by bromoket
Drive x64dbg with your AI. MCP server: 23 mega-tools / 153 endpoints for breakpoints, memory, disasm, tracing, anti-debug & PE dumping. Claude/Cursor/Windsurf/Cline. All local.
# Add to your Claude Code skills
git clone https://github.com/bromoket/x64dbg_mcpGuides for using mcp servers skills like x64dbg_mcp.
Last scanned: 8/14/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-08-14T05:37:51.405Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}x64dbg_mcp is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by bromoket. Drive x64dbg with your AI. MCP server: 23 mega-tools / 153 endpoints for breakpoints, memory, disasm, tracing, anti-debug & PE dumping. Claude/Cursor/Windsurf/Cline. All local. It has 100 GitHub stars.
Yes. x64dbg_mcp passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/bromoket/x64dbg_mcp" and add it to your Claude Code skills directory (see the Installation section above).
x64dbg_mcp is primarily written in C++. It is open-source under bromoket on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh x64dbg_mcp against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
Drive x64dbg with your AI. Talk to Claude, Cursor, Windsurf, Cline, or any MCP client in plain English and it sets breakpoints, reads memory, disassembles, traces, dumps PEs, and bypasses anti-debug — live, inside the debugger.
23 mega-tools over 153 REST endpoints, fully typed with Zod. A C++ plugin runs inside
x64dbg; a tiny TypeScript server bridges it to your client over stdio. Everything stays on
127.0.0.1 — nothing leaves your machine.
Latest — v2.3.0
- Hardened & crash-proof. A malformed HTTP request can no longer crash x64dbg; the plugin server drains connections cleanly on stop and ships an optional auth token (CORS is locked down).
- Real data from more tools.
imports/exports,symbolssearch/list,patcheslist, andstringsnow return actual parsed results instead of pointing you at a GUI view.- Live trace status. New
/api/trace/status(+tracing status) reports whether a trace is running, and the exception/trace tools now honor every parameter they accept.- Plus the v2.2.x fixes: x32dbg loads on current snapshots, and requests no longer time out on long operations.
"Set a breakpoint on CreateFileW and run the program"
"Disassemble the current function and explain what it does"
"Search for 48 8B ?? 48 85 C0 in the main module and disassemble the hits"
"Hide the debugger and bypass the anti-debug checks"
"Trace into the VM dispatcher and log every instruction to a file"
"Dump the main module to disk and fix the import table"
Real use: tracing VMProtect'd code, finding anti-cheat scanner threads, decoding XOR'd class names, mapping detection logic — all by asking, no manual scripting.
Download x64dbg_mcp.dp64 / .dp32 from the
latest release and drop them in:
x64dbg/x64/plugins/x64dbg_mcp.dp64 ← 64-bit targets
x64dbg/x32/plugins/x64dbg_mcp.dp32 ← 32-bit targets
…or build + install it yourself (auto-detects your x64dbg — no path editing):
.\build.ps1 -Install
Start x64dbg; the log shows [MCP] x64dbg MCP Server started on 127.0.0.1:27042.
No install — just point your client at npx. Claude Code:
{
"mcpServers": {
"x64dbg": {
"type": "stdio",
"command": "cmd",
"args": ["/c", "npx", "-y", "x64dbg-mcp-server"]
}
}
}
Claude Desktop / Cursor / Windsurf / Cline use the same block without the cmd /c wrapper:
{ "command": "npx", "args": ["-y", "x64dbg-mcp-server"] }.
Full per-client paths are in the reference.
Open a target in x64dbg and start talking to your assistant.
23 action-based tools spanning the whole debugger:
Every tool, action, and endpoint is documented in docs/REFERENCE.md.
The plugin binds to 127.0.0.1 only; the server talks pure stdio. All traffic stays on
localhost — no remote access, no telemetry, no data leaves your machine. For defense against
other local processes, set a token in the plugin's Settings and pass it via
X64DBG_MCP_TOKEN — every request must then carry it.
bromo — GitHub. Built with Claude Code. MIT.