Try “Claude Code skills”, “MCP servers for Cursor” or “Codex” · Esc to close

Ghidra MCP 🔌 MCP server Open source

AI-driven reverse engineering: 250+ MCP tools over Ghidra's decompiler, analysis and debugger

Developer tool MCP servers · Open source ★ 4.1k · +105 this week · Apache-2.0 · updated 2026-10-02

6.5editor score
View on GitHub ↗
GitHub stars
4.1k
Stars this week
+105
Forks
164
Licence
Apache-2.0
Last push
2026-10-02
Maintainer
bethington
Installpython -m tools.setup ensure-prereqs --ghidra-path /path/to/ghidra_12.1.2_PUBLIC python -m tools.setup build python -m tools.setup deploy --ghidra-path /path/to/ghidra_12.1.2_PUBLIC uv run bridge-mcp-ghidra

Third-party MCP servers run with your permissions. Read the source before installing, and prefer pinned versions.

Works with

Built on the open MCP standard, so it works in every app that supports MCP.

About Ghidra MCP

What it does

Ghidra MCP Server bridges Ghidra's reverse-engineering toolkit with AI coding agents via the Model Context Protocol. It ships as a Ghidra GUI plugin plus a Python bridge/headless server, giving an agent structured, high-level access to binary analysis, decompilation and documentation workflows instead of requiring a human to script Ghidra's Java API directly.

Tools it gives your agent

The project exposes roughly 250 MCP tools (up to 253: 239 in GUI mode, 226 headless), grouped into functional areas: program/session management, listing and enumeration (functions, strings, imports/exports), function analysis (decompile, rename, retype, tag), cross-references and call graphs, data type/struct/enum/union editing, batch comment operations, control-flow and P-code dataflow analysis, malware/anti-analysis helpers (crypto detection, IOC extraction), cross-binary documentation transfer via SHA-256 hash matching, P-code emulation and API-hash brute-forcing, Ghidra Server/version-control operations, and a 22-tool debugger integration over TraceRmi (breakpoints, stepping, register/memory reads). Tools load lazily by group to keep the surface manageable for a given client.

Works with

Any MCP-compliant client over stdio or streamable-HTTP transport; the README specifically shows configuration for Claude Desktop and Cursor. It requires Ghidra 12.1.2, Java 21, and Python 3.10+ with uv.

How to install or connect

Build and deploy the Ghidra extension with the included setup tool, then run the Python bridge:

python -m tools.setup ensure-prereqs --ghidra-path /path/to/ghidra_12.1.2_PUBLIC
python -m tools.setup build
python -m tools.setup deploy --ghidra-path /path/to/ghidra_12.1.2_PUBLIC
uv run bridge-mcp-ghidra

In Ghidra: Tools > GhidraMCP > Start MCP Server (default http://127.0.0.1:8089), then point your MCP client at the bridge via stdio or HTTP as shown above.

Maintenance and safety

Actively maintained (v7.0.0, 1,190+ commits, 11 open PRs, ~30 open issues, 3.9k stars). The server binds to localhost with no auth by default; remote access requires an explicit bearer token, and script execution is off by default given the tool's reach into live debugging and binary manipulation.

Who should use it

Reverse engineers, malware analysts and security researchers who want an AI agent to drive Ghidra's decompiler, debugger and documentation workflow at scale, and who are comfortable running a local, version-matched Ghidra + Java + Python toolchain.

reverse-engineering ghidra binary-analysis decompiler malware-analysis security

Pros

  • Enormous, well-organized tool surface (~250 tools) spanning decompilation, data types, cross-refs, malware/IOC analysis, P-code emulation and live TraceRmi debu
  • Actively developed: v7.0.0, 1,190+ commits, 3.9k stars, 11 open PRs — not an abandoned side project
  • Batch operations and lazy per-group tool loading keep large tool counts usable by real MCP clients

Cons

  • Requires a local, version-matched Ghidra install (12.1.2) plus Java 21 and a Maven/uv build toolchain — a much heavier setup than a typical hosted MCP server
  • Given its reach into script execution and live debugging, remote/networked use needs explicit auth and script execution is disabled by default — worth understan

GitHub MCP Server 🔌 MCP serverFree

GitHub's official MCP server: issues, pull requests, code, Actions and security alerts

★ 33k · +132 this week

XcodeBuildMCP 🔌 MCP serverOpen source

Build, run, test and debug iOS and macOS apps from AI agents, maintained by Sentry

★ 6.5k · +27 this week

8.4 Visit ↗

MCP Reference Servers 🔌 MCP serverFree

The official reference MCP servers: fetch, filesystem, git, memory and more

★ 91k · +362 this week

Unity MCP 🔌 MCP serverOpen source

Lets AI agents drive the Unity Editor: scenes, C# scripts, assets, tests and builds

★ 15k · +173 this week

8.0 Visit ↗

Popular searches