Binary AnalysisSAFE
MCP server for analyzing PE, ELF, and Mach-O binaries using LIEF
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server for analysing PE, ELF, Mach-O, and COFF binary files using LIEF. Pass an absolute file path to any tool and the format is auto-detected.
Tools
Requirements
- Python 3.10+
- Dependencies listed in
requirements.txt: mcp[cli]— Model Context Protocol SDKlief>=0.17.0— binary parsing library
Installation
git clone https://github.com/Ap3x/BinaryAnalysis-MCP.git cd BinaryAnalysis-MCP python -m venv .venv # Windows .venv\Scripts\activate # macOS / Linux source .venv/bin/activate pip install -r requirements.txt
Running the server
python server.py
The server communicates over stdio using the MCP protocol.
MCP client configuration
Claude Desktop
Add the following to your Claude Desktop config file:
- Windows:
%APPDATA%\Claude\claude_desktop_config.json
-
924366f926fdOBSERVED · 2026-10-09Exposed tools (9)
9 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_binary_exports | read | Exported functions / symbols. |
get_binary_headers | read | Detailed header fields for a binary. |
get_binary_imports | read | Imported functions, grouped by library. |
get_binary_info | read | Quick triage of a binary file. |
get_binary_libraries | read | Dynamic library dependencies (DLLs / shared objects / dylibs). |
get_binary_sections | read | List all sections with name, sizes, virtual address, permissions, and entropy. |
get_binary_security | read | Security features and hardening of a binary. |
get_binary_signatures | read | Certificate and code-signing info for a binary. |
get_coff_info | read | Parse a COFF object file and return header, sections, symbols, and relocations. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
.gitmodules
sphinx, furo, myst-parser
mcp, lief
Gates applied: no_behavioural_pass.
924366f926fdfull audit observations/trust-audit/mcp-server/ap3x__binary-analysis.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 924366f926fd | SAFE | B | 89 | first audit |
Questions
What is the Binary Analysis MCP server?
MCP server for analyzing PE, ELF, and Mach-O binaries using LIEF
What tools does Binary Analysis expose?
9 in total: 9 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Binary Analysis safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Binary Analysis need?
No credential environment variables were found in its source, so it appears to need none.
How does Binary Analysis run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (924366f926fd), read on 2026-10-09. The repository is watched and re-audited when it changes.