MCP server for Cheat Engine with a hot-reloadable CE plugin and a packaged Codex entrypoint
25 tools with complete schemas and descriptions, but significant gaps in parameter documentation and error guidance. Tool names follow verb_noun convention well (get_*, list_*, debug_*). Descriptions average ~80 chars, below the 194-char baseline for A+ tools. Most parameters lack detailed constraints, ranges, or format specifications. No error recovery guidance visible. Output schemas not documented. Composition is sound, tools are single-responsibility and chainable. Security: no credentials exposed as parameters (good). However, many parameters accept flexible types (integer|string for addresses) without validation hints.
Run a unique libhat-backed AOB scan against one module and return one matching address when the result set is unique.
Run a unique libhat-backed AOB scan and return one matching address when the result set is unique.
Continue from the current breakpoint using run, step_into, or step_over.
List effective active breakpoints, including CE MCP hardware watches that may not appear in Cheat Engine's raw breakpoint list.
Start Cheat Engine debugging on the attached process using the requested debugger interface.
Return Cheat Engine debugger state plus an effective breakpoint view that includes CE MCP watches and the raw CE breakpoint list.
Output schemas not documented. Tools return data but LLMs cannot infer response structure (fields, types, pagination). Breaks downstream tool chaining and forces agents to guess field names.
Parameter constraints missing. 'timeout_seconds' accepts any number with no min/max. 'scan_alignment' and 'scan_hint' lack enum definitions, LLMs may hallucinate invalid values like 'x32' or 'sse2'.
No error recovery guidance. Tools lack descriptions of failure modes, retryability, or next steps. E.g., 'aob_scan_unique' may timeout or find no matches, no guidance on what to do.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 69 | 2026-07-28+ | v2 |
Start a watch session equivalent to Cheat Engine's 'find out what accesses this address'.
Start an execution-breakpoint watch session on an address.
Return recorded hits from a CE MCP debugger watch session.
Stop one CE MCP debugger watch session and remove its breakpoint.
Stop all CE MCP debugger watch sessions and remove their breakpoints.
Start a watch session equivalent to Cheat Engine's 'find out what writes to this address'.
Fetch multiple ExportedFunctions fields by name in one call.
List ExportedFunctions fields that are currently non-null in the connected Cheat Engine build.
List raw pointer fields from the copied ExportedFunctions block.
List typed function-pointer fields from the copied ExportedFunctions block.
Search ExportedFunctions field names and type names by substring.
Resolve a CE expression or symbol to an address.
Safely resolve a CE expression or symbol to an address, returning nil on failure.
Convert an address back into a CE symbol-like name.
Return whether an address falls inside a loaded module according to CE.
Return whether an address falls inside a system module according to CE.
Register a named symbol in Cheat Engine.
Reinitialize Cheat Engine's symbol handler.
Unregister a named symbol from Cheat Engine.
Flexible parameter types without validation hints. 'address' accepts integer|string but no format guidance (hex vs decimal, 0x prefix required?). LLMs may pass '12345' when '0x12345' is needed.
Descriptions too brief. Average ~70 chars vs 194-char baseline. E.g., 'Return whether an address falls inside a loaded module' lacks context on when to use it vs similar tools (in_system_module).