Ghidra MCP Server

An MCP server for the Ghidra disassembler: hundreds of tools for reverse engineering, decompilation, renaming, structures, emulation and debugging

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Tools write into the Ghidra project: renaming, types, comments, structures
  • There are endpoints that run arbitrary Java and Python scripts and a live debugger
  • The server is unauthenticated by default and can be exposed beyond localhost if misconfigured
All reasons and checks

bethington/ghidra-mcp

Install

Manual install

git clone https://github.com/bethington/ghidra-mcp.git
cd ghidra-mcp
python -m tools.setup ensure-prereqs --ghidra-path /path/to/ghidra
python -m tools.setup build
python -m tools.setup deploy --ghidra-path /path/to/ghidra

Point to your installed Ghidra. Deploy installs the extension, starts Ghidra and waits for MCP readiness. Java 21 and Python with uv or pip are required.

This is third-party code. Review the repository files before installing.

What it does

The project bridges the Ghidra disassembler with agents over the Model Context Protocol. It has two parts: a Ghidra plugin that runs a local HTTP server, and a Python bridge that exposes the tools to the agent over MCP. There are more than two hundred tools, and not only read ones: decompilation and call graphs, renaming functions and variables, comments, creating structs, unions and enums, string and byte-pattern search, import and export analysis, code emulation via EmulatorHelper and live debugger integration. It adds batch operations for bulk edits, documentation transfer across binary versions by function hash, and shared Ghidra Server workflows. Some naming and typing conventions are moved into the tool layer so output stays consistent across sessions. GUI and headless modes are supported, including running in Docker.

Who it is for. For reverse engineers and analysts who work on binaries in Ghidra and want to drive the work through an agent.

Good fit when

  • You need to decompile and document functions in Ghidra through an agent
  • You need to bulk rename, comment and type code in a Ghidra project
  • You need to transfer documentation across versions of one binary or work with a shared Ghidra Server

Not a fit when

  • You have no Ghidra installed or a matching environment (Java, Python)
  • You only need a one-off read and do not want to set up the plugin and the bridge

Example request

Document this function in Ghidra: analyze the decompilation, rename the variables and add a plate comment

Limitations

You need Ghidra, Java 21 and Python with uv or pip, and the plugin version is tied to a specific Ghidra version stated in the project. Python scripts inside Ghidra require the Jython extension. By default the plugin HTTP server listens on localhost only and does not authenticate requests, which is a trusted-local-user model. The arbitrary-script endpoints are off and are enabled by a separate variable, and an access token must be set before exposing the server beyond localhost.

How to disable. Remove the ghidra-mcp server entry from your agent's MCP configuration and uninstall the GhidraMCP extension from Ghidra via File > Install Extensions.

MCP

Transport
stdio, http
Authentication
not required
Environment variables
Environment variables
GHIDRA_MCP_URL
Address of the Ghidra plugin HTTP server, default http://127.0.0.1:8089.
GHIDRA_MCP_ALLOW_SCRIPTS
Enables the arbitrary-script endpoints, off by default.
GHIDRA_MCP_AUTH_TOKEN
secret
Access token, required before exposing the server beyond localhost.

Security check

  • Tools write into the Ghidra project: renaming, types, comments, structures
  • There are endpoints that run arbitrary Java and Python scripts and a live debugger
  • The server is unauthenticated by default and can be exposed beyond localhost if misconfigured

README in short

The README presents an MCP server that connects Ghidra's reverse engineering capabilities to agents and offers more than two hundred tools with full write access. Beyond reading and decompilation it does renaming, typing, comments, struct creation, script execution, P-code emulation and debugger integration. Installation goes through python -m tools.setup: preparing dependencies, a Maven build and deploying the extension into Ghidra, with GUI, headless and Docker support. A separate section covers moving naming conventions into the tool layer and hardening the server when it is exposed beyond localhost. Apache 2.0 licensed.

FAQ

Is this a standalone program or a Ghidra add-on?

It is a plugin for an already installed Ghidra plus a Python bridge. The plugin runs a local HTTP server, and the bridge exposes the tools to the agent over MCP.

Can the agent run arbitrary code?

The script-execution endpoints are off by default and are enabled by a separate environment variable. Turn them on only if you truly need scripting and trust the caller.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIGhidra MCP Server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.