Ida Pro ServerBLOCK
A Model Context Protocol (MCP) server that enables AI assistants to interact with IDA Pro for reverse engineering and binary analysis tasks.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that enables AI assistants to interact with IDA Pro for reverse engineering and binary analysis tasks.
Overview
This project provides a bridge between AI assistants and IDA Pro, a popular disassembler and debugger used for reverse engineering software. It consists of three main components:
- IDA Pro Remote Control Plugin (
ida_remote_server.py): An IDA Pro plugin that creates an HTTP server to remotely control IDA Pro functions. - IDA Remote Client (
idaremoteclient.ts): A TypeScript client for interacting with the IDA Pro Remote Control Server. - MCP Server (
index.ts): A Model Context Protocol server that exposes IDA Pro functionality to AI assistants.
Features
- Execute Python scripts in IDA Pro from AI assistants
- Retrieve information about binaries:
- Strings
- Imports
- Exports
- Functions
- Advanced binary analysis capabilities:
- Search for immediate values in instructions
- Search for text strings in the binary
- Search for specific byte sequences
- Get disassembly for address ranges
- Automate IDA Pro operations through a standardized interface
- Secure communication between components
Prerequisites
- IDA Pro 8.3 or later
- Node.js 18 or later
- TypeScript
Example usage idaremoteserver.py
curl -X POST -H "Content-Type: application/json" -d '{"script":"print(\"Script initialization...\")"}' http://127.0.0.1:9045/api/execute
{"success": true, "output": "Script initialization...\n"}Example usage MCP Server
Installation
1. Install the IDA Pro Remote Control Plugin
- Copy
ida_remote_server.pyto your IDA Pro plugins directory: - Windows:
%PROGRAMFILES%\IDA Pro\plugins
-
ef81da426d71OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ida-server -- npx -y [email protected]
{
"mcpServers": {
"ida-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (12)
10 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_disassembly | read | Get disassembly for an address range |
get_exports | read | Get list of exports from the binary |
get_functions | read | Get list of functions from the binary |
get_strings | read | Get list of strings from the binary |
get_xrefs_from | read | Get cross-references from an address |
get_xrefs_to | read | Get cross-references to an address |
run_ida_command | write | Execute an IDA Pro Script (IdaPython, Version IDA 8.3) |
run_ida_command_filebased | write | (FOR IDE USAGE) Execute an IDA Pro Script (IdaPython, Version IDA 8.3) |
search_byte_sequence | read | Search for a byte sequence in the binary |
search_immediate_value | read | Search for immediate values in the binary |
search_in_names | read | Search for names/symbols in the binary |
search_text | read | Search for text in the binary |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
exec(script, exec_globals)
curl -X POST -H "Content-Type: application/json" -d '{"script":"print(\"Script initialization...\")"}' http://127.0.0.1:9045/api/execute@modelcontextprotocol/sdk, diff, glob, minimatch, mongodb, zod-to-json-schema, @types/diff, @types/minimatch
Gates applied: no_behavioural_pass.
ef81da426d71full audit observations/trust-audit/mcp-server/fdrechsler__ida-pro-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ef81da426d71 | BLOCK | D | 69 | first audit |
Questions
What is the Ida Pro Server MCP server?
A Model Context Protocol (MCP) server that enables AI assistants to interact with IDA Pro for reverse engineering and binary analysis tasks.
What tools does Ida Pro Server expose?
12 in total: 10 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ida Pro Server safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Ida Pro Server need?
No credential environment variables were found in its source, so it appears to need none.
How does Ida Pro Server run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as ida-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (ef81da426d71), read on 2026-10-07. The repository is watched and re-audited when it changes.