ghidra-mcpCAUTION
Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mcptoplist.com/server/glama%2Fbethington%2Fghidra-mcp)
[](https://github.com/bethington/ghidra-mcp/actions/workflows/tests.yml) [](https://github.com/bethington/ghidra-mcp/releases/latest) [](LICENSE) [](https://github.com/sponsors/bethington)
[](https://www.python.org/) [](https://openjdk.org/projects/jdk/21/) [](https://ghidra-sre.org/) [](https://modelcontextprotocol.io/)
[](https://github.com/bethington/ghidra-mcp/stargazers) [](https://github.com/bethington/ghidra-mcp/commits/main) [
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
check_tools | read | |
list_instances | read | |
list_tool_groups | read |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (20)
gradle-wrapper.jar
GHIDRA_MCP_URL=http://127.0.0.1:8089/
GHIDRA_SERVER_URL=http://127.0.0.1:8089/
# GHIDRA_DEBUGGER_URL=http://127.0.0.1:8099
Benchmark.dll
BenchmarkDebug.exe
.env.template
.markdownlint-cli2.jsonc
.mcp.json.example
assert bri.md5(str(binary)) == hashlib.md5(payload).hexdigest()
digest = hashlib.md5()
http://127.0.0.1:8089/check_connection` reports the extension's version;
curl http://127.0.0.1:8089/check_connection
DOS_STUB = bytes.fromhex(
**The MCP bridge reads the same `GHIDRA_MCP_AUTH_TOKEN`** and attaches `Authorization: Bearer <token>` to every outbound call (UDS and TCP). Export the same token in the bridge's environment — otherwi
Successfully implemented 3 high-priority improvements to the Ghidra MCP server based on recommendations from the session evaluation report. These changes fix critical bugs, add missing functionality,
`env` block, or your shell); it does not read a `.env` file.
| `--use-debugger-toggle` | Read `INSTALL_DEBUGGER_DEPS` from `.env` to decide whether to install debugger deps. |
> curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
a25a93adcd41full audit observations/trust-audit/mcp-server/bethington__ghidra-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a25a93adcd41 | CAUTION | B | 85 | first audit |
Questions
What is the ghidra-mcp MCP server?
Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.
What tools does ghidra-mcp expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ghidra-mcp safe to connect to an agent?
With care. The audit graded it B (85/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does ghidra-mcp need?
It reads GHIDRA_MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ghidra-mcp run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as ghidra-mcp-bridge.
How current is this page?
The grade is for one exact copy of the source (a25a93adcd41), read on 2026-10-08. The repository is watched and re-audited when it changes.