AcademyMCP serversDevelopment

GhidraMCP

Security and engineering teams use it to analyse binaries in Ghidra with help from an AI assistant.

  • Recommendedour rating
  • 145gitHub stars
  • Apache-2.0licence
  • 19 days agolast update
claude mcp add ghidra -- /path/to/mcp_bridge --host localhost --port 8765
README.md

Loading the file...

What it does

A Ghidra extension that exposes 70 reverse-engineering tools to AI assistants through MCP. With a binary open in Ghidra, the assistant can decompile functions, rename symbols, annotate code and inspect memory, imports and exports.

Use cases

  1. 01Decompile a function and explain what it does
  2. 02Rename symbols and annotate code in a binary
  3. 03Review imports and exports of a suspicious file

Questions about
GhidraMCP.

What is GhidraMCP used for?

Security and engineering teams use it to analyse binaries in Ghidra with help from an AI assistant. A Ghidra extension that exposes 70 reverse-engineering tools to AI assistants through MCP. With a binary open in Ghidra, the assistant can decompile functions, rename symbols, annotate code and inspect memory, imports and exports.

How do I install GhidraMCP?

Run this in your terminal: claude mcp add ghidra -- /path/to/mcp_bridge --host localhost --port 8765

Is GhidraMCP open source?

Yes. The code is on GitHub (13bm/GhidraMCP) under the Apache-2.0 licence.

Is GhidraMCP safe to use?

It passed our automatic scan for credential theft, hidden instructions and risky install commands. Third party open source software. Sabemos AI does not maintain it. Check the code and permissions before you connect it to company data.