCII text"00 00 00 01" - Find integer value 1# Disassemble 100 bytes of code
result = use_tool("disassemble_code", {
"address": "0x140001000",
"size": 100,
"architecture": "x64"
})
# Analyze memory for data structures
result = use_tool("analyze_structure", {
"address": "0x200000000",
"size": 256
})
# Resolve [[base + 0x10] + 0x20] + 0x30
result = use_tool("resolve_pointer_chain", {
"base_address": "0x140000000",
"offsets": [16, 32, 48] # 0x10, 0x20, 0x30 in decimal
})
The server cannot modify memory - it can only read and analyze. This prevents:
Only approved processes can be accessed:
{
"processes": [
{"name": "notepad.exe", "allowed": true},
{"name": "suspicious.exe", "allowed": false}
]
}
All operations are logged to logs/operations.log:
2025-07-30 10:30:15 - INFO - Process attached: notepad.exe (PID: 1234)
2025-07-30 10:30:20 - INFO - Memory read: 0x140000000, size: 64
2025-07-30 10:30:25 - INFO - Process detached: notepad.exe
Problem: Cannot attach to process Solutions:
Problem: Python dependencies missing Solution:
pip install --upgrade -r requirements.txt
Problem: Process ID doesn't exist Solutions:
list_processes to get current IDsProblem: Cannot read memory at address Solutions:
get_memory_regionsEnable detailed logging:
python server/main.py --debug
logs/ directoryserver/config/Import existing .CT files:
result = use_tool("import_cheat_table", {
"file_path": "C:/path/to/table.CT"
})
Analyze Cheat Engine Lua scripts:
result = use_tool("execute_lua_script", {
"script_content": "print('Hello from Lua')",
"safe_mode": true
})
Define specific regions for analysis:
# Get full memory map
regions = use_tool("get_memory_regions")
# Analyze specific region
for region in regions:
if region['protect'] == 'PAGE_EXECUTE_READ':
# Analyze executable memory
pass
# Complete analysis workflow
def analyze_process(process_name):
# 1. Find and attach to process
processes = use_tool("list_processes")
target_pid = find_process_by_name(processes, process_name)
# 2. Attach to process
use_tool("attach_to_process", {"process_id": target_pid})
# 3. Get memory layout
regions = use_tool("get_memory_regions")
# 4. Scan for patterns
for region in regions:
if region['readable']:
scan_results = use_tool("scan_memory", {
"pattern": "48 8B 05",
"start_address": region['base_address'],
"end_address": region['base_address'] + region['size']
})
# 5. Clean up
use_tool("detach_from_process")
| Type | Size | Range | Use Case |
|---|---|---|---|
int8 | 1 byte | -128 to 127 | Small signed numbers |
uint8 | 1 byte | 0 to 255 | Bytes, characters |
int16 | 2 bytes | -32,768 to 32,767 | Short integers |
uint16 | 2 bytes | 0 to 65,535 | Port numbers |
int32 | 4 bytes | ±2.1 billion | Standard integers |
uint32 | 4 bytes | 0 to 4.2 billion | Addresses (32-bit) |
int64 | 8 bytes | ±9.2 quintillion | Large numbers |
uint64 | 8 bytes | 0 to 18.4 quintillion | Addresses (64-bit) |
float | 4 bytes | ±3.4E±38 | Decimal numbers |
double | 8 bytes | ±1.7E±308 | High precision decimals |
Q: Is this tool safe to use? A: Yes, the server operates in read-only mode and cannot modify memory or harm your system.
Q: Can I use this on games? A: Yes, but respect the terms of service of online games. This tool is primarily for educational and debugging purposes.
Q: Do I need Cheat Engine installed? A: No, this is a standalone server that provides similar functionality through MCP.
Q: Why do I need Administrator privileges? A: Windows requires elevated privileges to read memory from other processes for security reasons.
Q: Can I run this on Mac or Linux? A: The server has limited support for Mac/Linux. Some Windows-specific features may not work.
Q: How much memory does the server use? A: Typically 50-100MB, depending on the size of processes being analyzed.
Q: What processes should I start with? A: Begin with simple programs like Notepad, Calculator, or your own test applications.
Q: How do I find the right memory addresses? A: Use memory scanning to find patterns, then analyze the results to identify relevant addresses.
Q: Can I save my analysis results? A: Yes, all tool results can be saved to files for later reference and analysis.
Q: The server won't start - what should I check? A: Verify Python version (3.9+), install dependencies, and run as Administrator.
Q: I can't attach to a process - why? A: Check the process whitelist, verify the process is running, and ensure you have Administrator privileges.
Q: Memory reads are failing - what's wrong?
A: The memory address may be invalid or protected. Use get_memory_regions to find readable areas.
This project is licensed under the MIT License. Built with:
For additional help:
Remember: This tool is for educational and legitimate debugging purposes. Always respect software licenses and terms of service.
591 followers · starred Feb 2026
41 followers · starred May 2026