IDABLOCK
A headless MCP server for IDA Pro and Ghidra
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A multi-backend reverse-engineering MCP server. Exposes binary analysis capabilities from IDA Pro and Ghidra over the Model Context Protocol, letting LLMs drive reverse-engineering tools directly. Supports multiple simultaneous databases through a supervisor/worker architecture.
Both backends are standalone servers, not plugins. They use headless APIs (idalib for IDA, pyghidra for Ghidra) to run analysis engines without a GUI.
Backends
Both backends share a common tool interface — core analysis tools use the same names, parameters, and response shapes — so LLM workflows are portable across backends. Each backend also has tools for platform-specific features (e.g. IDA: file region mapping, executable rebuilding, IDC evaluation, IDAPython scripting; Ghidra: Function ID analysis, data type archives).
Requirements
- Python 3.12+
- uv package manager (recommended) or pip
- macOS, Windows, or Linux
- At least one supported backend installed on the same machine
Installation
Install individual backend packages directly, or install re-mcp and select a backend with --backend:
# Individual backend packages (each provides its own CLI) uv tool install re-mcp-ida uv tool install re-mcp-ghidra # Or install the core package and use --backend to select uv tool install re-mcp --with re-mcp-ida --with re-mcp-ghidra
With pip:
pip install re-mcp-ida # IDA only pip install re-mcp-ghidra # Ghidra only p
a550093b25f1OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add re-mcp -- uvx re-mcp
{
"mcpServers": {
"re-mcp": {
"command": "uvx",
"args": [
"re-mcp"
]
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
close_database | read | Close the currently open database. |
convert_number | read | Convert a number between hex, decimal, octal, and binary representations. |
open_database | read | Open a binary for analysis with Ghidra. |
Trust audit
BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (14)
exec(bytecode, glb)
exec(code, exec_globals)
return __import__(name, globals, locals, fromlist, level)
mod = importlib.import_module(f"re_mcp_ghidra.tools.{module_name}")mod = importlib.import_module(f"re_mcp_ida.tools.{module_name}").pre-commit-config.yaml
LICENSES/Apache-2.0.txt
LICENSES/MIT.txt
"url": "http://127.0.0.1:<port>/mcp",
ResourceContent(base64.b64decode(item.blob), mime_type=item.mimeType)
raw = bytes.fromhex(data)
new_bytes = bytes.fromhex(cleaned)
search_bytes = bytes.fromhex(clean)
raw = bytes.fromhex(data)
Gates applied: no_behavioural_pass.
a550093b25f1full audit observations/trust-audit/mcp-server/jtsylve__ida-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a550093b25f1 | BLOCK | D | 65 | first audit |
Questions
What is the IDA MCP server?
A headless MCP server for IDA Pro and Ghidra
What tools does IDA expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is IDA safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does IDA need?
No credential environment variables were found in its source, so it appears to need none.
How does IDA run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as re-mcp.
How current is this page?
The grade is for one exact copy of the source (a550093b25f1), read on 2026-10-08. The repository is watched and re-audited when it changes.