No production release yet

Minecraft integrity,
clearly scoped.

A portable Windows scanner for consent-based reviews. It checks bounded Minecraft evidence with explicit consent—without claiming to inspect or clear an entire PC.

  • No installer
  • No administrator access
  • Consent before collection
3ab3ali scan
SCAN SCOPEMinecraft evidence only
BOUNDED
Mod inventoryResolved game roots
Complete
Game processesSame user · Windows
Coverage shown
Signed rulesLocally verified pack
Verified
Hard scope boundaryNo browser data, credentials, client screenshots, personal documents, or raw process memory.
01Portable Windows app
02Explicit consent gate
03Minimized scan report
04Manual review required
Bounded by design

What the scanner actually checks

The scanner gathers a narrow set of Minecraft integrity signals. Every collector reports its own limits instead of turning missing access, an ambiguous helper/decoy JVM, or an unresolved launch value into a misleading result.

01

Bounded-root mod JARs

Names, sizes, ZIP metadata, declared nested JARs, selected structure identities, and SHA-256 fingerprints beneath the selected JVM's exact root—or an explicitly incomplete fallback limited to validated launcher roots.

02

Active launch lineage

The selected version's bounded inheritsFrom chain, paired client JARs, conventional declared libraries, and exact validated JAR entries from the declared classpath.

03

One active Minecraft JVM

Exactly one same-user JVM must have a validated root, version, reviewed launch class, and declared classpath. V3.0 also recognizes narrowly corroborated renamed JVM hosts, preserves exact failure categories, and checks declared agents and Toolhelp-visible modules in separately reported stages.

04

Supplemental mod history

On Windows, at most 64 current-user Recycle Bin facts can report a normalized JAR basename and UTC move time. Coverage is supplemental and cannot make the required scan incomplete.

05

Bounded log context

A bounded tail of latest.log is parsed locally for normalized active version, loader, and mod references. Raw log lines are discarded.

About mod history: V3.0 may report no more than 64 normalized JAR basenames and UTC times that Windows recorded when items moved into only the current user's Recycle Bin. It cannot see Shift+Delete, an emptied bin, another user's items, or universal deletion history. A move does not prove that a mod was loaded or used, that cheating occurred, or that anyone attempted evasion. Separately, latest.log may reference an absent JAR, but its log-line time is not a verified deletion time. The scanner does not recover deleted files.

A visible process

Consent first. Evidence second.

The app creates a short-lived scanner API capability automatically—no ticket is required. This is not proof that the selected JVM is the named live game/server session. The player sees what will be inspected and uploaded, plus whether an external staff summary or optional NVIDIA NIM advisory review is enabled for that request, before anything runs.

  1. 1
    The app verifies a capability

    The server supplies a short-lived scanner capability, policy, and signed rule-pack identity—no ticket field is shown.

  2. 2
    Player reads and consents

    The app lists local collection, upload fields, and explicit exclusions.

  3. 3
    Bounded collectors run

    V3.0 selects and pins one exact JVM/root, including narrowly corroborated renamed Windows JVM hosts, then inspects its declared classpath, active version lineage, declared agents, and Toolhelp-visible modules within item, byte, and time budgets. Module snapshotting, hashing, and signature classification report their own timing and failure state. It also checks at most 64 current-user Recycle Bin mod-history facts as supplemental coverage. If pinning fails, only static mods, installed versions, and latest.log use the validated-root fallback and stay partial, while the exact path-free target failure is retained for staff.

  4. 4
    The backend validates the report

    For the authorized policy, it sends a minimized summary and a fixed 1200×1200 backend-rendered PNG report card to staff Discord. When accepted mod names are present, it attaches their complete bounded current inventory and any accepted Recycle Bin facts in a separate mod-history attachment. A separately disclosed NIM review receives only normalized bounded identifiers and remains advisory.

Results with context

A verdict is not a conviction.

Results describe configured rules and measured coverage. Staff must review them alongside legitimate mod use and scan limitations.

INDICATORS_FOUND

At least one configured rule matched an observed indicator.

Staff actionStaff review the finding and context. It is not automatic proof.

NO_INDICATORS_OBSERVED

No configured rule matched within fully completed expected coverage.

Staff actionThis does not mean the whole PC—or even every possible cheat—is clean.

INCOMPLETE / INCONCLUSIVE

Required visibility was partial, unavailable, or internally inconsistent.

Staff actionStaff treat the result as limited evidence, never as a failed scan by the player.

V3.0 reports declared device-check completeness separately from live game/server-session association. A completed self-service device review remains unbound and is never session-level clearance. No verdict should automatically ban, punish, or clear a player.

Privacy boundary

Useful evidence. Less exposure.

Designed to report

  • Opaque scan and client identifiers
  • Collector coverage, counts, bytes, and duration
  • Up to eight fixed path-free codes for incomplete checks
  • SHA-256 digests and redacted rule findings
  • Normalized current mod JAR names, version and loader identifiers
  • Normalized absent-now JAR references and log-reference times
  • Up to 64 current-user Recycle Bin mod-history basenames and UTC move times
  • A fixed 1200×1200 backend-rendered staff card, bounded current inventory, and separate mod-history attachment

× Explicitly excluded

  • Raw files, raw log lines, or raw process memory
  • Local paths or raw process command lines
  • Credentials, browser, or Discord data
  • Client, gameplay, or desktop screenshots and personal documents
  • Full window captions or free-form collector errors
  • Whole-disk scans or deleted-file recovery
  • Any claim to detect every possible cheat
Standalone staging channel

Download the portable EXE

Unsigned staging preview · not a production release.Windows may show a SmartScreen warning because this build has not been Authenticode-signed.

V3.0 explicitly opts in to a signed, legacy ungoverned prerelease pack. That pack contains only nonmatching informational plumbing rules and no production cheat intelligence. Its signature protects pack identity and integrity; it does not supply the private sample dossiers, independent approvals, expiry, and rollback evidence required for production rules. This staging-only exception does not weaken the production governance or release gates.

This is one portable Windows x64 file. It needs no installer, administrator access, Go, Java, or separate runtime. It contacts only the public MaghrebSMP scanner API. The client never receives Discord credentials or an NVIDIA API key. Backend-only Discord delivery is enabled for authorized scan policies and is disclosed before consent. Optional NIM review runs only when the request-specific consent notice says it is enabled.

For the private staff-report policy, the consent summary also states that the accepted minimized report is encrypted on the backend for no longer than 720 hours after scan completion. The staff Discord message receives a code-free report link and a separate high-entropy case key. The page reveals no result until that key is accepted; the key is sent only in an HTTPS POST body and is never put in the URL or browser storage.

The compact native Windows interface has one dominant Scan button, one short status, and a dark progress view. Full scope and result text stays available under Details without filling the default screen. While collectors run, the activity bar remains indeterminate because the remaining work is not knowable; it shows 100% only after the backend accepts the completed report.

  1. Download and verify the SHA-256 shown here.
  2. Start one Minecraft Java instance and keep it open, then run the EXE as your normal Windows account. Multiple plausible JVMs or no uniquely corroborated target make the runtime checks incomplete.
  3. Wait for the app to verify its short-lived scanner capability and signed staging rule pack.
  4. Open Details to read the exact disclosure, then click Scan. No ticket is required.

V3.0 attempts to pin exactly one active Minecraft JVM, canonical game directory, declared JAR classpath, active version lineage, declared -javaagent/-agentpath files, local-only -agentlib signals, and Toolhelp-visible modules. It can also recognize a renamed Windows JVM host only when the same PID owns an exact GLFW/LWJGL window and exposes an adjacent, loader-visible jvm.dll in a normal runtime layout. Its Windows launch parser recognizes Minecraft 26.2's documented Java 25 unsafe-memory option and safely handles long classpath arguments within the Windows command-line limit. An unreadable or truncated same-user Java candidate remains fail-closed; V3.0 preserves the exact path-free failure category for staff. If no target can be pinned, current mods, installed versions, and bounded latest.log evidence are still collected only from validated launcher roots or the exact folder you chose; those fallback checks remain incomplete. Local paths stay local and raw command lines are discarded.

V3.0 gives current official client archives more bounded structural headroom and sends the loaded-module collector directly to the already pinned JVM. Module review now runs as three explicit stages: Windows snapshot, SHA-256 fingerprinting, and Authenticode classification. A stable-identity cache is limited to the current scan, and staff can see the exact stage that timed out instead of one generic incomplete result.

V3.0 includes a signed, fail-closed format for version-specific Mojang, loader, library, native, launcher, overlay, and signer baselines. This staging download does not yet contain reviewed production baseline identities: the checked-in empty example trusts nothing, and unknown or mismatched files are never automatically labeled as cheating.

V3.0 can inspect a maximum of 64 Minecraft mod-history facts from only the current Windows user's Recycle Bin. Each accepted fact contains only a normalized JAR basename and the UTC time Windows recorded the item moving into the Recycle Bin. The scanner does not open, recover, hash, or upload the retained deleted-file content or its original path.

This history coverage is supplemental and non-verdict-gating: partial or unavailable Recycle Bin visibility does not make the required scan incomplete. It cannot observe Shift+Delete, an emptied Recycle Bin, another user's items, or universal deletion history. A basename, move time does not by itself prove that a mod was loaded or used, that anyone cheated, or that anyone attempted evasion. Recycle Bin metadata is current-user-modifiable historical context, not trusted proof.

Every accepted completed staff report includes a fixed 1200×1200 PNG summary card rendered by the backend from the already accepted structured fields. It is not a client, desktop, or gameplay screenshot. When any of the up to 512 normalized mod-JAR names accepted by the report are present, the backend also generates one bounded current-inventory text attachment containing every accepted name. Accepted Recycle Bin facts are placed in a separate bounded mod history attachment. A listed JAR is inventory context, not proof that it was loaded or used. The card summarizes governed detections, injection-check coverage, and the optional NIM advisory without allowing model output to change the deterministic verdict.

Download Windows EXE

Do not disable antivirus. V3.0 reports declared device-check completeness separately from live game/server-session association. A completed self-service scan remains unbound and is never session-level clearance. It does not inspect process memory, read raw target-JVM environment variables, recover deleted files, or claim to detect every cheat. Scoped current-user Recycle Bin metadata is not deleted-file recovery.

Channel
Standalone staging preview
Version
3.0.1
EXE size
6.73 MB
Download SHA-256
6f878f645839831b7f3f33d9ecdb77ae9f34f8b1218759d347b4dbe9b1ee9a35
EXE SHA-256
6f878f645839831b7f3f33d9ecdb77ae9f34f8b1218759d347b4dbe9b1ee9a35
Build state
Built from a committed, verified source tree
Release integrity

Release verification pending.

Every public executable must have canonical release metadata and an Ed25519 statement verified by a pre-approved key before its download button can activate.

Release validation in progress

Do not download development builds shared through messages or unofficial mirrors.

Platform
Windows 10/11 · 64-bit
Version
Pending signed release
SHA-256
Published when the production binary is signed
Signature
Verification material pending
Signing key
Approved production key pending
Signed at
Canonical UTC timestamp pending