Reverify
An MCP server and CLI where deterministic tools verify every agent claim about code and binaries against ground truth
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Runs file analysis and edits agent settings when installing hooks
Install
Manual install
pip install reverifyBase mode; for full binary analysis use pip install "reverify[full]" or "reverify[angr]".
This is third-party code. Review the repository files before installing.
What it does
Reverify makes a deterministic tool the judge: the model proposes a claim about structure or behavior, the tool checks it against the artifact itself, and returns a verdict with evidence. The model cannot assert a fact on its own. The reverify verify command and the MCP server operate where hallucination is most dangerous, in binary reverse engineering. A separate rollover feature hands session context to a file and starts a fresh one so long tasks keep their accuracy. The core installs on pure Python, with heavier analysis engines available optionally.
Who it is for. For code-analysis and security engineers who need verifiable agent answers rather than guesses.
Good fit when
- You need agent claims about code or a binary checked against facts
- You reverse binaries and refuse to accept fabrications as facts
- A long session is losing context and needs a clean handoff
Not a fit when
- The task is text generation, not fact verification
- There is no artifact that can be checked deterministically
Example request
Use reverify to check whether this function really reads memory at the given offsetLimitations
The base mode is pure Python; full binary analysis needs the optional capstone, unicorn, lief, Z3 or angr packages. Reverify verifies claims but does not build its own program-analysis engine.
How to disable. Remove the hooks with reverify rollover uninstall, then uninstall the package with pip uninstall reverify.
MCP
- Transport
- stdio
- Authentication
- not required
Security check
- Runs file analysis and edits agent settings when installing hooks
README in short
The README explains that the model proposes a claim and reverify checks it against the artifact, returning VERIFIED, REFUTED or INCONCLUSIVE with evidence. The tool installs from PyPI, the base mode works with no external dependencies, and capstone, unicorn, lief, Z3 and angr connect optionally. The rollover feature for moving context between sessions is described separately. MIT licensed.
FAQ
Is Ghidra required?
No, the base mode installs on pure Python with no external tools; advanced engines are optional.
Which agents does rollover support?
Claude Code, Codex, Gemini CLI and OpenCode.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything