ida-mcp-rs
A headless IDA Pro MCP server in Rust: the agent opens a database, lists functions, disassembles, decompiles and builds cross references
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Runs IDAPython scripts and can modify the analysis database
- A reverse engineering tool; use it on your own or authorized binaries
- Working with untrusted binaries requires environment isolation
Install
Manual install
brew install blacktop/tap/ida-mcpmacOS and Linux via Homebrew; use Scoop on Windows.
This is third-party code. Review the repository files before installing.
What it does
The server connects an AI agent to IDA Pro in headless mode through the idalib library and runs without a GUI. It opens a database from a file, quickly returns the function list, disassembly and strings, while heavier cross reference analysis and decompilation run in the background with status polling. It supports raw image loading with processor, bitness and entry point, dyld_shared_cache work, IDAPython script execution and a read-only mode. Transports include stdio and streamable HTTP, plus a workspace with several databases.
Who it is for. For reverse engineers and malware analysts with an IDA Pro license who automate analysis through an agent.
Good fit when
- You automate binary analysis in IDA Pro from an AI client
- You need headless mode for pipelines and batch analysis
- You need disassembly, decompilation and cross references on the agent's request
Not a fit when
- You do not have an IDA Pro 9.4 license
- You analyze someone else's proprietary code without rights
- You only need the IDA GUI without automation
Example request
Open this binary and decompile the main functionLimitations
It needs an IDA Pro 9.4 license, and server versions are tied to IDA versions. Decompilation requires Hex-Rays and a completed analysis. Non-standard install paths need environment variables, for example DYLD_LIBRARY_PATH on macOS or IDADIR on Linux. Script execution and database editing tools can be disabled with the read-only mode.
How to disable. Remove the server with the client command, for example claude mcp remove ida, and uninstall the binary through the manager used to install it (Homebrew, Scoop, Nix).
MCP
- Transport
- stdio, http
- Authentication
- not required
| Environment variables | |
|---|---|
| IDADIR | Path to the IDA install on Linux for library discovery when it is non-standard. |
| DYLD_LIBRARY_PATH | Path to IDA libraries on macOS when the binary cannot find libida.dylib. |
| IDA_MCP_READ_ONLY | Enables read-only mode and removes mutating tools. |
Security check
- Runs IDAPython scripts and can modify the analysis database
- A reverse engineering tool; use it on your own or authorized binaries
- Working with untrusted binaries requires environment isolation
README in short
The README covers install via Homebrew, Scoop and Nix, setup on macOS, Linux and Windows with environment variables for locating IDA libraries, and wiring to Claude Code, Codex CLI, Gemini CLI and Cursor. It shows the workflow: open a database, list functions, disassemble, background analysis and decompile. It also details the multi-database workspace, an HTTP pool, an experimental debugger, dyld_shared_cache work, IDAPython and disabling Lumina. It includes context optimization flags and a read-only mode.
FAQ
Do I need paid IDA Pro?
Yes. A valid IDA Pro 9.4 license is required, and server versions match IDA versions.
How do I limit capabilities?
There is a read-only mode and toolset filtering that strip database edits and arbitrary code execution.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents