gearcoleco-debugging — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited gearcoleco-debugging (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Debug ColecoVision and Super Game Module games using the Gearcoleco emulator as an MCP server. Control execution (pause, step, breakpoints), inspect the Z80 CPU and hardware (TMS9918A VDP, SN76489 PSG, AY-3-8910 SGM PSG), read/write memory across multiple areas (BIOS, RAM, SGM RAM, VRAM, ROM banks), disassemble code, trace instructions, rewind to earlier states, view sprites, and capture screenshots - all through MCP tool calls. Hardware documentation is available in the references/ directory.
IMPORTANT - Check before installing: Before attempting any installation or configuration, you MUST first verify if the Gearcoleco MCP server is already connected in your current session. Call debug_get_status - if it returns a valid response, the server is active and ready.
Only if the tool is not available or the call fails, you need to help install and configure the Gearcoleco MCP server:
Run the bundled install script (macOS/Linux):
bash scripts/install.shThis installs Gearcoleco via Homebrew on macOS or downloads the latest release on Linux. It prints the binary path on completion. You can also set INSTALL_DIR to control where the binary goes (default: ~/.local/bin).
Alternatively, download from GitHub Releases or install with brew install --cask drhelius/geardome/gearcoleco on macOS.
Configure your AI client to run Gearcoleco as an MCP server via STDIO transport. Example for Claude Desktop (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"gearcoleco": {
"command": "/path/to/gearcoleco",
"args": ["--mcp-stdio"]
}
}
}Replace /path/to/gearcoleco with the actual binary path from the install script. Add --headless before --mcp-stdio on headless machines.
ColecoVision and Super Game Module hardware documentation is available in the references/ directory. Load them into your context when investigating specific hardware or BIOS behavior.
| Reference | File | Quality | Load when... |
|---|---|---|---|
| ColecoVision Technical Notes | references/colecovision.md | PRIMARY - system quick reference | Cartridge headers, title-screen behavior, controller modes, keypad codes, memory map, I/O map, basic SN76489 and VDP context |
| TMS9918A VDP (Sean Young) | references/tms9918a.md | PRIMARY - detailed VDP reference | VDP registers, status flags, VRAM access, display modes, interrupts, sprites, fifth-sprite flag, collisions, undocumented modes |
| SN76489A PSG | references/sn76489.md | PRIMARY - ColecoVision PSG quick reference | SN76489 latch/data writes, tone periods, attenuation, noise control, frequency formula, PSG debugging |
| Super Game Module Notes | references/super_game_module.md | PRIMARY - SGM memory reference | SGM RAM mapping, port $53, port $7F, ADAM compatibility, SGM initialization, SGM AY summary |
load_media -> get_media_info -> get_z80_status -> get_screenshotStart every session by loading the ROM, confirming it loaded correctly (file path, type, size, mapper), then checking Z80 CPU state and taking a screenshot to understand the current game state. If a .sym file exists alongside the ROM, symbols are loaded automatically. Gearcoleco accepts .sym entries using BANK:ADDRESS LABEL format.
Load additional symbols with load_symbols or add individual labels with add_symbol.
Always call debug_pause before inspecting state. While paused:
get_z80_status - registers AF, BC, DE, HL, AF', BC', DE', HL', IX, IY, SP, PC, WZ, I, R, flags (S, Z, H, P/V, N, C), interrupt state, halt status, interrupt mode (0/1/2)get_disassembly with a start/end address range. Disassembled records exist for code that has executed during emulationget_call_stack - current subroutine hierarchyread_memory with a memory editor area ID and offset. Use list_memory_areas first to see available areas and physical offsetslist_sprites - all 32 TMS9918A sprites with position, size, pattern indexUse breakpoints to stop execution at points of interest:
| Breakpoint Type | Tool | Use Case |
|---|---|---|
| Execution | set_breakpoint (execute: true) | Stop when PC reaches address |
| Read | set_breakpoint (read: true) | Stop when memory address is read |
| Write | set_breakpoint (write: true) | Stop when memory address is written |
| Range | set_breakpoint_range | Cover an address range (exec/read/write) |
| IRQ | toggle_irq_breakpoints | Break on RESET, NMI, or INT interrupts |
Breakpoints support 3 memory areas: rom_ram, vram, vdp_reg. Use rom_ram for Z80 address space, vram for VDP memory access, and vdp_reg for VDP register writes.
Important: Read/write breakpoints stop with PC at the instruction after the memory access.
Manage breakpoints with list_breakpoints and remove_breakpoint.
