cheatengine-mcp-bridge: Driving Cheat Engine From an AI Agent Over MCP
Connect Cursor, Copilot & Claude AI directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using natural language.
At a glance
- What is it?
- The project exposes roughly 180 Cheat Engine operations as MCP tools so Cursor, Copilot or Claude can read memory, follow pointer chains and set hardware breakpoints in natural language. It is Windows-first, Lua plus Python, and the security model is entirely the operator's responsibility.
- Who is it for?
- Adopt it if you already work in Cheat Engine on Windows and want an agent to handle repetitive memory reads, pointer chain resolution and structure dissection while you keep the debugger open. Do not adopt it if your target is on Linux without a reachable Windows host, or if you need a stable, versioned tool surface: there are no tagged releases, so pin a commit.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 47 days ago.
- What is it written in?
- Mainly Lua, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What cheatengine-mcp-bridge Actually Automates
The README frames the problem in terms of scale: gigabytes of memory, millions of addresses, and a pointer or structure that takes days to locate by hand. The project's answer is to put an AI agent in front of Cheat Engine and let it drive the debugger through the Model Context Protocol. The stated use cases are trainers, mods, security audits, game bots and general reverse engineering.
The intended user is someone who already knows Cheat Engine and is tired of clicking through hex dumps. The README's own examples are the tell: "Find the packet decryptor hook", "Find the OPcode of character coordinates", "Generate unique AOB signature to make it update persistent". These are tasks a Cheat Engine user would recognize, not tasks you can hand to someone who has never opened the memory viewer. The agent is a faster pair of hands on an existing workflow, not a replacement for knowing what an AOB signature is.
One framing choice is worth flagging. The README leads with "Let multibillion $ AI datacenters analyze the program memory for you", and its before/after table compresses five days of manual work into ten minutes. Treat that table as marketing rhythm rather than a measurement. The repository contains no benchmark, and the timeline depends entirely on how well the agent's guesses land on a target you already understand.
Named Pipes, a Lua Worker Thread and JSON-RPC
The architecture is a two-hop bridge, and the README's flowchart spells it out. On one end is the AI agent (Claude, Cursor or Copilot) speaking MCP, which is JSON-RPC over stdio. In the middle is mcp_cheatengine.py, a Python MCP server. On the other end is Cheat Engine running ce_mcp_bridge.lua.
The Python server and Cheat Engine do not share a process. They communicate over a Windows named pipe, and the README gives the exact name: \\.\pipe\CE_MCP_Bridge_v99. The version suffix in the pipe name is a detail worth noticing, because it means a client built against one bridge version will not silently attach to a different one.
Inside Cheat Engine, the Lua script runs two threads. A worker thread handles the blocking I/O of the pipe, and the main thread owns the GUI and the Cheat Engine API. The two synchronize. That split matters: Cheat Engine's API is not thread-safe in general, so keeping memory access on the main thread while the worker waits on the pipe is the design that avoids the debugger locking up while an agent request is in flight.
The transport is not fixed to the pipe. The README documents a TCP relay, ce_tcp_relay.py, for the case where the MCP server runs outside the Windows environment hosting Cheat Engine. In that mode the Lua bridge still runs on Windows and still talks to the relay over the pipe; the relay exposes a TCP socket that the Python server connects to instead. The README explicitly names WSL as a use case that works without changing the Lua bridge.
Installing the Python Side and Loading the Lua Bridge
Two installs are involved, and they happen in different places. The Python MCP server needs Python 3.10 or newer according to the README badge. From the repository root, the documented command is:
pip install -r MCP_Server/requirements.txtThe README also gives the manual equivalent, which is useful if you want to see exactly what is being pulled in:
pip install mcp pywin32pywin32 is the dependency that ties this mode to Windows, because it is what opens the named pipe. The README states this plainly: native pipe mode is Windows only.
The second half happens inside Cheat Engine. Enable DBVM if you intend to use the DBVM tools, then open the Lua engine. The preferred path is File, then Execute Script, then open MCP_Server/ce_mcp_bridge.lua and execute it. If your Cheat Engine build does not show that menu item, the README offers a fallback: use Table, then Show Cheat Table Lua Script, paste the dofile line, and execute it.
dofile([[C:\path\to\cheatengine-mcp-bridge\MCP_Server\ce_mcp_bridge.lua]])Success looks like a specific line in the Cheat Engine output: [MCP v12.0.0] MCP Server Listening on: CE_MCP_Bridge_v99. If you do not see it, the bridge did not load and no amount of MCP client configuration will help.
Finally, register the server with your MCP client. The README's JSON example uses a servers block with a command and args pair:
{
"servers": {
"cheatengine": {
"command": "python",
"args": ["C:/path/to/MCP_Server/mcp_cheatengine.py"]
}
}
}For Codex, the README gives a TOML block in ~/.codex/config.toml, and notes that single quotes should be used around the Windows path so TOML treats backslashes literally. After restarting the IDE, the documented verification step is the ping tool, which should return a JSON object with success true, version 12.0.0 and the message CE MCP Bridge Active.
Running the MCP Server Off the Windows Box With the TCP Relay
The relay is the part of this project most likely to be misconfigured, so it deserves its own walkthrough. The sequence is: load the Lua bridge in Cheat Engine on Windows as usual, start the relay on Windows, then point the MCP server at the relay from wherever it runs.
The relay is started with an explicit host and port:
python C:\path\to\cheatengine-mcp-bridge\MCP_Server\ce_tcp_relay.py --host 127.0.0.1 --port 9876On the machine that will host the MCP server, install the TCP requirements instead of the default set, which avoids pywin32:
python3 -m pip install -r MCP_Server/requirements-tcp.txtThen run the server with the transport switched to TCP. The README shows both the environment-variable form and the MCP client config form. The environment-variable form is:
CE_MCP_TRANSPORT=tcp \
CE_MCP_HOST=127.0.0.1 \
CE_MCP_PORT=9876 \
python3 /path/to/cheatengine-mcp-bridge/MCP_Server/mcp_cheatengine.pyThe client config equivalent puts the same three keys in an env block alongside command and args. The README's warning about this mode is direct and should be read before you change the bind address: keep the relay bound to trusted interfaces only, because anyone who can reach it can control the Cheat Engine bridge. There is no authentication layer described. Binding the relay to 0.0.0.0 on a shared network hands debugger control to that network.
The Tool Surface and Where It Gets Thin
The README advertises roughly 180 MCP tools, grouped into memory, analysis and debugging. The memory group covers typed reads (read_memory, read_integer, read_string), pointer chain resolution such as [[base+0x10]+0x20], and scanning (scan_all, aob_scan). The analysis group covers disassemble, analyze_function, dissect_structure, get_rtti_classname for identifying C++ object types, and cross-reference lookups through find_references and find_call_references. The debugging group covers hardware breakpoints via set_breakpoint and set_data_breakpoint.
The README excerpt ends mid-sentence in the debugging table, so the full debugging surface is not visible here. That is a real gap for anyone evaluating the project: the headline claim is about debugging invisibly with hardware breakpoints and a Ring -1 hypervisor, but the tool list is truncated in the documentation. You will need to read MCP_Server/ directly to enumerate what is actually exposed.
A second limitation is structural. There are no tagged releases and no release notes. The README carries a version badge of 12.0.0 and the ping response reports the same number, but the repository's own release list is empty. Version 12.0.0 is a string in the source, not an artifact you can download and pin. If you are building against this, pin a commit hash rather than trusting a version number.
Third, the whole thing depends on Cheat Engine being open with the bridge loaded. There is no headless mode described. The agent cannot start Cheat Engine for you, and it cannot recover if you close the Lua engine mid-session.
Alternatives and the Difference That Matters
The closest alternative is using Cheat Engine's own Lua API directly, without an agent in the loop. Cheat Engine has a long-standing Lua scripting surface, and anything the bridge exposes is ultimately a call into it. Writing a script means you decide exactly what runs, you can version it, and you can run it headless through Cheat Engine's own automation. The difference is not capability, it is who chooses the next step. A script executes a plan you wrote; the bridge lets a model decide the next call based on what it just read. For a stable, repeatable trainer, the script is the better tool. For exploratory work where you do not yet know which address matters, the agent loop earns its keep.
On the MCP side, the alternative is any other debugger-backed MCP server, and the meaningful axis is transport. This project's default path is a Windows named pipe, which is why it needs pywin32 and why the README calls pipe mode Windows only. A server built on gdb or LLDB over a network protocol would not have that constraint, but it also would not have Cheat Engine's scanner, its RTTI inspection or its DBVM integration. If your target is a Windows game and your workflow already lives in Cheat Engine, the constraint is acceptable. If your target is a Linux binary, this project is the wrong shape entirely.
Maintenance, Licence and Upgrade Cost
The repository is not archived, and the last push was on 2026-08-14. The default branch is main. The licence is MIT, which is permissive and places few obligations on you beyond retaining the copyright notice; the repository contains a LICENSE file at the top level. This is not legal advice, and if you redistribute the bridge inside a commercial trainer you should read the licence text yourself rather than take a summary.
Upgrade cost is the part worth planning for. Because there are no tagged releases, there is no changelog to read before you move. The pipe name carries a version suffix, CE_MCP_Bridge_v99, and the ping response reports version 12.0.0, which suggests the protocol and the product version move independently. If you upgrade the Lua bridge without upgrading the Python server, or the reverse, the mismatch will surface as a failed connection rather than a clear error.
The dependency surface is small, which keeps upgrade cost low: mcp and pywin32 on the pipe path, mcp alone on the TCP path. Python 3.10 or newer is required per the README badge. The larger ongoing cost is behavioural, not technical. An agent that can set hardware breakpoints and read arbitrary memory is a powerful tool pointed at whatever process you attach it to, and the README's own warning about relay exposure is the only security guidance it offers.
Editorial conclusion
Adopt it if you already work in Cheat Engine on Windows and want an agent to handle repetitive memory reads, pointer chain resolution and structure dissection while you keep the debugger open. Do not adopt it if your target is on Linux without a reachable Windows host, or if you need a stable, versioned tool surface: there are no tagged releases, so pin a commit. Before wiring it into an agent, verify the ping tool returns the version string, confirm whether you need the named pipe or the TCP relay, and decide explicitly who can reach the relay port, because the README states that anyone who can reach it can control the Cheat Engine bridge.
Frequently asked questions
Does cheatengine-mcp-bridge work on Linux or macOS?
The default named pipe transport is Windows only because it uses pywin32. The TCP relay mode lets the MCP server run on another Windows process, a VM, a container, a Linux host or a remote machine, but Cheat Engine and the Lua bridge still run on Windows.
How do I verify that cheatengine-mcp-bridge is connected?
The README says to use the ping tool, which returns a JSON object with success true, version 12.0.0 and the message CE MCP Bridge Active. On the Cheat Engine side, loading the Lua bridge prints [MCP v12.0.0] MCP Server Listening on: CE_MCP_Bridge_v99.
Is Cheat Engine detected as a virus?
The repository does not discuss antivirus detection, and nothing in the README or the repository layout addresses it. The only security guidance present concerns the TCP relay, which the README says should be bound to trusted interfaces only because anyone who can reach it can control the Cheat Engine bridge.
Will Steam ban you for using Cheat Engine?
The README does not cover Steam, anti-cheat systems or account bans, so there is nothing to answer with. The project is framed around mods, trainers, security audits, game bots and reverse engineering without discussing platform policy.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/miscusi-peek-cheatengine-mcp-bridge)