Atlas / MCP servers / cnitlrt / Headless Ida

Headless IdaSAFE

mcp/cnitlrt/headless-ida

headless-ida-mcp-server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
21 14r · 7w · 0d
Transport
—
License
—
Stars
43
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This project builds upon the work of:

Headless IDA MCP Server

If you want to run the server directly as a cli app, rather than an IDA plugin interactively,you can chose it.

Project Description

This project uses IDA Pro's headless mode to analyze binary files and provides a suite of tools via MCP to manage and manipulate functions, variables, and more.

Prerequisites

  • Python 3.12 or higher
  • IDA Pro with headless support (idat) https://github.com/DennyDai/headless-ida

Installation

  1. Clone the project locally:
git clone https://github.com/cnitlrt/headless-ida-mcp-server.git 
cd headless-ida-mcp-server
  1. Install dependencies:
uv python install 3.12
uv venv --python 3.12
uv pip install -e .

Configuration

  1. Copy the example environment file:
cp .env_example .env
  1. Configure the following environment variables in .env:
  • IDA_PATH: Path to IDA Pro's headless executable (idat), e.g., /home/ubuntu/idapro/idat
  • PORT: Port number for the MCP server, e.g., 8888
  • HOST: Host address for the MCP server, e.g., 127.0.0.1
  • TRANSPORT: MCP transport mode (sse or stdio)

Usage

  1. Start the server:
uv run headless_ida_mcp_server
  1. Connect to the server using an MCP client:

Debug it:

npx -y @modelcontextprotocol/inspector

or

{
"mcpServers": {
"ida": {
"command": "/path/to/uv",
"args": ["--directory","path/to/headless-ida-mcp-server","run","headless_ida_mcp_server"]
}
}
}

Read from source at commit 6a4239145db0OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add headless-ida-mcp-server -- uvx headless-ida-mcp-server
claude-desktop
{
  "mcpServers": {
    "headless-ida-mcp-server": {
      "command": "uvx",
      "args": [
        "headless-ida-mcp-server"
      ]
    }
  }
}
03

Exposed tools (21)

14 read · 7 write · 0 destructive.

ToolRiskDescription
convert_numberreadConvert a number to a different representation
decompile_checkedreadDecompile a function at the given address
decompile_functionreadDecompile a function at the given address
disassemble_functionreadDisassemble a function at the given address
get_current_addressreadGet the current address
get_current_functionreadGet the current function
get_entry_pointsreadGet all entry points of the binary
get_functionreadGet a function by address
get_function_by_addressreadGet a function by address
get_function_by_namereadGet a function by name
get_xrefs_toreadGet cross references to a given address
list_functionsreadList all functions
refresh_decompiler_ctextreadRefresh the decompiler ctext for a given function
refresh_decompiler_widgetreadRefresh the decompiler widget
rename_functionwriteRename a function
rename_local_variablewriteRename a local variable in a function
save_idb_filewriteSave the IDB file
set_binary_pathwriteSet the path to the binary file
set_decompiler_commentwriteSet a comment for a given address in the function pseudocode
set_disassembly_commentwriteSet a comment for a given address in the function disassembly
set_function_prototypewriteSet a function
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

LOWInventory / provenance · inv.binary · CWE-1104
test/heap/main
main
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
test/stack/main
main
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env_example
.env_example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 6a4239145db0full audit observations/trust-audit/mcp-server/cnitlrt__headless-ida.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086a4239145db0SAFEB89first audit
06

Questions

What is the Headless Ida MCP server?

headless-ida-mcp-server

What tools does Headless Ida expose?

21 in total: 14 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Headless Ida safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Headless Ida need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (6a4239145db0), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement