CutterSAFE
MCP Server for Cutter
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.apache.org/licenses/LICENSE-2.0) [](https://www.linkedin.com/in/amey-pathak/)
cutterMCP is an Model Context Protocol server for allowing LLMs to autonomously reverse engineer applications. It exposes numerous tools from core Cutter functionality to MCP clients.
Features
MCP Server + Cutter Plugin
- Decompile and analyze binaries in Cutter
- Automatically rename methods and data
- List methods, imports, and exports
Installation
Prerequisites
Cutter
First, download the latest release from this repository. This contains the Cutter plugin and Python MCP client. Then, you can directly import the plugin into Cutter.
- Run Cutter
- Go to Edit -> Preferences -> Plugins
- Find the plugin directory location
- Copy
CutterMCPPlugin.pyfrom the downloaded release and paste it inside the python folder - Restart Cutter
- If successful, you’ll see the plugin under Windows -> Plugins and a new widget in the bottom panel
MCP Clients
Theoretically, any MCP client should work with cutterMCP. one example is given below.
Example 1: Claude Desktop
To set up Claude Desktop as a Cutter MCP client, go to Claude -> Settings -> Developer -> Edit Config -> claude_desktop_config.json and add the following:
MacOS/Linux :
{
"mcpServers": {
"cutter": {
"command": "python",
"args": [
"/ABSOLUTE_PATH_TO/bridge_mcp_cutter.py"
]
}
}
}Windows :
{
"mcpServers": {
"cutter": {
"command": "python",
"args": [
"C:\\ABSOLUTE_PATH_TO\\bridge_mcp_cutter.py"
]
}
}
}ba0a00f3fca0OBSERVED · 2026-10-08Exposed tools (15)
12 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
decompile_function_by_address | read | |
disassemble_function | read | |
get_function_prototype | read | |
list_exports | read | |
list_functions | read | |
list_imports | read | |
list_libraries | read | |
list_segments | read | |
rename_function_by_address | write | |
search_functions_by_name | read | |
set_decompiler_comment | write | |
set_function_prototype | write | |
show_function_detail | read | |
show_headers | read | |
xrefs_to | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
DEFAULT_CUTTER_SERVER = "http://127.0.0.1:8000/"
Gates applied: no_behavioural_pass.
ba0a00f3fca0full audit observations/trust-audit/mcp-server/ap425q__cutter.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ba0a00f3fca0 | SAFE | B | 89 | first audit |
Questions
What is the Cutter MCP server?
MCP Server for Cutter
What tools does Cutter expose?
15 in total: 12 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Cutter safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Cutter need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (ba0a00f3fca0), read on 2026-10-08. The repository is watched and re-audited when it changes.