vulhunt
Vulnerability detection framework by Binarly's REsearch team
VulHunt Community Edition is an MCP server that brings vulnerability hunting capabilities to AI assistants through the Model Context Protocol. Developed by Binarly's Research team, it enables security researchers to scan software binaries, UEFI firmware, and Binary Ninja databases for vulnerabilities directly from their AI workflows. The server exposes Binarly's Binary Analysis and Inspection System (BIAS) engine and rule-based vulnerability detection to AI agents, supporting multiple input formats including standalone binaries, BA2 archives, and BNDB files. It can run over HTTP with Server-Sent Events or stdio transport for flexible integration.
Key Features
Use Cases
- 01Enabling AI assistants to scan firmware images for known vulnerabilities during security audits
- 02Integrating binary vulnerability analysis into AI-powered code review workflows
- 03Automating vulnerability triage by allowing AI agents to analyze and classify findings
- 04Building AI-assisted security research tools that query and scan binary components
- 05Creating conversational interfaces for exploring vulnerability scan results from BTP
- 06Developing AI agents that can upload binaries to BTP and retrieve scan findings programmatically
Related MCP Servers
View moremarkitdown
Python tool for converting files and office documents to Markdown.
firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥
prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
langflow
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
vulhunt — FAQ
What is the VulHunt MCP server?+
VulHunt MCP server is a Model Context Protocol interface to Binarly's vulnerability hunting framework, allowing AI assistants to scan software binaries and firmware for security vulnerabilities. It exposes binary analysis and rule-based detection capabilities through the MCP protocol.
How do I install and run the VulHunt MCP server?+
Build VulHunt from source using Rust (cargo build --release), install prerequisite LuaJIT with patches, then start the MCP server with 'vulhunt-ce mcp -d <BIAS_DATA>' pointing to your auxiliary data directory. By default it runs an HTTP server on port 8080, or use --stdio for stdio transport.
What are the prerequisites for running VulHunt?+
You need Rust toolchain (cargo), LuaJIT 2.1 with VulHunt-specific patches applied, a BIAS data directory containing processor specifications, and VulHunt rule files. Optionally, Binary Ninja support requires building with the bndb feature flag.
Which AI clients work with the VulHunt MCP server?+
VulHunt supports any MCP-compatible AI assistant that can connect via HTTP/SSE transport (default) or stdio. The README mentions integration with AI assistants but does not specify particular client applications.
Is VulHunt MCP server free to use?+
Yes, VulHunt Community Edition is free and open-source software licensed under GNU GPL v3.0. Integration with the commercial Binarly Transparency Platform requires BTP credentials but is optional.
Can VulHunt scan Binary Ninja databases?+
Yes, VulHunt can scan BNDB files if you build it with the bndb feature enabled (cargo build --release --features=bndb) and use the --loader bndb option when scanning.
How do I install vulhunt?+
Open the source repository on GitHub and follow its README. vulhunt is a mcp server — MCP Agents Market links you directly to the official repo.
Is vulhunt free?+
vulhunt is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.