IDA Pro MCP
MCP server that bridges IDA Pro with an agent: reading decompilation, renaming and typing, comments and running IDAPython right in the database
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Runs arbitrary IDAPython and modifies the IDA Pro database
- Opens and analyzes potentially malicious binaries
Install
Manual install
claude plugin marketplace add mrexodia/claude-marketplace
claude plugin install ida-pro-mcp@mrexodiaInstalls the idalib MCP server as a plugin.
This is third-party code. Review the repository files before installing.
What it does
The server exposes an IDA Pro database to an agent through a set of MCP tools. The agent can read the decompilation and disassembly, list functions and cross references, rename variables and functions, change argument and pointer types, leave comments and run arbitrary IDAPython. A dedicated tool converts numbers between bases so the model does not miscalculate. It runs in two modes: as a plugin inside a running IDA Pro, or headless through idalib, where a database is analyzed without the GUI. Transport is stdio for local clients and HTTP or SSE for connecting to the interface.
Who it is for. For reverse engineers and malware analysts who work with binaries in IDA Pro and want to bring an AI agent into the loop.
Good fit when
- You want the agent to work through a function in IDA Pro and add meaningful names and comments
- You need headless analysis of a binary through idalib without opening the GUI
- You want to connect IDA Pro to Claude Code, Cursor, Codex or another MCP client
Not a fit when
- You have IDA Free: it is not supported, a commercial IDA Pro is required
- The code is heavily obfuscated; string encryption and control flow flattening are better removed before the model works
- You need analysis without any risk of database edits: the server can modify and execute code
Example request
Work through this function in IDA Pro, rename the variables, fix the types and leave comments with your findingsLimitations
A commercial IDA Pro 8.3 or newer is required, 9 is recommended, IDA Free is not supported. Python 3.11 or newer and uv must be installed. Headless mode needs a one-time idalib activation with the script shipped in IDA. The GUI method via ida-pro-mcp --install is marked by the author as deprecated in favor of idalib-mcp. Models miscalculate base conversions, so arithmetic should explicitly use the int_convert tool.
How to disable. Remove the plugin: claude plugin uninstall ida-pro-mcp@mrexodia or codex plugin remove ida-pro-mcp@mrexodia. For a manual install, drop the server entry from the MCP client config and remove the IDA plugin, then pip uninstall ida-pro-mcp.
MCP
- Transport
- stdio, http
- Authentication
- not required
| Environment variables | |
|---|---|
| IDA_MCP_URL | Address of the running GUI server the client connects to. |
| IDA_MCP_TOOL_TIMEOUT_SEC | Tool call timeout in seconds. |
| IDA_MCP_MAX_WORKERS | Maximum number of concurrent idalib worker processes. |
Security check
- Runs arbitrary IDAPython and modifies the IDA Pro database
- Opens and analyzes potentially malicious binaries
README in short
The README describes an MCP server for analyzing binaries in IDA Pro together with an agent. It lists requirements: IDA Pro 8.3 and up, Python 3.11 and up, uv, and idalib activation for headless mode. It gives plugin install commands for Claude Code, Codex and Kimi Code, a manual pip install with ida-pro-mcp --install, and how to run SSE and headless idalib-mcp over stdio or HTTP. It also covers prompting advice: read the decompilation, rename and type, never convert numbers by hand but call the int_convert tool. MIT licensed.
FAQ
Does it work with IDA Free?
No. A commercial IDA Pro 8.3 or newer is required, 9 is recommended.
How does GUI mode differ from idalib?
In GUI mode the server runs as a plugin inside an open IDA Pro. idalib-mcp runs analysis without the GUI, each database in its own worker process. The author recommends idalib and marks the old GUI plugin as deprecated.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents