A Model Context Protocol server for ProcessHacker that provides system introspection and memory manipulation tools via dynamically loaded DLL extensions.
This ProcessHacker MCP server has severe definition quality issues. Most tools have basic descriptions but lack proper parameter documentation, output schema definitions, and comprehensive error handling guidance. The server includes dangerous capabilities (arbitrary DLL compilation, memory writing, thread suspension) with minimal safeguards in the tool definitions themselves. While tool names follow reasonable verb_noun patterns (ph_list_*, ext_*), parameter descriptions are mostly missing or minimal, input schemas are present but incomplete, and output schemas are entirely undocumented. The auto_compiler tool is particularly concerning, its description warns it is 'DANGEROUS' but provides no guidance on how the LLM should handle confirmation, rollback, or error recovery. Most tools lack the 10 - 1024 character description baseline; several are under 50 chars. Parameter types are defined in JSON Schema but lack the human-readable constraints (range, format, enums) that LLMs need to avoid invalid input. No tools document their return structure, pagination behavior, or recovery paths for failure.
DANGEROUS: Core capability to allow the AI to compile raw C code into a self-loading Extension DLL dynamically. DO NOT RUN WITHOUT EXPLICIT USER CONSENT.
Writes arbitrary hex bytes to a specified memory address in a target process.
Scans process memory for a byte signature/pattern. Bypasses static offsets.
Suspends or resumes all threads in a process (Time Stopper).
Scans memory for exactly x64 MSVC RTTI locators and dumps Class Names (Reverse Engineering).
Reads memory using direct assembly syscalls, bypassing ntdll.dll user-mode hooks.
No output schemas documented for any tool. LLMs cannot plan downstream calls or extract results without knowing what fields are returned. All 13 tools lack return type documentation.
Parameter descriptions are missing or minimal across all tools. E.g., 'ph_suspend_resume_thread' has parameters 'tid' and 'action' with no descriptions of what values 'action' accepts ('suspend' vs 'resume'?). LLMs cannot infer valid parameter values.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
Lists all handles opened by a specific process ID.
Lists all loaded modules (DLLs) for a specific process ID.
Lists all running processes on the system.
Lists all threads for a specific process ID.
Lists memory regions (VirtualQueryEx) for a specific process ID.
Reads memory from a specific process given an address and size, returning a hex string.
Suspends or resumes a specific thread ID.
Dangerous tools lack confirmation or dry-run patterns. 'ext_auto_compiler' allows arbitrary C code compilation and loading; 'ext_memory_patcher' writes to process memory; 'ph_suspend_resume_thread' and 'ext_process_freezer' freeze processes. No tool provides a dry-run, confirmation step, or rollback capability documented in the schema.
Error handling guidance is absent. No tool description explains what error conditions might occur, when to retry, or how to recover. The code includes rate limiting logic (50 calls/min), but this constraint is not documented in any tool schema or description.
Parameter enums are not declared. 'ph_suspend_resume_thread' and 'ext_process_freezer' have 'action' parameters that accept a fixed set of strings (suspend/resume), but the schema does not declare an enum. LLMs may hallucinate invalid action values like 'pause', 'stop', or 'hold'.
'ext_auto_compiler' description is vague about what 'McpExtensionApi.h template' means and does not explain how the LLM should validate or test compiled code before execution. The tool is marked 'IRREVERSIBLE' but no recovery guidance is provided.
Pagination parameters (offset, limit) are present in some tools (ph_list_processes, ph_list_modules, ph_query_memory_regions, ph_list_handles) but no tool documents the total count, next_cursor, or how pagination works. LLMs cannot reliably iterate through large result sets.
Descriptions are under 20 characters for several tools, failing the baseline. E.g., 'ph_read_memory' (48 chars) is borderline; 'ph_suspend_resume_thread' (38 chars) does not explain the consequences. Descriptions should be 50 - 200 characters to provide sufficient context for LLM selection.
Read-only mode is implemented in code (--read-only flag) but not exposed as a tool capability or constraint in the schema. LLMs cannot discover or reason about whether destructive tools are available.
Tool names like 'ext_memory_patcher' and 'ext_pattern_scanner' use 'ext_' prefix that signals internal implementation detail, not user intent. Names should describe what the tool does in user-facing terms.