open-reverselabBLOCK
Open-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware research, with 100+ MCP tools and a 194-article runnable knowledge base.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Open-source AI-powered reverse-engineering platform for autonomous binary analysis, built for Claude Code, Codex, OpenCode and any MCP-compatible agent.
Ghidra · Frida · x64dbg · Rizin · PE · APK · Malware Analysis · CTF · Binary Analysis
An open-source reverse-engineering lab — executable knowledge base, 100+ MCP tools, Agent-native.
From an input signal to an evidence chain, every step is runnable.
[](https://discord.gg/But5j58J2f) [](https://deepwiki.com/LING71671/open-reverselab) [](LICENSE) [](#sponsors)
English · 简体中文
:handshake: Sponsored by Sentry
[Sentry](https://sentry.io) supports openreverselab with a sponsored account — error monitoring and performance tracing for the lab's toolchain.
Since Aug 2026 — see SPONSORS.md for the full sponsor list and how to become one.
What is ReverseLab
ReverseLab is an opinionated, runnable attack-knowledge base for reverse engineers, security researchers, CTF players, and AI Agents. Every article is structured as `Scenario → Input signal → Method → Attack chain → MCP tool mapping`, so a human or an Agent can pick up at any entry signal and walk the chain to evidence.
- 5 boards spanning web, mobile, Windo
83231f9154d0OBSERVED · 2026-09-19Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add reverselab-site -- npx -y [email protected]
{
"mcpServers": {
"reverselab-site": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (124)
94 read · 24 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
android_adb_connect | read | 连接 MuMu/Android ADB 端点;默认使用 MuMu 当前实例 serial。 |
android_adb_devices | read | 列出当前 adb devices -l。 |
android_app_baseline | read | 安装/启动 APK 或已装包,收集 Activity、APK 路径、package info、logcat、Frida 进程基线。 |
android_capture_screenshot | read | 抓取当前设备屏幕截图。 |
android_clear_logcat | destructive | 清空当前设备 logcat 缓冲区。 |
android_crypto_unpack_recipe | read | Android 解密/去壳 runtime recipe:Frida 抓 Cipher/key/iv/hash/dex loader/dlopen/mmap/RegisterNatives。 |
android_current_activity | read | 读取当前前台 Activity。 |
android_device_info | read | 读取 Android 设备的 model/sdk/abi/fingerprint/root 状态。 |
android_force_stop | destructive | 强制停止 Android app。 |
android_frida_ensure_server | read | 在 MuMu/Android root 设备上部署并启动 frida-server。 |
android_frida_processes | read | 通过桌面端 Frida 枚举 Android 设备进程。 |
android_frida_render_template | read | 渲染 Frida 模板为可直接运行的 JS 源码。 |
android_frida_run_script | write | 对指定进程/包运行一次性 Frida JS 脚本,收集 send() 消息并导出 JSON。 |
android_frida_status | read | 检查 frida-server 进程和桌面端 Frida 是否能枚举该设备。 |
android_frida_template_library | read | 列出可直接复用的 Frida JS 模板。 |
android_http_observation_recipe | read | 对已登录/已安装 Android 包做 HTTP/WebView/OkHttp 运行时观察,输出 Frida + logcat 证据汇总。 |
android_install_apk | write | 通过 adb install 把 APK 装进 MuMu/Android 设备。 |
android_list_packages | read | 列出 Android 包名,可按 query 过滤。 |
android_logcat_dump | read | 导出当前设备 logcat 到 exports\\android。 |
android_mumu_instance_info | read | 读取 MuMu 当前实例状态、候选 serial 和 adb 可达性。 |
android_package_fs_recipe | read | 按包名取证私有目录,列结构并按需回拉 shared_prefs/databases/files 归档。 |
android_package_info | read | 导出 dumpsys package 结果,便于分析权限、组件和安装状态。 |
android_package_paths | read | 读取包对应的 base.apk / split APK 路径。 |
android_pull_artifact_recipe | read | 按包名回拉 APK、截图、包信息、logcat,并写出一份 artifact manifest。 |
android_pull_file | read | 从 Android 设备拉取文件到 exports\\android。 |
android_pull_package_apk | read | 把设备上的包 APK 拉回 exports\\android\\packages。 |
android_push_file | write | 把本地文件推送到 Android 设备。 |
android_runtime_file_watch_recipe | read | 对包目录做运行前后快照,输出 shared_prefs/databases/files 的差异清单。 |
android_start_package | write | 启动 Android app;未指定 activity 时走 monkey 启动默认入口。 |
android_uninstall_package | destructive | 卸载 Android 包。 |
burp_launch | read | 生成或可选启动 Burp Suite。默认 launch=False,只返回命令,不弹 GUI。 |
burp_status | read | 检查 Burp Suite JAR、wrapper 和默认代理状态;不启动 GUI。 |
carve_payloads_from_dump | read | 从 dump/decrypted buffer 中自动 carve PE/DEX payload,并可导入 samples\\unpacked 供下一轮分析。 |
copy_sample | read | 复制 samples 下的样本到另一个 samples 位置。 |
copy_sample_to_patches | read | 复制样本到 patches 目录,原始样本不变,并写入 audit log。 |
ctf-24h-fleet | read | Multi-target Web CTF 24h loop orchestrator: normalize targets, shard into batches, run ctf-24h-round for each target, synthesize fleet status |
ctf-24h-round | read | Web CTF 24h loop 的单轮有状态 workflow:初始化/读取 manifest → 执行一轮推进 → 写 checkpoint → 返回 CONTINUE/DONE/EXHAUSTED |
ctf-asset-discovery | read | CTF digital asset discovery — crt.sh, DNS, WHOIS, HTTP probe, email security, search exposure, synthesis |
ctf-attack-api_business | read | API and business-logic worker: API discovery, IDOR/BAC, mass assignment, rate limit, payment, signature |
ctf-attack-auth | read | Auth worker: JWT, OAuth/OIDC, SAML, Host Header, LDAP, session/cookie trust boundaries |
ctf-attack-client | read | Client-side worker: XSS, CORS, CSP, CSRF, postMessage, WebSocket, Web Crypto, admin bot |
ctf-attack-cve_cloud_dos | read | CVE/cloud/supply/DoS/database worker: fingerprint-to-CVE, cloud metadata, CI/CD, Kubernetes, DoS, database chains |
ctf-attack-file_ssrf | write | File and SSRF worker: LFI/path traversal/upload/XXE/file wrappers/SSRF/open redirect |
ctf-attack-injection | read | Injection worker: SQLi/NoSQLi/SSTI/GraphQL/HPP/CRLF/prototype pollution/gRPC |
ctf-attack-recon | read | Recon worker: asset discovery, route discovery, JS/API mining, fingerprint, subdomain takeover |
ctf-attack-router | write | Route Web CTF signals/focus items to concrete attack workflows and run selected workers in parallel |
