Developer Tools · Security

ghidrassistmcp

jtang613/ghidrassistmcp

A powerful Ghidra extension that provides an MCP (Model Context Protocol) server, enabling AI assistants and other tools to interact with Ghidra's reverse engineering capabilities through a standardized API.

Install

Environment variables

GHIDRA_INSTALL_DIRGHIDRA_USER_EXTENSIONS_DIRGHIDRASSISTMCP_EXT
Author
@jtang613
Category
Developer Tools, Security
License
MIT
Updated
Oct 6, 2026

About ghidrassistmcp

GhidrAssistMCP bridges the gap between AI-powered analysis tools and Ghidra's comprehensive reverse engineering platform. By implementing the Model Context Protocol, this extension allows external AI assistants, automated analysis tools, and custom scripts to seamlessly interact with Ghidra's analysis capabilities.

Features

  • MCP Server Integration: Full Model Context Protocol server implementation using official SDK

  • Dual HTTP Transports: Supports SSE and Streamable HTTP transports for maximum client compatibility

  • 49 Built-in Tools: Comprehensive set of analysis tools with action-based consolidation for cleaner APIs

  • 6 MCP Resources: Static data resources for program info, functions, strings, imports, exports, and segments

  • 7 MCP Prompts: Pre-built analysis prompts for common reverse engineering tasks

  • Result Caching: Intelligent caching system to improve performance for repeated queries

  • Async Task Support: Long-running operations execute asynchronously with task management

  • Multi-Program Support: Work with multiple open programs simultaneously using program_name; use list_binaries Project Path values to disambiguate duplicate filenames

  • Multi-Window Support: Single MCP server shared across all CodeBrowser windows with intelligent focus tracking

  • Active Context Awareness: Automatic detection of which binary window is in focus, with context hints in all tool responses

Tools (40)

  • get_binary_info

    Get basic program information (name, architecture, compiler, etc.)

  • list_binaries

    List all open programs across all CodeBrowser windows, including Project Path values for unambiguous program_name targeting

  • open_program

    List/open project programs in CodeBrowser, with optional analysis prompt suppression and analysis-after-open task submission

  • close_program

    Close an open CodeBrowser program; changed programs require save=true or ignore_changes=true

  • import_file

    Import a host file into the current Ghidra project and optionally open it (disabled by default)

  • project_files

    List or delete files/folders in the active Ghidra project; deletion requires confirm=true

  • scripts

    List/read/create/delete/run Ghidra scripts (disabled by default)

  • assemble_code

    Assemble instruction text at an address and optionally patch it into program memory

  • patch_bytes

    Patch raw bytes in program memory at a given address

  • export_program

    Export the current program to disk (binary or original_file) (disabled by default)

  • analysis_options

    List/set/reset Auto Analysis options and save/apply/list/delete option presets for the current program

  • analyze_program

    Run Auto Analysis on the current program or all open programs; supports full re-analysis, pending-changes analysis, address ranges, and option overrides

  • analysis_control

    Query Auto Analysis status or request cancellation of queued analysis tasks

  • get_functions

    List functions with optional pattern filtering and pagination

  • search_functions_by_name

    Find functions by name pattern

  • get_function_statistics

    Comprehensive statistics for all functions

  • analyze_function

    Get detailed function information (signature, variables, etc.)

  • get_current_function

    Get function at current cursor position

  • get_function_stack_layout

    Get stack frame layout with variable offsets

  • get_basic_blocks

    Get basic block information for a function

  • create_function

    Create/define a function at an address, optionally clearing existing data/code first

  • disassemble_at

    Disassemble code at an address, optionally clearing existing data/code in the range first

  • get_imports

    List imported functions/symbols

  • get_exports

    List exported functions/symbols

  • get_strings

    List string references with optional filtering

  • search_strings

    Search strings by pattern

  • get_segments

    List memory segments

  • get_namespaces

    List namespaces in the program

  • get_relocations

    List relocation entries

  • get_entry_points

    List all binary entry points

  • get_data_vars

    List data definitions in the program

  • get_data_at

    Get hexdump/data at a specific address

  • create_data_var

    Define data variables at addresses

  • get_current_address

    Get current cursor address

  • get_code

    Code Retrieval Tool

  • list

    List classes with optional pattern filtering and pagination

  • get_info

    Get detailed class information (methods, fields, vtables, virtual functions)

  • address

    Find all references to/from a specific address

  • function

    Find all cross-references for a function

  • include_calls

    Include callers/callees (replaces separate call graph tool)

Details on this page are taken from the project's README. Open README

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools