Atlas / MCP servers / bethington / Ghidra

GhidraCAUTION

mcp/bethington/ghidra-7

Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
3,948
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mcptoplist.com/server/glama%2Fbethington%2Fghidra-mcp)

[](https://github.com/bethington/ghidra-mcp/actions/workflows/tests.yml) [](https://github.com/bethington/ghidra-mcp/releases/latest) [](LICENSE) [](https://github.com/sponsors/bethington)

[](https://www.python.org/) [](https://openjdk.org/projects/jdk/21/) [](https://ghidra-sre.org/) [](https://modelcontextprotocol.io/)

[](https://github.com/bethington/ghidra-mcp/stargazers) [](https://github.com/bethington/ghidra-mcp/commits/main) [![Discussions](https://img.shields.io/badge/discussions-join-7B68EE?style=for-the-badge&logo=github&lo

Read from source at commit e6ccd8917d65OBSERVED · 2026-09-22
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ghidra-mcp-bridge --env GHIDRA_MCP_AUTH_TOKEN=${GHIDRA_MCP_AUTH_TOKEN} -- uvx ghidra-mcp-bridge
claude-desktop
{
  "mcpServers": {
    "ghidra-mcp-bridge": {
      "command": "uvx",
      "args": [
        "ghidra-mcp-bridge"
      ],
      "env": {
        "GHIDRA_MCP_AUTH_TOKEN": "${GHIDRA_MCP_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
check_toolsread
list_instancesread
list_tool_groupsread
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (20)

MEDIUMInventory / provenance · inv.binary · CWE-1104
gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.template:33
GHIDRA_MCP_URL=http://127.0.0.1:8089/
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.template:35
GHIDRA_SERVER_URL=http://127.0.0.1:8089/
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.template:39
GHIDRA_DEBUGGER_URL=http://127.0.0.1:8099
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/benchmark/Benchmark.dll
Benchmark.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/benchmark/BenchmarkDebug.exe
BenchmarkDebug.exe
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint-cli2.jsonc
.markdownlint-cli2.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/unit/test_build_reference_index.py:266
assert bri.md5(str(binary)) == hashlib.md5(payload).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tools/build_reference_index.py:178
digest = hashlib.md5()
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/ISSUE_TEMPLATE/bug_report.yml:104
curl http://127.0.0.1:8089/mcp/instance_info
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/ISSUE_TEMPLATE/bug_report.yml:105
curl -s http://127.0.0.1:8089/mcp/schema | jq '.tools | length'
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/fixtures/benchmark/pe32.py:52
DOS_STUB = bytes.fromhex(
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/integration/test_oracle_live.py:155
live_bytes = bytes.fromhex(live["hex"])
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/integration/test_oracle_live.py:193
x, y = (int.from_bytes(bytes.fromhex(h), "little", signed=True) for h in out["args_out"])
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:1242
| `--use-debugger-toggle` | Read `INSTALL_DEBUGGER_DEPS` from `.env` to decide whether to install debugger deps. |
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:214
> curl -LsSf https://astral.sh/uv/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:752
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/prompts/TOOL_USAGE_GUIDE.md:518
**The MCP bridge reads the same `GHIDRA_MCP_AUTH_TOKEN`** and attaches `Authorization: Bearer <token>` to every outbound call (UDS and TCP). Export the same token in the bridge's environment — otherwi
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/releases/archive/v1.5.1/IMPROVEMENTS_IMPLEMENTED.md:9
Successfully implemented 3 high-priority improvements to the Ghidra MCP server based on recommendations from the session evaluation report. These changes fix critical bugs, add missing functionality, 
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha e6ccd8917d65full audit observations/trust-audit/mcp-server/bethington__ghidra-7.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-22e6ccd8917d65CAUTIONB83score 87 -> 83
2026-09-1859223f9f5924CAUTIONB87first audit
06

Questions

What is the Ghidra MCP server?

Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.

What tools does Ghidra expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Ghidra safe to connect to an agent?

With care. The audit graded it B (83/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Ghidra need?

It reads GHIDRA_MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Ghidra run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as ghidra-mcp-bridge.

How current is this page?

The grade is for one exact copy of the source (e6ccd8917d65), read on 2026-09-22. The repository is watched and re-audited when it changes.

Advertisement