ReVa

A Ghidra MCP server: the agent decompiles, renames variables, builds cross references and works through a binary via a set of small tools

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Exposes the PyGhidra environment, meaning arbitrary code execution
  • A reverse engineering tool; use it on your own or authorized binaries
  • A public interface without an API key grants access to analysis and scripting
All reasons and checks

cyberkaida/reverse-engineering-assistant

Install

Manual install

claude mcp add --scope user --transport http ReVa -- http://localhost:8080/mcp/message

Assistant mode: Ghidra must be open with a project.

This is third-party code. Review the repository files before installing.

What it does

ReVa is a Ghidra extension that runs an MCP server and exposes Ghidra to an AI agent. Its approach is built on many small tools: decompilation with context about names and references, variable renaming, type work, string search and diffing two programs. This set reduces context use and helps the model explore a binary step by step, the way a human does. It works in two modes: an assistant inside the Ghidra UI over streamable HTTP on port 8080 and headless for automation and pipelines. The repository ships a Claude Code plugin marketplace with skills for triage, deep analysis, cryptography and CTF.

Who it is for. For reverse engineers and analysts who work in Ghidra and want to connect an agent to the analysis.

Good fit when

  • You run analysis in Ghidra and want an assistant in the same project
  • You need headless mode for automation and pipelines
  • You work through a large binary or firmware and context economy matters

Not a fit when

  • You analyze someone else's proprietary code without rights
  • Your Ghidra is below version 12.0
  • The server is exposed on a public interface without an API key and with scripting enabled

Example request

Start from main, examine the program in detail and rename variables as you go

Limitations

It needs Ghidra 12.0 or newer, and headless mode uses the GHIDRA_INSTALL_DIR variable. ReVa exposes the PyGhidra environment, so when listening on a public interface the authors advise enabling an API key or disabling the scripting tools. By default the server listens on localhost. Headless projects are ephemeral and cleaned up after the session.

How to disable. Disable the ReVa plugins in Ghidra settings and remove the MCP entry from the client. The headless package is removed with uv tool uninstall reverse-engineering-assistant.

MCP

Transport
http, stdio
Authentication
API key
Environment variables
Environment variables
GHIDRA_INSTALL_DIR
Path to the Ghidra install, required for headless mode.

Security check

  • Exposes the PyGhidra environment, meaning arbitrary code execution
  • A reverse engineering tool; use it on your own or authorized binaries
  • A public interface without an API key grants access to analysis and scripting

README in short

The README explains ReVa's small-tools approach that reduces context use and gives example questions about a binary. It describes installing the Ghidra extension and enabling two plugins, and two modes: assistant over streamable HTTP on port 8080 and headless for automation. It gives config for Claude Code and VS Code, PyGhidra integration and installing the Claude Code plugin marketplace with skills. It notes the Ghidra 12.0 requirement and a warning about the API key on a public interface.

FAQ

How does assistant mode differ from headless?

In assistant mode ReVa runs inside an open Ghidra project over HTTP. In headless it starts Ghidra itself and creates an ephemeral project, which suits automation.

Are there Claude Code skills?

Yes. The repository has a plugin marketplace with skills for triage, deep analysis, cryptography and CTF.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIReVa

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.