UnityRuntimeExplorer is a runtime inspector for Windows Unity games. It loads as a URKit mod and gives you a live view of the running process: scenes, GameObjects, components, managed members, references, and selected runtime values can be inspected without rebuilding the game.
The project is built on the URKit native C++ SDK. URKit provides the loader, Unity bindings, Mono/IL2CPP runtime access, main-thread dispatch, hooks, and ImGui integration. UnityRuntimeExplorer adds the Explorer UI and the inspection model on top of those services.
- Browse loaded scenes, hidden roots, and
DontDestroyOnLoadobjects. - Search GameObjects by name, tag, or instance ID.
- Inspect GameObjects, components, fields, properties, and methods.
- Read and edit supported values while the game is running.
- Copy and paste local transforms from the Inspector or the Hierarchy context menu.
- Duplicate, delete, enable, disable, and add components when the target game and runtime support the operation.
- Follow managed object references and open returned objects in the Object Inspector.
- Invoke methods with supported signatures.
- Trace managed methods, including callers, arguments, return values, ABI data, and captured value types.
- Focus the camera on an object and highlight it in the game.
- Use a dockable ImGui interface with DX11, DX12, and OpenGL render paths.
- Investigate the live game from MCP clients through a separate helper, including managed type discovery and explicitly approved method tracing.
The Inspector resolves type and member information from the runtime rather than using a game-specific type list. As a result, unsupported or unsafe operations are reported as unavailable instead of being guessed.
Two plugin binaries are produced:
URK_Il2cpp_UnityRuntimeExplorer.dll # IL2CPP games
URK_Mono_UnityRuntimeExplorer.dll # Mono games
Use only the binary that matches the target game. The two plugins share the Explorer UI and inspection code, but use different runtime backends.
Compatibility depends on the game's Unity version, generated metadata, runtime exports, and the URKit version used to load the mod. Mono support also depends on the embedding exports shipped by the game.
Download URKit from the URKit v0.3.0 release.
urk-sdk.exe is not required to use UnityRuntimeExplorer. It is only needed
for creating new URKit mod projects.
Download the Explorer DLL matching the target game's runtime:
URK_Il2cpp_UnityRuntimeExplorer.dll # IL2CPP games
URK_Mono_UnityRuntimeExplorer.dll # Mono games
Use only one of these DLLs. Do not use the IL2CPP plugin for a Mono game, or the Mono plugin for an IL2CPP game.
- From
version.dll,winhttp.dll, andwinmm.dll, choose only the proxy matching a DLL imported by the game executable. - Place that single proxy DLL next to the game executable. Do not place all three.
- Create a
Modsfolder beside the game executable. - Copy the Explorer DLL matching the game's runtime into the
Modsfolder. - Start the game normally.
- Press F7 to open or close the Explorer.
- Use
URKitInjector.dllfrom the URKit release. - No proxy DLL or
Modsfolder is required. - Inject
URKitInjector.dllinto the supported Windows x64 game. - Select the URKit configuration
.iniwhen prompted. - Select the Explorer DLL matching the game's runtime.
Do not inject either Explorer DLL directly. It must be loaded by URKit or
URKitInjector.dll as a URKit plugin.
If the Explorer does not appear, inspect URKit_logs.log beside the game
executable. The log usually identifies a wrong proxy name, an incompatible
backend, or a missing runtime export.
Builds are supported on Windows with CMake, Ninja, and Clang.
Requirements:
- Windows 10 or newer, x64
- CMake 3.28 or newer
- LLVM/Clang
- Ninja
- Network access for the first configure, which downloads ImGui and the other CMake dependencies
From the repository root:
cmake --preset clang-release
cmake --build --preset clang-release --parallelFor a debug build:
cmake --preset clang-debug
cmake --build --preset clang-debug --parallelRelease outputs are written to:
out/build/clang-release/URK_Il2cpp_UnityRuntimeExplorer.dll
out/build/clang-release/URK_Mono_UnityRuntimeExplorer.dll
out/build/clang-release/URK_UnityRuntimeExplorer_McpServer.exe
Run the test suite with:
ctest --test-dir out/build/clang-release --output-on-failureMCP support is optional. The MCP server is not embedded in the injected DLL. Instead, the architecture has three parts:
- The Explorer DLL runs inside Unity and owns all runtime access.
- A local Windows named-pipe bridge carries bounded requests to the Unity main thread.
URK_UnityRuntimeExplorer_McpServer.exeis a separate MCP server that speaks JSON-RPC over stdio to the MCP client.
The helper discovers running Explorer instances through:
%LOCALAPPDATA%\URK\UnityRuntimeExplorer\bridges
When one compatible game is running, it attaches automatically. If several are
running, pass --game-pid <pid> in the MCP client configuration.
The MCP helper publishes a complete discovery and control catalog. Explorer's Config tab is the authoritative permission boundary; clients cannot grant themselves capabilities through tool arguments or helper flags.
| Tool | Purpose |
|---|---|
runtime_status |
Runtime backend, scene, GC, revision, and diagnostic status. |
discover_runtime |
Search GameObjects and loaded managed types in one bounded discovery pass. |
hierarchy_search |
Bounded search by name, path, tag, instance ID, component, or dynamic behaviour type. |
find_game_objects |
Rank objects by name/path, components, dynamic behaviour types, scene, activity, and semantic role. |
get_selected_object |
Return the object selected in the Explorer. |
inspect_game_object |
Inspect identity, state, transform, and components. |
list_components |
List component types and opaque component references. |
read_member |
Read one explicitly requested field or readable property. |
inspect_managed_object |
Traverse fields on components and ordinary managed objects; property getters are opt-in. |
read_array |
Page through managed arrays while preserving reference elements as opaque tokens. |
decode_byte_array |
Copy and decode bounded byte arrays as MessagePack, JSON, text, compressed-payload detection, or hex. |
start_instance_scan |
Start a direct Unity-object query or a time-sliced reachable managed-object scan. |
get_instance_scan |
Read scan progress and page through discovered managed instances. |
search_types |
Search loaded Mono/IL2CPP types and assemblies. |
search_members |
Search fields, properties, and methods across bounded matching types. |
inspect_type |
Inspect fields, properties, methods, and signatures. |
list_method_traces |
List active and retained trace sessions. Consecutive identical calls are grouped. |
get_method_trace |
Read decoded calls, callers, arguments, and results. Grouped calls include their range and repeat count. |
build_call_graph |
Aggregate caller-to-target relationships from captured calls, including grouped repeats. |
get_activity_log |
Read recent Explorer activity and MCP audit events. |
build_reference_graph |
Build a bounded graph for the current selection. |
get_watch_history |
Return watched values and recent changes. |
export_diagnostic_bundle |
Export a diagnostic bundle to the fixed local directory. |
write_member |
Write fields or writable properties using bounded JSON values and opaque references. |
mutate_game_object |
Rename, retag, relayer, activate, transform, duplicate, or destroy a GameObject. |
manage_component |
Add, remove, or enable components. |
load_scene |
Load a build scene by index or name. |
Object, component, managed-object, scan, type, method, and trace references are opaque, bounded tokens. Managed pointers, native addresses, raw ABI values, and runtime handles are never sent to the MCP client.
The Config tab provides Enable full access and Read-only preset actions, plus independent controls for automatic discovery, property getters, writes, method tracing, managed invocation, and destructive Unity operations. Tool calls are schema-validated, bounded, rate-limited, and audited. Raw pointers, native-address execution, scripting, and assembly loading remain outside the MCP surface because they bypass Explorer's managed object/lifetime model.
A typical investigation is:
runtime_status
-> discover_runtime / find_game_objects / search_members
-> inspect_game_object / inspect_type / start_instance_scan
-> inspect_managed_object / read_array / decode_byte_array
-> start_method_trace
-> reproduce the behavior in game
-> get_method_trace / build_call_graph
-> stop_method_trace
Ready-to-copy MCP client configuration examples are included for:
Replace the placeholder executable path in the selected example with the full
path to URK_UnityRuntimeExplorer_McpServer.exe. If multiple compatible games
are running, add "--game-pid", "<pid>" to the example's args list.
Client-specific setup instructions, security properties, troubleshooting, and remote HTTPS/tunnel guidance are in docs/MCP.md.
Runtime inspection depends on the target game's metadata and runtime layout. The same type or method can have a different ABI or managed representation in another game. A member may also be unavailable because metadata was stripped, the object was destroyed, or the operation is not safe to perform generically.
Tracing, live edits, method calls, and component operations can affect game state or stability. Test with a restartable game session and keep backups of any data that matters.
- Confirm that URKit loaded the DLL matching the game's Mono/IL2CPP backend.
- Check
URKit_logs.logbeside the game executable. - Confirm that the proxy filename and
Modslayout match the URKit setup. - Press F7 after the game has reached its main menu or a loaded scene.
- Start the game with the Explorer DLL loaded before starting the MCP client.
- Confirm that the helper executable exists at the configured path.
- If more than one game is running, configure
--game-pid <pid>. - Check
%LOCALAPPDATA%\URK\UnityRuntimeExplorer\bridgesfor a discovery record and inspectURKit_logs.logfor runtime load errors.
Run find_game_objects or hierarchy_search again after a scene-generation
change. Object and component references survive ordinary hierarchy refreshes;
graph references remain tied to the hierarchy revision that produced them.
The member may be a property with side effects, stripped from metadata, opaque to the generic inspector, or attached to a destroyed object. The tool returns the failure instead of substituting a default value.
UnityRuntimeExplorer is under active development. Compatibility reports and small, reproducible examples are especially useful when opening an issue. Include the following information:
- game runtime: IL2CPP or Mono;
- Unity version, if known;
- the relevant section of
URKit_logs.log; - the type or method signature involved; and
- what the Explorer displayed and what you expected to see.
Copyright (c) 2026 Jadis0x. All rights reserved.

