Ghidra MCP Server
An MCP server for the Ghidra disassembler: hundreds of tools for reverse engineering, decompilation, renaming, structures, emulation and debugging
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Tools write into the Ghidra project: renaming, types, comments, structures
- There are endpoints that run arbitrary Java and Python scripts and a live debugger
- The server is unauthenticated by default and can be exposed beyond localhost if misconfigured
Install
Manual install
git clone https://github.com/bethington/ghidra-mcp.git
cd ghidra-mcp
python -m tools.setup ensure-prereqs --ghidra-path /path/to/ghidra
python -m tools.setup build
python -m tools.setup deploy --ghidra-path /path/to/ghidraPoint to your installed Ghidra. Deploy installs the extension, starts Ghidra and waits for MCP readiness. Java 21 and Python with uv or pip are required.
This is third-party code. Review the repository files before installing.
What it does
The project bridges the Ghidra disassembler with agents over the Model Context Protocol. It has two parts: a Ghidra plugin that runs a local HTTP server, and a Python bridge that exposes the tools to the agent over MCP. There are more than two hundred tools, and not only read ones: decompilation and call graphs, renaming functions and variables, comments, creating structs, unions and enums, string and byte-pattern search, import and export analysis, code emulation via EmulatorHelper and live debugger integration. It adds batch operations for bulk edits, documentation transfer across binary versions by function hash, and shared Ghidra Server workflows. Some naming and typing conventions are moved into the tool layer so output stays consistent across sessions. GUI and headless modes are supported, including running in Docker.
Who it is for. For reverse engineers and analysts who work on binaries in Ghidra and want to drive the work through an agent.
Good fit when
- You need to decompile and document functions in Ghidra through an agent
- You need to bulk rename, comment and type code in a Ghidra project
- You need to transfer documentation across versions of one binary or work with a shared Ghidra Server
Not a fit when
- You have no Ghidra installed or a matching environment (Java, Python)
- You only need a one-off read and do not want to set up the plugin and the bridge
Example request
Document this function in Ghidra: analyze the decompilation, rename the variables and add a plate commentLimitations
You need Ghidra, Java 21 and Python with uv or pip, and the plugin version is tied to a specific Ghidra version stated in the project. Python scripts inside Ghidra require the Jython extension. By default the plugin HTTP server listens on localhost only and does not authenticate requests, which is a trusted-local-user model. The arbitrary-script endpoints are off and are enabled by a separate variable, and an access token must be set before exposing the server beyond localhost.
How to disable. Remove the ghidra-mcp server entry from your agent's MCP configuration and uninstall the GhidraMCP extension from Ghidra via File > Install Extensions.
MCP
- Transport
- stdio, http
- Authentication
- not required
| Environment variables | |
|---|---|
| GHIDRA_MCP_URL | Address of the Ghidra plugin HTTP server, default http://127.0.0.1:8089. |
| GHIDRA_MCP_ALLOW_SCRIPTS | Enables the arbitrary-script endpoints, off by default. |
| GHIDRA_MCP_AUTH_TOKEN secret | Access token, required before exposing the server beyond localhost. |
Security check
- Tools write into the Ghidra project: renaming, types, comments, structures
- There are endpoints that run arbitrary Java and Python scripts and a live debugger
- The server is unauthenticated by default and can be exposed beyond localhost if misconfigured
README in short
The README presents an MCP server that connects Ghidra's reverse engineering capabilities to agents and offers more than two hundred tools with full write access. Beyond reading and decompilation it does renaming, typing, comments, struct creation, script execution, P-code emulation and debugger integration. Installation goes through python -m tools.setup: preparing dependencies, a Maven build and deploying the extension into Ghidra, with GUI, headless and Docker support. A separate section covers moving naming conventions into the tool layer and hardening the server when it is exposed beyond localhost. Apache 2.0 licensed.
FAQ
Is this a standalone program or a Ghidra add-on?
It is a plugin for an already installed Ghidra plus a Python bridge. The plugin runs a local HTTP server, and the bridge exposes the tools to the agent over MCP.
Can the agent run arbitrary code?
The script-execution endpoints are off by default and are enabled by a separate environment variable. Turn them on only if you truly need scripting and trust the caller.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents