Headless IdaSAFE
headless-ida-mcp-server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This project builds upon the work of:
- Tools code adapted from ida-pro-mcp by mrexodia
- Utilizes the headless-ida library by DennyDai
Headless IDA MCP Server
If you want to run the server directly as a cli app, rather than an IDA plugin interactively,you can chose it.
Project Description
This project uses IDA Pro's headless mode to analyze binary files and provides a suite of tools via MCP to manage and manipulate functions, variables, and more.
Prerequisites
- Python 3.12 or higher
- IDA Pro with headless support (idat) https://github.com/DennyDai/headless-ida
Installation
- Clone the project locally:
git clone https://github.com/cnitlrt/headless-ida-mcp-server.git cd headless-ida-mcp-server
- Install dependencies:
uv python install 3.12 uv venv --python 3.12 uv pip install -e .
Configuration
- Copy the example environment file:
cp .env_example .env
- Configure the following environment variables in
.env:
IDA_PATH: Path to IDA Pro's headless executable (idat), e.g.,/home/ubuntu/idapro/idatPORT: Port number for the MCP server, e.g.,8888HOST: Host address for the MCP server, e.g.,127.0.0.1TRANSPORT: MCP transport mode (sseorstdio)
Usage
- Start the server:
uv run headless_ida_mcp_server
- Connect to the server using an MCP client:
Debug it:
npx -y @modelcontextprotocol/inspector
or
{
"mcpServers": {
"ida": {
"command": "/path/to/uv",
"args": ["--directory","path/to/headless-ida-mcp-server","run","headless_ida_mcp_server"]
}
}
}6a4239145db0OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add headless-ida-mcp-server -- uvx headless-ida-mcp-server
{
"mcpServers": {
"headless-ida-mcp-server": {
"command": "uvx",
"args": [
"headless-ida-mcp-server"
]
}
}
}Exposed tools (21)
14 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
convert_number | read | Convert a number to a different representation |
decompile_checked | read | Decompile a function at the given address |
decompile_function | read | Decompile a function at the given address |
disassemble_function | read | Disassemble a function at the given address |
get_current_address | read | Get the current address |
get_current_function | read | Get the current function |
get_entry_points | read | Get all entry points of the binary |
get_function | read | Get a function by address |
get_function_by_address | read | Get a function by address |
get_function_by_name | read | Get a function by name |
get_xrefs_to | read | Get cross references to a given address |
list_functions | read | List all functions |
refresh_decompiler_ctext | read | Refresh the decompiler ctext for a given function |
refresh_decompiler_widget | read | Refresh the decompiler widget |
rename_function | write | Rename a function |
rename_local_variable | write | Rename a local variable in a function |
save_idb_file | write | Save the IDB file |
set_binary_path | write | Set the path to the binary file |
set_decompiler_comment | write | Set a comment for a given address in the function pseudocode |
set_disassembly_comment | write | Set a comment for a given address in the function disassembly |
set_function_prototype | write | Set a function |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
main
main
.env_example
Gates applied: no_behavioural_pass, no_license.
6a4239145db0full audit observations/trust-audit/mcp-server/cnitlrt__headless-ida.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 6a4239145db0 | SAFE | B | 89 | first audit |
Questions
What is the Headless Ida MCP server?
headless-ida-mcp-server
What tools does Headless Ida expose?
21 in total: 14 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Headless Ida safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Headless Ida need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (6a4239145db0), read on 2026-10-08. The repository is watched and re-audited when it changes.