</>MCP Agents Market
MCP Server

GhidraMCP

by LaurieWired9.9kJavaUpdated 2025-06-23

MCP Server for Ghidra

Claude DesktopCline5ire

GhidraMCP is an MCP server that enables AI language models to perform autonomous reverse engineering and binary analysis through Ghidra. Developed by LaurieWired, it bridges Ghidra's powerful software reverse engineering suite with MCP-compatible AI clients, exposing decompilation, analysis, and code annotation tools. The implementation consists of both a Ghidra plugin and a Python MCP bridge server that communicate via HTTP. Developers can use it to let AI assistants autonomously analyze binaries, rename functions, and explore program structures without manual Ghidra interaction.

Key Features

Exposes Ghidra decompilation and binary analysis capabilities through the Model Context Protocol
Automatic method and data renaming based on AI analysis
List and inspect methods, classes, imports, and exports from compiled binaries
Dual-component architecture with Ghidra plugin and Python MCP bridge server
HTTP-based communication between Ghidra and MCP clients with configurable ports
Support for both stdio and SSE transport modes for different client types
Compatible with multiple MCP clients including Claude Desktop, Cline, and 5ire
Apache 2.0 licensed with active development and release management

Use Cases

  • 01Letting AI assistants autonomously reverse engineer malware or suspicious binaries
  • 02Automated code analysis and documentation generation for legacy compiled software
  • 03AI-assisted vulnerability research and security auditing of binary executables
  • 04Batch renaming and annotation of functions in large codebases using natural language instructions
  • 05Educational reverse engineering sessions with AI explaining decompiled code structures
  • 06Accelerating incident response workflows by having AI analyze suspicious executables

Related MCP Servers

View more

GhidraMCP — FAQ

What is GhidraMCP?+

GhidraMCP is an MCP server that connects the Ghidra reverse engineering framework to AI language models, allowing assistants to autonomously decompile and analyze compiled binaries. It consists of a Ghidra plugin and a Python bridge server that communicate via HTTP.

How do I install GhidraMCP?+

Download the latest release ZIP from the GitHub repository and install it as a Ghidra extension via File → Install Extensions. Then configure your MCP client (like Claude Desktop) to run the included bridge_mcp_ghidra.py Python script, pointing it to your Ghidra instance's HTTP endpoint (default localhost:8080).

Which AI clients work with GhidraMCP?+

GhidraMCP works with any MCP-compatible client. The documentation provides configuration examples for Claude Desktop (stdio mode), Cline (SSE mode), and 5ire, though theoretically any MCP client should function correctly.

What are the prerequisites for using GhidraMCP?+

You need Ghidra installed on your system, Python 3, and the MCP SDK for Python. No API keys are required since the server communicates locally with your Ghidra installation.

Is GhidraMCP free to use?+

Yes, GhidraMCP is open source and released under the Apache 2.0 license, making it free for both personal and commercial use.

Can I customize the ports GhidraMCP uses?+

Yes, both the Ghidra HTTP server port and the MCP server port are configurable. You can set the Ghidra port in Tool Options → GhidraMCP HTTP Server, and specify MCP ports via command-line arguments when running the bridge script.

How do I install GhidraMCP?+

Open the source repository on GitHub and follow its README. GhidraMCP is a mcp server — MCP Agents Market links you directly to the official repo.

Is GhidraMCP free?+

GhidraMCP is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches