Atlas / MCP servers / ling71671 / ReverseLab

ReverseLabBLOCK

mcp/ling71671/reverselab

Open-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware research, with 100+ MCP tools and a 194-article runnable knowledge base.

Verdict
BLOCK
Grade
F
Trust score
28 /100
Exposed tools
124 94r · 24w · 6d
Transport
—
License
GPL-3.0
Stars
1,182
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Open-source AI-powered reverse-engineering platform for autonomous binary analysis, built for Claude Code, Codex, OpenCode and any MCP-compatible agent.

Ghidra · Frida · x64dbg · Rizin · PE · APK · Malware Analysis · CTF · Binary Analysis

An open-source reverse-engineering lab — executable knowledge base, 100+ MCP tools, Agent-native.

From an input signal to an evidence chain, every step is runnable.

[](https://discord.gg/But5j58J2f) [](https://deepwiki.com/LING71671/open-reverselab) [](LICENSE) [](#sponsors)

English · 简体中文

:handshake: Sponsored by Sentry

[Sentry](https://sentry.io) supports openreverselab with a sponsored account — error monitoring and performance tracing for the lab's toolchain.

Since Aug 2026 — see SPONSORS.md for the full sponsor list and how to become one.

What is ReverseLab

ReverseLab is an opinionated, runnable attack-knowledge base for reverse engineers, security researchers, CTF players, and AI Agents. Every article is structured as `Scenario → Input signal → Method → Attack chain → MCP tool mapping`, so a human or an Agent can pick up at any entry signal and walk the chain to evidence.

  • 5 boards spanning web, mobile, Windo
Read from source at commit 83231f9154d0OBSERVED · 2026-09-26
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add reverselab-site -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "reverselab-site": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (124)

