Open-ReverseLab

An MCP server and agent toolkit for reverse engineering: Ghidra, Frida, x64dbg and Rizin for binary analysis, CTF and malware research

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • It runs reverse-engineering tools and arbitrary binary analysis
  • It handles malware and exploit samples
All reasons and checks

ling71671/open-reverselab

Install

Manual install

git clone https://github.com/LING71671/open-reverselab.git
cd open-reverselab
./scripts/misc/bootstrap.sh

Install only the tool sets you need, not the whole toolchain at once.

This is third-party code. Review the repository files before installing.

What it does

Open-ReverseLab gives an agent reverse-engineering tools through an MCP server that ties together Ghidra, Frida, x64dbg and Rizin. The agent runs automated analysis of PE, APK and other binaries and helps with CTF tasks and malware research. The repository is cloned into a workspace, tools install in the sets you need, and the agent connects over MCP. It ships skills, task templates and a tool contract check via a smoke test.

Who it is for. For security and reverse-engineering specialists, CTF players and malware researchers.

Good fit when

  • You need automated analysis of a binary or mobile package
  • You need Ghidra, Frida, x64dbg or Rizin driven by an agent
  • You need an environment for CTF tasks or sample research

Not a fit when

  • You have no lawful basis to analyze a binary or sample
  • You need ordinary development, not reverse engineering

Example request

Analyze this binary: find the entry point and break down the suspicious functions

Limitations

The project is heavy to set up: it needs reverse-engineering tools and environment preparation via bootstrap. Working with exploit and malware samples may be flagged by antivirus, so targeted path exclusions and isolation are recommended. Use it only on what you are allowed to analyze.

How to disable. Remove the MCP server entry from the agent config and delete the cloned repository directory.

MCP

Transport
stdio
Authentication
not required

Security check

  • It runs reverse-engineering tools and arbitrary binary analysis
  • It handles malware and exploit samples

README in short

The README describes Open-ReverseLab as an open platform and MCP server for agent-driven reverse engineering. It ties together Ghidra, Frida, x64dbg and Rizin and supports PE, APK and other binary analysis, CTF tasks and malware research. The repository is cloned locally, tools install in sets, and the MCP is verified with a smoke test. It provides an agent context-loading chain and antivirus notes. GPL-3.0 licensed.

FAQ

Do I need to install all tools at once?

No, sets install on demand: for example, web CTF does not need the full reverse-engineering toolchain.

Which agents does it work with?

Claude Code, Codex, OpenCode and any MCP-compatible agent.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIOpen-ReverseLab

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.