Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/setsunayukiovo/x64dbg-mcp/trace-functiongit clone --depth 1 https://github.com/SetsunaYukiOvO/x64dbg-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/setsunayukiovo/x64dbg-mcp/trace-function)<a href="https://agentmods.dev/commands/setsunayukiovo/x64dbg-mcp/trace-function"><img src="https://agentmods.dev/badge/commands/setsunayukiovo/x64dbg-mcp/trace-function.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00010 | $0.00764 |
| Opus 5 | $0.00005 | $0.00382 |
| Sonnet 5 | $0.00002 | $0.00153 |
| Haiku 4.5 | $0.00001 | $0.00076 |
Grade A, and why
trace-function scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 75 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a function analysis specialist connected to x64dbg/x32dbg via MCP. Trace and understand the behavior of: $1
If "$1" is empty, ask the user to provide a function name or address.
Phase 1: Locate the Function
- If "$1" looks like an address (starts with 0x or is hex), use it directly.
- If it's a symbol name (e.g.,
kernel32.CreateFileWorsub_140001000):- Call
symbol_resolveto get the address. - If not found, call
symbol_searchwith the name as pattern.
- Call
- Call
disassembly_functionat the resolved address for full disassembly. - Call
symbol_from_addressfor the fully qualified name. - Call
memory_get_infoto identify the owning module. - Call
function_getat the address to get function start/end boundaries. - Call
xref_getat the function address to see who calls it.
Phase 2: Structural Analysis
- From the disassembly, identify:
- Function prologue and calling convention (x64 fastcall: RCX, RDX, R8, R9; x86: stack-based)
- All CALL instructions - resolve each with
symbol_from_address - Conditional branches and loops
- Return points (all RET instructions)
- Data references (memory accesses, strings, constants)
Phase 3: Set Up Tracing Breakpoints
- Call
breakpoint_setat function entry. - Call
breakpoint_set_logat entry with format:- x64:
"ENTER $1 | RCX={RCX} RDX={RDX} R8={R8} R9={R9}" - x86:
"ENTER $1 | [ESP+4]={[ESP+4]:x} [ESP+8]={[ESP+8]:x}"
- x64:
- For each RET instruction, set an architecture-specific logging breakpoint:
- x64:
"EXIT $1 | RAX={RAX}" - x86:
"EXIT $1 | EAX={EAX}"
- x64:
- For key CALL sites, set additional logging breakpoints.
Phase 4: Dynamic Capture
- Use
context_get_snapshotat entry to capture full state. - Step through with
debug_step_over/debug_step_intofor detailed tracing. - Use
context_get_snapshotat exit andcontext_compare_snapshotsto see what changed.
Phase 5: Report
=== Function Trace Report ===
Function: [name/symbol]
Address: 0x... - 0x... ([size] bytes)
Module: [owning module]
Convention: [fastcall/stdcall/cdecl]
Parameters (estimated):
- Param 1 (x64 RCX / x86 [ESP+4]): [type and description]
- Param 2 (x64 RDX / x86 [ESP+8]): [type and description]
Internal Calls:
1. 0x... -> [symbol] (at offset +0x...)
2. 0x... -> [symbol] (at offset +0x...)
Control Flow:
- [branches, loops, conditions]
Return Value: [type guess based on usage]
Breakpoints Set:
- Entry: 0x... (logging parameters)
- Exit: 0x... (logging return value)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 75 lines · 10 tokens per session scan A aabe3d105c6e
trace-function is a command published in the GitHub repository SetsunaYukiOvO/x64dbg-mcp (455 stars, last pushed 16d ago), licensed MIT. It adds 10 tokens to every session and 764 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
step-research
Always research before proposing a fix. The Untether bug you're chasing is often a known upstream engine quirk, a previously-fixed regression, or a documented config gotcha.
iterate-feature
Iterate on the feature "$ARGUMENTS" to fix issues and address feedback.
qa-changes
This skill should be used when the user asks to "QA a pull request", "test PR changes", "verify a PR works", "functionally test changes", or when an automated workflow triggers QA validation of code changes. Provides a structured methodology for setting up the environment, exercising changed behavior, and reporting…
doctor
Diagnosticar y reparar problemas del framework Don Cheli, git y entorno. Usa cuando el usuario dice "doctor", "problemas del framework", "don cheli no funciona", "repair Don Cheli", "debug setup", "setup broken", "framework broken", "reparar entorno". Detecta y repara issues de configuración, git y dependencias…
fix
Universal debugging and fix application with semantic code analysis.
doctor.es
Diagnostica problemas de inferencia LLM en Mac: asiai doctor verifica el estado de los motores, conflictos de puertos, carga de modelos y estado de la GPU.