ctf-dos-assessment | read | DoS attack surface assessment — map all 13 DoS techniques to discovered targets, execute according to workflow parameters, rate exploitability |
ctf-full-pipeline | read | CTF 全链路评估流水线 — 资产发现 → DoS攻击面 → 全面漏洞挖掘 → 漏洞逐条验证 → 综合报告 |
ctf-vuln-discovery | read | CTF 全面漏洞挖掘 — 敏感文件/XSS/SQLi/路径穿越/CMS漏洞/认证缺陷/SSRF/WAF绕过,自适应目标技术栈 |
ctf-vuln-verify | read | CTF 漏洞逐条验证 — PoC/漏洞利用/盲注提取/默认口令/CVE确认,基于先前的发现列表 |
ctf_autopilot_round | read | 读取 Web CTF ai_manifest.json,执行一轮带 checkpoint 的 autopilot 计划/allowlist 动作。 |
ctf_new_challenge | read | 创建新的 CTF 题目 case 目录,从模板初始化。 |
ctf_save_request | write | 保存 raw HTTP request 到 exports/ctf-website/<case>/requests,供 Burp Repeater/Intruder 或 sqlmap -r 使用。 |
ctf_tool_status | read | 检查 CTF 工具安装状态。 |
delete_generated_artifact | destructive | 删除工具生成目录内的文件/目录;默认 dry_run=True。 |
delete_sample | destructive | 删除 samples 下样本;默认 dry_run=True。 |
die_scan | read | 使用 DiE/diec 扫描文件类型、编译器、packer/signature。默认 JSON 输出。 |
extract_frida_buffers | read | 从 Frida JSON 的 data_hex 消息中落盘二进制 buffer,并可自动 carve PE/DEX payload。 |
extract_iocs_from_summary | read | 从 Ghidra summary、triage 字符串和分析笔记中提取 IOC 与行为线索,写入 exports\\iocs。 |
generate_patch_report | write | 从 mutation audit log 生成 Markdown patch report。 |
ghidra_headless_analyze | read | 调用 Ghidra analyzeHeadless 导入并自动分析样本,导出 JSON 摘要;不执行样本。 |
ghidra_summary_call_focus | read | 基于 Ghidra xrefs/calls/decompile/imports/strings 给出函数阅读优先级;兼容 legacy summary。 |
ghidra_summary_function_detail | read | 按地址或函数名读取单个 Ghidra 函数的 callers/callees/import_refs/string_refs/decompile 证据。 |
ghidra_summary_functions | read | 从已导出的 Ghidra summary 中按函数名、signature 或地址过滤 functions。 |
ghidra_summary_imports | read | 从已导出的 Ghidra summary 中按 API 名、namespace/library、引用数过滤 imports。 |
ghidra_summary_list | read | 列出 exports\\windows\\ghidra 下已导出的 Ghidra summary JSON。 |
ghidra_summary_overview | read | 读取 Ghidra summary 的总体信息,不返回完整 functions/imports/strings。 |
ghidra_summary_strings | read | 从已导出的 Ghidra summary 中按字符串内容、地址、最小长度过滤 strings。 |
hash_file | read | 计算文件 MD5/SHA1/SHA256 和大小。 |
http_probe | read | 对目标 URL 发起 GET 探测,收集 header/body/cookie/指纹。 |
import_sample | write | 导入文件到 samples,可选 move;适合把外部样本纳入工作台。 |
kb_catalog | read | 列出知识库所有板块、分类、条目数和文件数。board 可选: ctf-website|apk-reverse|pe-reverse,不传则列出全部板块。 |
kb_read_file | read | 读取知识库技术文件内容。自动检测板块或通过 board 参数指定。路径格式如 |
kb_router | read | 按攻击信号搜索知识库(支持所有板块),返回匹配的技术文件和路径。board 可选: ctf-website|apk-reverse|pe-reverse,不传则全部搜索。 |
list_generated_artifacts | read | 列出 exports/patches/projects/reports 中的工具生成物。 |
list_samples | read | 列出 samples 下样本,可按子目录过滤。 |
make_crypto_replay_scaffold | read | 从 Frida crypto 证据生成可运行的 Python 解密/Hash/HMAC 复现脚本骨架。 |
make_pe_crypto_unpack_plan | read | 生成 PE 解密/去壳动态分析包:x64dbg 断点脚本、Windows Frida hook、重点函数队列和 JSON plan。 |
make_procmon_filters | read | 根据样本导入表和 Ghidra summary 生成 Procmon 过滤计划,写入 scripts\\procmon。 |
make_sigma_stub | read | 根据样本、IOC 结果和可选 summary 生成可继续精修的 Sigma 草案,写入 exports\\sigma。 |