94 read · 24 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
android_adb_connectread连接 MuMu/Android ADB 端点;默认使用 MuMu 当前实例 serial。
android_adb_devicesread列出当前 adb devices -l。
android_app_baselineread安装/启动 APK 或已装包,收集 Activity、APK 路径、package info、logcat、Frida 进程基线。
android_capture_screenshotread抓取当前设备屏幕截图。
android_clear_logcatdestructive清空当前设备 logcat 缓冲区。
android_crypto_unpack_recipereadAndroid 解密/去壳 runtime recipe:Frida 抓 Cipher/key/iv/hash/dex loader/dlopen/mmap/RegisterNatives。
android_current_activityread读取当前前台 Activity。
android_device_inforead读取 Android 设备的 model/sdk/abi/fingerprint/root 状态。
android_force_stopdestructive强制停止 Android app。
android_frida_ensure_serverread在 MuMu/Android root 设备上部署并启动 frida-server。
android_frida_processesread通过桌面端 Frida 枚举 Android 设备进程。
android_frida_render_templateread渲染 Frida 模板为可直接运行的 JS 源码。
android_frida_run_scriptwrite对指定进程/包运行一次性 Frida JS 脚本,收集 send() 消息并导出 JSON。
android_frida_statusread检查 frida-server 进程和桌面端 Frida 是否能枚举该设备。
android_frida_template_libraryread列出可直接复用的 Frida JS 模板。
android_http_observation_reciperead对已登录/已安装 Android 包做 HTTP/WebView/OkHttp 运行时观察,输出 Frida + logcat 证据汇总。
android_install_apkwrite通过 adb install 把 APK 装进 MuMu/Android 设备。
android_list_packagesread列出 Android 包名,可按 query 过滤。
android_logcat_dumpread导出当前设备 logcat 到 exports\\android。
android_mumu_instance_inforead读取 MuMu 当前实例状态、候选 serial 和 adb 可达性。
android_package_fs_reciperead按包名取证私有目录,列结构并按需回拉 shared_prefs/databases/files 归档。
android_package_inforead导出 dumpsys package 结果,便于分析权限、组件和安装状态。
android_package_pathsread读取包对应的 base.apk / split APK 路径。
android_pull_artifact_reciperead按包名回拉 APK、截图、包信息、logcat,并写出一份 artifact manifest。
android_pull_fileread从 Android 设备拉取文件到 exports\\android。
android_pull_package_apkread把设备上的包 APK 拉回 exports\\android\\packages。
android_push_filewrite把本地文件推送到 Android 设备。
android_runtime_file_watch_reciperead对包目录做运行前后快照,输出 shared_prefs/databases/files 的差异清单。
android_start_packagewrite启动 Android app;未指定 activity 时走 monkey 启动默认入口。
android_uninstall_packagedestructive卸载 Android 包。
burp_launchread生成或可选启动 Burp Suite。默认 launch=False,只返回命令,不弹 GUI。
burp_statusread检查 Burp Suite JAR、wrapper 和默认代理状态;不启动 GUI。
carve_payloads_from_dumpread从 dump/decrypted buffer 中自动 carve PE/DEX payload,并可导入 samples\\unpacked 供下一轮分析。
copy_sampleread复制 samples 下的样本到另一个 samples 位置。
copy_sample_to_patchesread复制样本到 patches 目录,原始样本不变,并写入 audit log。
ctf-24h-fleetreadMulti-target Web CTF 24h loop orchestrator: normalize targets, shard into batches, run ctf-24h-round for each target, synthesize fleet status
ctf-24h-roundreadWeb CTF 24h loop 的单轮有状态 workflow:初始化/读取 manifest → 执行一轮推进 → 写 checkpoint → 返回 CONTINUE/DONE/EXHAUSTED
ctf-asset-discoveryreadCTF digital asset discovery — crt.sh, DNS, WHOIS, HTTP probe, email security, search exposure, synthesis
ctf-attack-api_businessreadAPI and business-logic worker: API discovery, IDOR/BAC, mass assignment, rate limit, payment, signature
ctf-attack-authreadAuth worker: JWT, OAuth/OIDC, SAML, Host Header, LDAP, session/cookie trust boundaries
ctf-attack-clientreadClient-side worker: XSS, CORS, CSP, CSRF, postMessage, WebSocket, Web Crypto, admin bot
ctf-attack-cve_cloud_dosreadCVE/cloud/supply/DoS/database worker: fingerprint-to-CVE, cloud metadata, CI/CD, Kubernetes, DoS, database chains
ctf-attack-file_ssrfwriteFile and SSRF worker: LFI/path traversal/upload/XXE/file wrappers/SSRF/open redirect
ctf-attack-injectionreadInjection worker: SQLi/NoSQLi/SSTI/GraphQL/HPP/CRLF/prototype pollution/gRPC
ctf-attack-reconreadRecon worker: asset discovery, route discovery, JS/API mining, fingerprint, subdomain takeover
ctf-attack-routerwriteRoute Web CTF signals/focus items to concrete attack workflows and run selected workers in parallel
ctf-dos-assessmentreadDoS attack surface assessment — map all 13 DoS techniques to discovered targets, execute according to workflow parameters, rate exploitability
ctf-full-pipelinereadCTF 全链路评估流水线 — 资产发现 → DoS攻击面 → 全面漏洞挖掘 → 漏洞逐条验证 → 综合报告
ctf-vuln-discoveryreadCTF 全面漏洞挖掘 — 敏感文件/XSS/SQLi/路径穿越/CMS漏洞/认证缺陷/SSRF/WAF绕过,自适应目标技术栈
