cheatengine-mcp-automation

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to give an AI agent high-impact reverse-engineering and code-injection capabilities against local processes. Installation trust is fairly ordinary aside from unpinned PyPI deps, but the execution scope is broad: memory access, breakpoints, DBVM, DLL injection, shellcode execution, and an optional shell-enabling flag. I see no clear credential harvesting or third-party exfiltration path, so this is not confirmed malware; it is a high-risk offensive automation skill.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:33 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fcheatengine-mcp-automation%2F@f98dfbda601cc5245498bef9c83122c3e5334fa745bb51d3d17bc0e5a7ec4b0f
Security Audit — socket — cheatengine-mcp-automation