Open-ReverseLab
An MCP server and agent toolkit for reverse engineering: Ghidra, Frida, x64dbg and Rizin for binary analysis, CTF and malware research
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- It runs reverse-engineering tools and arbitrary binary analysis
- It handles malware and exploit samples
Install
Manual install
git clone https://github.com/LING71671/open-reverselab.git
cd open-reverselab
./scripts/misc/bootstrap.shInstall only the tool sets you need, not the whole toolchain at once.
This is third-party code. Review the repository files before installing.
What it does
Open-ReverseLab gives an agent reverse-engineering tools through an MCP server that ties together Ghidra, Frida, x64dbg and Rizin. The agent runs automated analysis of PE, APK and other binaries and helps with CTF tasks and malware research. The repository is cloned into a workspace, tools install in the sets you need, and the agent connects over MCP. It ships skills, task templates and a tool contract check via a smoke test.
Who it is for. For security and reverse-engineering specialists, CTF players and malware researchers.
Good fit when
- You need automated analysis of a binary or mobile package
- You need Ghidra, Frida, x64dbg or Rizin driven by an agent
- You need an environment for CTF tasks or sample research
Not a fit when
- You have no lawful basis to analyze a binary or sample
- You need ordinary development, not reverse engineering
Example request
Analyze this binary: find the entry point and break down the suspicious functionsLimitations
The project is heavy to set up: it needs reverse-engineering tools and environment preparation via bootstrap. Working with exploit and malware samples may be flagged by antivirus, so targeted path exclusions and isolation are recommended. Use it only on what you are allowed to analyze.
How to disable. Remove the MCP server entry from the agent config and delete the cloned repository directory.
MCP
- Transport
- stdio
- Authentication
- not required
Security check
- It runs reverse-engineering tools and arbitrary binary analysis
- It handles malware and exploit samples
README in short
The README describes Open-ReverseLab as an open platform and MCP server for agent-driven reverse engineering. It ties together Ghidra, Frida, x64dbg and Rizin and supports PE, APK and other binary analysis, CTF tasks and malware research. The repository is cloned locally, tools install in sets, and the MCP is verified with a smoke test. It provides an agent context-loading chain and antivirus notes. GPL-3.0 licensed.
FAQ
Do I need to install all tools at once?
No, sets install on demand: for example, web CTF does not need the full reverse-engineering toolchain.
Which agents does it work with?
Claude Code, Codex, OpenCode and any MCP-compatible agent.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents