Ghidra MCP 🔌 MCP server Open source
AI-driven reverse engineering: 250+ MCP tools over Ghidra's decompiler, analysis and debugger
- GitHub stars
- 4.1k
- Stars this week
- +105
- Forks
- 164
- Licence
- Apache-2.0
- Last push
- 2026-10-02
- Maintainer
- bethington
python -m tools.setup ensure-prereqs --ghidra-path /path/to/ghidra_12.1.2_PUBLIC
python -m tools.setup build
python -m tools.setup deploy --ghidra-path /path/to/ghidra_12.1.2_PUBLIC
uv run bridge-mcp-ghidraThird-party MCP servers run with your permissions. Read the source before installing, and prefer pinned versions.
Works with
Built on the open MCP standard, so it works in every app that supports MCP.
About Ghidra MCP
What it does
Ghidra MCP Server bridges Ghidra's reverse-engineering toolkit with AI coding agents via the Model Context Protocol. It ships as a Ghidra GUI plugin plus a Python bridge/headless server, giving an agent structured, high-level access to binary analysis, decompilation and documentation workflows instead of requiring a human to script Ghidra's Java API directly.
Tools it gives your agent
The project exposes roughly 250 MCP tools (up to 253: 239 in GUI mode, 226 headless), grouped into functional areas: program/session management, listing and enumeration (functions, strings, imports/exports), function analysis (decompile, rename, retype, tag), cross-references and call graphs, data type/struct/enum/union editing, batch comment operations, control-flow and P-code dataflow analysis, malware/anti-analysis helpers (crypto detection, IOC extraction), cross-binary documentation transfer via SHA-256 hash matching, P-code emulation and API-hash brute-forcing, Ghidra Server/version-control operations, and a 22-tool debugger integration over TraceRmi (breakpoints, stepping, register/memory reads). Tools load lazily by group to keep the surface manageable for a given client.
Works with
Any MCP-compliant client over stdio or streamable-HTTP transport; the README specifically shows configuration for Claude Desktop and Cursor. It requires Ghidra 12.1.2, Java 21, and Python 3.10+ with uv.
How to install or connect
Build and deploy the Ghidra extension with the included setup tool, then run the Python bridge:
python -m tools.setup ensure-prereqs --ghidra-path /path/to/ghidra_12.1.2_PUBLIC
python -m tools.setup build
python -m tools.setup deploy --ghidra-path /path/to/ghidra_12.1.2_PUBLIC
uv run bridge-mcp-ghidra
In Ghidra: Tools > GhidraMCP > Start MCP Server (default http://127.0.0.1:8089), then point your MCP client at the bridge via stdio or HTTP as shown above.
Maintenance and safety
Actively maintained (v7.0.0, 1,190+ commits, 11 open PRs, ~30 open issues, 3.9k stars). The server binds to localhost with no auth by default; remote access requires an explicit bearer token, and script execution is off by default given the tool's reach into live debugging and binary manipulation.
Who should use it
Reverse engineers, malware analysts and security researchers who want an AI agent to drive Ghidra's decompiler, debugger and documentation workflow at scale, and who are comfortable running a local, version-matched Ghidra + Java + Python toolchain.
Pros
- Enormous, well-organized tool surface (~250 tools) spanning decompilation, data types, cross-refs, malware/IOC analysis, P-code emulation and live TraceRmi debu
- Actively developed: v7.0.0, 1,190+ commits, 3.9k stars, 11 open PRs — not an abandoned side project
- Batch operations and lazy per-group tool loading keep large tool counts usable by real MCP clients
Cons
- Requires a local, version-matched Ghidra install (12.1.2) plus Java 21 and a Maven/uv build toolchain — a much heavier setup than a typical hosted MCP server
- Given its reach into script execution and live debugging, remote/networked use needs explicit auth and script execution is disabled by default — worth understan
Similar MCP servers
All developer tool MCP servers →GitHub MCP Server 🔌 MCP serverFree
GitHub's official MCP server: issues, pull requests, code, Actions and security alerts
XcodeBuildMCP 🔌 MCP serverOpen source
Build, run, test and debug iOS and macOS apps from AI agents, maintained by Sentry
Sentry MCP 🔌 MCP serverFreemium
Sentry's MCP server: pull errors, stack traces and issues into your agent
🔥 Sentry for Startups: up to $5,000 in credits (12-month expiry) for companies founded in the last 2 years with under $5M raisedMCP Reference Servers 🔌 MCP serverFree
The official reference MCP servers: fetch, filesystem, git, memory and more
Unity MCP 🔌 MCP serverOpen source
Lets AI agents drive the Unity Editor: scenes, C# scripts, assets, tests and builds
n8n-MCP 🔌 MCP serverFreemium
n8n node docs, templates and validation so agents build workflows that actually run
🔥 Startup Plan: 50% off the self-hosted Business plan (fewer than 20 employees, under €5M raised)