After hitting a breakpoint or pausing:
| Action | Tool | Behavior |
|---|---|---|
| Step Into | debug_step_into | Execute one Z80 instruction, enter subroutines |
| Step Over | debug_step_over | Execute one instruction, skip CALL subroutines |
| Step Out | debug_step_out | Run until RET returns from current subroutine |
| Step Frame | debug_step_frame | Execute until next frame / VBlank |
| Run To | debug_run_to_cursor | Continue until PC reaches target address |
| Continue | debug_continue | Resume normal execution |
After each step, call get_z80_status and get_disassembly to see where you are.
The trace logger records Z80 instructions interleaved with hardware events (VDP writes/status, PSG, AY-3-8910, I/O ports, SGM mapping events).
set_trace_log with enabled: true to start recording (optionally use flags; 0xFF enables all trace types)set_trace_log with enabled: false to stop (entries are preserved)get_trace_log to read recorded entriesTrace flags: bit 0 = CPU, 1 = CPU IRQ, 2 = VDP write, 3 = VDP status, 4 = PSG, 5 = AY-3-8910, 6 = I/O port, 7 = SGM.
Tracing is essential for understanding timing-sensitive code, interrupt handlers, VDP access sequences, sound register writes, controller reads, and SGM RAM enable behavior.
get_rewind_status reports whether rewind is enabled, how many snapshots are available, total capacity, and memory usage.rewind_seek jumps to a specific buffered snapshot. The emulator must be paused first.Typical flow:
debug_pauseget_rewind_statusrewind_seek to an earlier snapshotget_z80_status and get_disassembly to inspect the restored pointdebug_continue or keep stepping from thereget_vdp_registers - VDP registers with hex values and descriptionsget_vdp_status - status flags, current mode, render line, display statelist_sprites - all 32 sprites with position, size, pattern indexget_sprite_image - get a specific sprite as base64 PNGget_psg_status - all 4 channels (3 tone + 1 noise): volume, period, frequencyget_ay8910_status - 3 AY channels, mixer, noise, envelope, registers, mute state$50 register select, $51 data write, $52 data readget_screenshot - current rendered frame as PNGUse screenshots after stepping or continuing to see the visual impact of changes.
Use list_memory_areas to discover all available physical areas. Memory tools use the returned area IDs and 0-based offsets, while breakpoints use logical areas.
| Logical Area | Description |
|---|---|
rom_ram | Full Z80 64K address space (BIOS, RAM, SGM RAM windows, cartridge ROM) |
vram | Video RAM - pattern tables, name table, color table, sprite attribute table |
vdp_reg | VDP register file |
Additional read_memory/write_memory areas include physical BIOS, WRAM, SGM RAM, VRAM, ROM banks, and other mapped spaces - use list_memory_areas for the complete list.
toggle_irq_breakpoints to enable breaking on interruptsdebug_continue to run until the VDP NMI firesget_z80_status + get_disassembly to see the handler codeget_call_stack to see the call hierarchyadd_symbol to label the handler address and any subroutines it callsNote: The Z80 NMI vector is fixed at $0066. ColecoVision games normally receive VBlank through the TMS9918A NMI path.
debug_pause -> get_vdp_registers - check mode and table base addressesget_vdp_status - verify status flags, render state, and interrupt stateread_memory (VRAM area from list_memory_areas) - inspect pattern, name, color, and sprite tableslist_sprites - verify sprite positions, patterns, and orderingvram) on display data addresses to catch corruption sourceset_breakpoint at the subroutine entry pointdebug_continue -> when hit, get_z80_statusdebug_step_into / debug_step_overadd_symbol for the routine and any called subroutinesadd_disassembler_bookmark to mark interesting locationslist_memory_areas to identify WRAM or SGM RAM area IDsadd_memory_watch on the variable's physical offset - watches are visible in the emulator GUIset_breakpoint (write: true) on the logical address if the variable is in the Z80 address spaceget_disassembly reveals what code is modifying itget_call_stack shows the call chain leading to the writetoggle_irq_breakpoints to break on VBlank / NMIget_vdp_status to check flags and current render stateget_trace_log to see interleaved Z80 + VDP eventsget_psg_status - check all 4 SN76489 channels (tone frequencies, volumes, noise mode)get_ay8910_status - check SGM AY-3-8910 state (registers, mixer, envelope, channels)psg events to catch SN76489 writesay8910 and io_port events to catch SGM writes to $50/$51 and reads from $52sgm and io_port events with set_trace_log$53 for upper RAM enable and $7F for lower BIOS/RAM mappinglist_memory_areas and read_memory to inspect SGM RAM physical areasadd_symbol liberally to label addresses - makes disassembly readableadd_disassembler_bookmark for code locations and add_memory_bookmark for data regionsadd_memory_watch for variables you're tracking across stepssave_state / load_state to snapshot and restore emulator state at interesting pointsget_screenshot after significant changeswrite_z80_register to change register values live (AF, BC, DE, HL, IX, IY, SP, PC, etc.)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.