GhidraCAUTION
Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mcptoplist.com/server/glama%2Fbethington%2Fghidra-mcp)
[](https://github.com/bethington/ghidra-mcp/actions/workflows/tests.yml) [](https://github.com/bethington/ghidra-mcp/releases/latest) [](LICENSE) [](https://github.com/sponsors/bethington)
[](https://www.python.org/) [](https://openjdk.org/projects/jdk/21/) [](https://ghidra-sre.org/) [](https://modelcontextprotocol.io/)
[](https://github.com/bethington/ghidra-mcp/stargazers) [](https://github.com/bethington/ghidra-mcp/commits/main) [
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
check_tools | read | |
list_instances | read | |
list_tool_groups | read |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (20)
gradle-wrapper.jar
GHIDRA_MCP_URL=http://127.0.0.1:8089/
GHIDRA_SERVER_URL=http://127.0.0.1:8089/
GHIDRA_DEBUGGER_URL=http://127.0.0.1:8099
Benchmark.dll
BenchmarkDebug.exe
.env.template
.markdownlint-cli2.jsonc
assert bri.md5(str(binary)) == hashlib.md5(payload).hexdigest()
digest = hashlib.md5()
curl http://127.0.0.1:8089/mcp/instance_info
curl -s http://127.0.0.1:8089/mcp/schema | jq '.tools | length'
DOS_STUB = bytes.fromhex(
live_bytes = bytes.fromhex(live["hex"])
x, y = (int.from_bytes(bytes.fromhex(h), "little", signed=True) for h in out["args_out"])
| `--use-debugger-toggle` | Read `INSTALL_DEBUGGER_DEPS` from `.env` to decide whether to install debugger deps. |
> curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
**The MCP bridge reads the same `GHIDRA_MCP_AUTH_TOKEN`** and attaches `Authorization: Bearer <token>` to every outbound call (UDS and TCP). Export the same token in the bridge's environment — otherwi
Successfully implemented 3 high-priority improvements to the Ghidra MCP server based on recommendations from the session evaluation report. These changes fix critical bugs, add missing functionality,
Gates applied: no_behavioural_pass.
e6ccd8917d65full audit observations/trust-audit/mcp-server/bethington__ghidra-7.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | e6ccd8917d65 | CAUTION | B | 83 | score 87 -> 83 |
| 2026-09-18 | 59223f9f5924 | CAUTION | B | 87 | first audit |
Questions
What is the Ghidra MCP server?
Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.
What tools does Ghidra expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ghidra safe to connect to an agent?
With care. The audit graded it B (83/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Ghidra need?
It reads GHIDRA_MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Ghidra run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as ghidra-mcp-bridge.
How current is this page?
The grade is for one exact copy of the source (e6ccd8917d65), read on 2026-09-22. The repository is watched and re-audited when it changes.