make_x64dbg_breakpoint_script | read | 根据 triage/Ghidra summary 生成 x64dbg 断点脚本,写入 scripts\\debug。 |
make_yara_stub | read | 根据样本、Ghidra summary 和 IOC 产物生成可继续精修的 YARA 草案,写入 exports\\yara。 |
mcp_update_audit | write | 审计工作区/全局 MCP 配置中的本地 Git、npm、PyPI/uvx 工具是否有上游更新或弃用风险。 |
move_sample | write | 移动或整理 samples 下的样本。 |
mutation_audit_tail | read | 读取 mutation audit log 尾部记录。 |
parse_android_crypto_unpack_result | read | 解析 android_crypto_unpack_recipe/Frida JSON,提取 key/iv、crypto op、动态 dex、native loader、mmap/mprotect、RegisterNatives 证据。 |
patch_bytes | write | 复制输入文件到 patches 后修改指定 offset 的字节;不原地修改样本。 |
patch_pattern | write | 按十六进制 pattern 定位后 patch 副本字节;pattern 支持 ?? 通配。 |
patch_pe_bytes | write | 按 PE file offset/RVA/VA 定位后 patch 副本字节;不原地修改样本。 |
pe_address_to_offset | read | 将 PE 的 file offset/RVA/VA 映射为文件偏移。 |
postprocess_frida_crypto_result | read | 对 Frida crypto/unpack JSON 一键执行 parse、solve、replay scaffold、buffer extract/carve,并输出总 manifest。 |
procmon_export_csv | read | 将 exports\\procmon 下的 PML 导出为 CSV,可选加载 Procmon 配置并应用当前过滤器。 |
procmon_start_capture | write | 启动 Procmon64 capture,backing file 默认写入 exports\\procmon。 |
procmon_stop_capture | write | 停止 Procmon capture。 |
project_skills_status | read | 查看项目级 skills/MCP 安装状态和推荐安装命令。 |
python_re_tool_install | write | 按 allowlist 安装 Python 逆向库,例如 lief、frida、angr。 |
python_re_tool_status | read | 检查 LIEF/Frida/angr/capstone/keystone 等 Python 逆向库是否已安装。 |
python_re_tool_version | read | 查询指定 Python 逆向库的版本和模块路径。 |
quarantine_sample | read | 把 samples 下样本移入 samples\\_quarantine。 |
refine_ioc_sources | read | 将 IOC 条目按 static_confirmed / mixed / note_only 分层,便于后续 YARA / Sigma 精修。 |
rename_sample | write | 重命名 samples 下的样本文件。 |
rizin_assemble_bytes | read | 调用 rz-asm 把汇编文本转成机器码。 |
rizin_assemble_patch | write | 先用 rz-asm 汇编,再对 patches 副本做 patch。 |
rizin_bin_info | read | 使用 rz-bin -j -I 输出二进制基础信息。 |
rizin_imports | read | 使用 rz-bin -j -i 输出导入表,可限制返回数量。 |
rizin_sections | read | 使用 rz-bin -j -S 输出节区信息。 |
rizin_strings | read | 使用 rz-bin -zz 输出 raw strings 文本行,可限制返回数量。 |
rizin_write_bytes | write | 使用 Rizin raw write 在 patches 副本上写入十六进制字节。 |
run_ctf_tool | write | 运行 CTF 工具。tool: sqlmap/dirsearch/jwt_tool/tplmap。args: 命令行参数。 |
run_sqlmap_request | write | 用 sqlmap -r 运行已保存的 raw HTTP request。 |
sample_autopilot_round | read | 从 battleplan manifest 自动规划/执行下一轮逆向动作:补 Ghidra、生成函数断点、行为断点、unpacking 断点和 Procmon 视图。 |
sample_full_workup | read | 一键自动逆向工作流:triage、可选 Ghidra、重点函数队列、x64dbg/Procmon 计划、IOC、YARA/Sigma 草案和总控 manifest。 |
search_pattern | read | 按十六进制 pattern 搜索文件,支持 ?? 通配。 |
solve_crypto_from_evidence | read | 从 Frida key/IV/input/output evidence 自动尝试常见解密/hash/HMAC,落盘命中结果并可继续 carve PE/DEX。 |
toolbox_launch | read | 启动 allowlist 中的 GUI/交互工具,可选打开目标文件;不提供任意 shell。 |
toolbox_list | read | 列出 ReverseLab allowlist 工具箱:DiE、Rizin/Cutter、Ghidra、PE-bear、Procmon、x64dbg。 |
toolbox_version | read | 对 allowlist 中支持安全版本探测的 CLI 工具执行版本查询。 |
