Developer Tools · Security

GhidraMCP logo

GhidraMCP

13bm/GhidraMCP

A Ghidra extension that exposes 70 reverse-engineering tools to AI assistants through the Model Context Protocol (MCP). Open a binary in Ghidra, enable the plugin, and let Claude (or any MCP client) decompile functions, rename symbols, annotate code, search for vulnerabilities, and more.

Install

Client configuration

{
  "mcpServers": {
    "ghidra": {
      "command": "/path/to/mcp_bridge",
      "args": [
        "--host",
        "localhost",
        "--port",
        "8765"
      ]
    }
  }
}

Environment variables

GHIDRA_API_KEYGHIDRA_INSTALL_DIR
GitHub stars
39
Author
@13bm
Category
Developer Tools, Security
License
Apache-2.0
Updated
Oct 6, 2026

Features

  • 70 MCP tools spanning query, mutation, analysis, malware triage, IoT/embedded security, structure management, async decompilation, and multi-instance support

  • Easy setup -- plugin auto-starts the bridge; use MCP > Settings > Write to Claude Config to configure your MCP client

  • Cross-platform -- prebuilt bridge binaries for Linux x86_64, Windows x86_64, macOS x86_64 and macOS ARM64

  • Configurable -- port, localhost-only binding, API-key auth, auto-start, bridge enable/disable via GhidraMCP.properties

  • Multi-instance -- work with multiple Ghidra windows simultaneously using target_port to route tool calls

  • Async decompilation -- decompile large functions without blocking; poll for results later

  • Connection retry -- the bridge reconnects automatically if Ghidra restarts or the connection drops

  • Pagination -- large result sets (functions, strings, imports,...) support offset/limit for safe incremental retrieval

  • CI/CD -- automated builds, Go + Java tests, Ghidra integration tests, and auto-release when a new Ghidra version drops

Tools (40)

  • list_functions

    List all functions with entry points, sizes, return types

  • list_classes

    List all classes / namespaces

  • list_imports

    List imported symbols and external dependencies

  • list_exports

    List exported symbols

  • list_namespaces

    List all namespaces

  • list_data_items

    List defined data (globals, constants, arrays, structs)

  • list_strings

    List strings with optional substring filter

  • search_functions_by_name

    Search functions by name substring

  • get_function_by_address

    Detailed info for a function at an address

  • get_current_address

    Address currently selected in Ghidra

  • get_current_function

    Function at the current cursor position

  • decompile_function

    Decompile by name to C pseudocode

  • decompile_function_by_address

    Decompile by address to C pseudocode

  • disassemble_function

    Raw disassembly listing for a function

  • get_xrefs_to

    Cross-references TO an address

  • get_xrefs_from

    Cross-references FROM an address

  • get_function_xrefs

    All xrefs (callers + callees) for a function

  • get_program_info

    Program metadata (arch, compiler, format, etc.)

  • get_memory_map

    Memory layout with segment permissions

  • get_variables

    Parameters and locals for a function

  • rename_function

    Rename a function by name

  • rename_function_by_address

    Rename a function by address

  • rename_data

    Rename a data label

  • rename_variable

    Rename a local variable

  • set_decompiler_comment

    Set a decompiler-view comment

  • set_disassembly_comment

    Set a disassembly-view comment

  • set_function_prototype

    Set full function prototype

  • set_local_variable_type

    Change a variable's data type

  • set_bookmark

    Add a bookmark

  • remove_bookmark

    Remove a bookmark

  • set_equate

    Set a named constant on a scalar operand

  • create_structure

    Create a structure data type

  • create_enum

    Create an enum data type

  • apply_data_type

    Apply a data type at an address

  • set_namespace

    Set namespace or class for a function

  • set_calling_convention

    Set calling convention for a function

  • set_image_base

    Set the image base address

  • set_memory_permissions

    Modify memory block permissions

  • patch_bytes

    Patch raw bytes at an address

  • get_basic_blocks

    Get basic blocks for a function

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools