GhidraMCP
MCP Server for Ghidra
GhidraMCP is an MCP server that enables AI language models to perform autonomous reverse engineering and binary analysis through Ghidra. Developed by LaurieWired, it bridges Ghidra's powerful software reverse engineering suite with MCP-compatible AI clients, exposing decompilation, analysis, and code annotation tools. The implementation consists of both a Ghidra plugin and a Python MCP bridge server that communicate via HTTP. Developers can use it to let AI assistants autonomously analyze binaries, rename functions, and explore program structures without manual Ghidra interaction.
Key Features
Use Cases
- 01Letting AI assistants autonomously reverse engineer malware or suspicious binaries
- 02Automated code analysis and documentation generation for legacy compiled software
- 03AI-assisted vulnerability research and security auditing of binary executables
- 04Batch renaming and annotation of functions in large codebases using natural language instructions
- 05Educational reverse engineering sessions with AI explaining decompiled code structures
- 06Accelerating incident response workflows by having AI analyze suspicious executables
Related MCP Servers
View moremarkitdown
Python tool for converting files and office documents to Markdown.
firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥
prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
langflow
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
GhidraMCP — FAQ
What is GhidraMCP?+
GhidraMCP is an MCP server that connects the Ghidra reverse engineering framework to AI language models, allowing assistants to autonomously decompile and analyze compiled binaries. It consists of a Ghidra plugin and a Python bridge server that communicate via HTTP.
How do I install GhidraMCP?+
Download the latest release ZIP from the GitHub repository and install it as a Ghidra extension via File → Install Extensions. Then configure your MCP client (like Claude Desktop) to run the included bridge_mcp_ghidra.py Python script, pointing it to your Ghidra instance's HTTP endpoint (default localhost:8080).
Which AI clients work with GhidraMCP?+
GhidraMCP works with any MCP-compatible client. The documentation provides configuration examples for Claude Desktop (stdio mode), Cline (SSE mode), and 5ire, though theoretically any MCP client should function correctly.
What are the prerequisites for using GhidraMCP?+
You need Ghidra installed on your system, Python 3, and the MCP SDK for Python. No API keys are required since the server communicates locally with your Ghidra installation.
Is GhidraMCP free to use?+
Yes, GhidraMCP is open source and released under the Apache 2.0 license, making it free for both personal and commercial use.
Can I customize the ports GhidraMCP uses?+
Yes, both the Ghidra HTTP server port and the MCP server port are configurable. You can set the Ghidra port in Tool Options → GhidraMCP HTTP Server, and specify MCP ports via command-line arguments when running the bridge script.
How do I install GhidraMCP?+
Open the source repository on GitHub and follow its README. GhidraMCP is a mcp server — MCP Agents Market links you directly to the official repo.
Is GhidraMCP free?+
GhidraMCP is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.