triage_pe | read | 组合 hash、DiE、rz-bin info/sections/imports/strings,生成只读初筛结果。 |
triage_to_notes | read | 根据 triage 和可选的 Ghidra summary 生成分析笔记骨架,写入 notes\\*.md。 |
workspace_copy_artifact | read | 复制 notes/reports/scripts/exports/patches/projects 下的文件或目录。 |
workspace_delete_artifact | destructive | 删除 notes/reports/scripts/exports/patches/projects 下的文件或目录;默认 dry_run=True。 |
workspace_move_artifact | write | 移动或重命名 notes/reports/scripts/exports/patches/projects 下的文件或目录。 |
workspace_read_text | read | 读取 notes/reports/scripts/exports 下的文本文件内容,适合 AI 后续处理。 |
workspace_write_text | write | 在 notes/reports/scripts/exports 下创建或更新文本文件。 |
Trust audit
BLOCKgrade F · trust 28/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (18 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
'Check for: location.hash/search → innerHTML/document.write, eval() with user input, jQuery .html()/.append() without sanitation, postMessage without origin check.',
'http://169.254.169.254/',
'http://169.254.169.254/',
p.add_argument("--insecure", action="store_true", help="关闭 TLS 证书校验")JAILBREAK["Jailbreak<br/>ai-security"]
PROMPT_INJECT -->|system prompt leak| JAILBREAK
JAILBREAK -->|bypass restrictions| TOOL_ABUSE
GUARDRAIL_BYPASS -->|DAN/encoding| JAILBREAK
### 路径 6: AI/LLM 安全 (Endpoint→Prompt→Jailbreak→Tool Abuse→Data)
"log_inject": "PAID\n2024-01-01 00:00:00 [ADMIN] order_id=ALL status=refund",
choice = random.choice(list(combiners.keys()))
'http://127.0.0.1/',
'http://169.254.169.254/',
'http://127.0.0.1/',
'http://169.254.169.254/',
'http://100.100.100.200/',
"IsDebuggerPresent",
"IsDebuggerPresent",
<#
<#
<#
<#
输入: token = "header.payload.signature"
secret = "leaked_jwt_secret_key"
<a :href="home" style="display: inline-block; padding: 8px 20px; background: var(--rl-primary); color: #fff; border-radius: 10px; text-decoration: none">{{ homeLabel }}</a>Gates applied: instruction_override, no_behavioural_pass.
83231f9154d0full audit observations/trust-audit/mcp-server/ling71671__open-reverselab.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-19 | 83231f9154d0 | BLOCK | F | 28 | first audit |
Questions
What is the open-reverselab MCP server?
Open-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware research, with 100+ MCP tools and a 194-article runnable knowledge base.
What tools does open-reverselab expose?
124 in total: 94 read-only, 24 that write, and 6 that can delete or overwrite (android_clear_logcat, android_force_stop, android_uninstall_package, delete_generated_artifact, delete_sample). Every one is listed on this page with its risk.
Is open-reverselab safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (28/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does open-reverselab need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (83231f9154d0), read on 2026-09-19. The repository is watched and re-audited when it changes.