ctf-vuln-verifyreadCTF 漏洞逐条验证 — PoC/漏洞利用/盲注提取/默认口令/CVE确认,基于先前的发现列表
ctf_autopilot_roundread读取 Web CTF ai_manifest.json,执行一轮带 checkpoint 的 autopilot 计划/allowlist 动作。
ctf_new_challengeread创建新的 CTF 题目 case 目录,从模板初始化。
ctf_save_requestwrite保存 raw HTTP request 到 exports/ctf-website/<case>/requests,供 Burp Repeater/Intruder 或 sqlmap -r 使用。
ctf_tool_statusread检查 CTF 工具安装状态。
delete_generated_artifactdestructive删除工具生成目录内的文件/目录;默认 dry_run=True。
delete_sampledestructive删除 samples 下样本;默认 dry_run=True。
die_scanread使用 DiE/diec 扫描文件类型、编译器、packer/signature。默认 JSON 输出。
extract_frida_buffersread从 Frida JSON 的 data_hex 消息中落盘二进制 buffer,并可自动 carve PE/DEX payload。
extract_iocs_from_summaryread从 Ghidra summary、triage 字符串和分析笔记中提取 IOC 与行为线索,写入 exports\\iocs。
generate_patch_reportwrite从 mutation audit log 生成 Markdown patch report。
ghidra_headless_analyzeread调用 Ghidra analyzeHeadless 导入并自动分析样本,导出 JSON 摘要;不执行样本。
ghidra_summary_call_focusread基于 Ghidra xrefs/calls/decompile/imports/strings 给出函数阅读优先级;兼容 legacy summary。
ghidra_summary_function_detailread按地址或函数名读取单个 Ghidra 函数的 callers/callees/import_refs/string_refs/decompile 证据。
ghidra_summary_functionsread从已导出的 Ghidra summary 中按函数名、signature 或地址过滤 functions。
ghidra_summary_importsread从已导出的 Ghidra summary 中按 API 名、namespace/library、引用数过滤 imports。
ghidra_summary_listread列出 exports\\windows\\ghidra 下已导出的 Ghidra summary JSON。
ghidra_summary_overviewread读取 Ghidra summary 的总体信息,不返回完整 functions/imports/strings。
ghidra_summary_stringsread从已导出的 Ghidra summary 中按字符串内容、地址、最小长度过滤 strings。
hash_fileread计算文件 MD5/SHA1/SHA256 和大小。
http_proberead对目标 URL 发起 GET 探测,收集 header/body/cookie/指纹。
import_samplewrite导入文件到 samples,可选 move;适合把外部样本纳入工作台。
kb_catalogread列出知识库所有板块、分类、条目数和文件数。board 可选: ctf-website|apk-reverse|pe-reverse,不传则列出全部板块。
kb_read_fileread读取知识库技术文件内容。自动检测板块或通过 board 参数指定。路径格式如
kb_routerread按攻击信号搜索知识库(支持所有板块),返回匹配的技术文件和路径。board 可选: ctf-website|apk-reverse|pe-reverse,不传则全部搜索。
list_generated_artifactsread列出 exports/patches/projects/reports 中的工具生成物。
list_samplesread列出 samples 下样本,可按子目录过滤。
make_crypto_replay_scaffoldread从 Frida crypto 证据生成可运行的 Python 解密/Hash/HMAC 复现脚本骨架。
make_pe_crypto_unpack_planread生成 PE 解密/去壳动态分析包:x64dbg 断点脚本、Windows Frida hook、重点函数队列和 JSON plan。
make_procmon_filtersread根据样本导入表和 Ghidra summary 生成 Procmon 过滤计划,写入 scripts\\procmon。
make_sigma_stubread根据样本、IOC 结果和可选 summary 生成可继续精修的 Sigma 草案,写入 exports\\sigma。
make_x64dbg_breakpoint_scriptread根据 triage/Ghidra summary 生成 x64dbg 断点脚本,写入 scripts\\debug。
make_yara_stubread根据样本、Ghidra summary 和 IOC 产物生成可继续精修的 YARA 草案,写入 exports\\yara。
mcp_update_auditwrite审计工作区/全局 MCP 配置中的本地 Git、npm、PyPI/uvx 工具是否有上游更新或弃用风险。
move_samplewrite移动或整理 samples 下的样本。
mutation_audit_tailread读取 mutation audit log 尾部记录。
parse_android_crypto_unpack_resultread解析 android_crypto_unpack_recipe/Frida JSON,提取 key/iv、crypto op、动态 dex、native loader、mmap/mprotect、RegisterNatives 证据。
patch_byteswrite复制输入文件到 patches 后修改指定 offset 的字节;不原地修改样本。
patch_patternwrite按十六进制 pattern 定位后 patch 副本字节;pattern 支持 ?? 通配。
patch_pe_byteswrite按 PE file offset/RVA/VA 定位后 patch 副本字节;不原地修改样本。
pe_address_to_offsetread将 PE 的 file offset/RVA/VA 映射为文件偏移。
postprocess_frida_crypto_resultread对 Frida crypto/unpack JSON 一键执行 parse、solve、replay scaffold、buffer extract/carve,并输出总 manifest。
procmon_export_csvread将 exports\\procmon 下的 PML 导出为 CSV,可选加载 Procmon 配置并应用当前过滤器。
procmon_start_capturewrite启动 Procmon64 capture,backing file 默认写入 exports\\procmon。
procmon_stop_capturewrite停止 Procmon capture。
project_skills_statusread查看项目级 skills/MCP 安装状态和推荐安装命令。
python_re_tool_installwrite按 allowlist 安装 Python 逆向库,例如 lief、frida、angr。
python_re_tool_statusread检查 LIEF/Frida/angr/capstone/keystone 等 Python 逆向库是否已安装。
python_re_tool_versionread查询指定 Python 逆向库的版本和模块路径。
quarantine_sampleread把 samples 下样本移入 samples\\_quarantine。
refine_ioc_sourcesread将 IOC 条目按 static_confirmed / mixed / note_only 分层,便于后续 YARA / Sigma 精修。
rename_samplewrite重命名 samples 下的样本文件。
rizin_assemble_bytesread调用 rz-asm 把汇编文本转成机器码。
rizin_assemble_patchwrite先用 rz-asm 汇编,再对 patches 副本做 patch。
rizin_bin_inforead使用 rz-bin -j -I 输出二进制基础信息。
rizin_importsread使用 rz-bin -j -i 输出导入表,可限制返回数量。
rizin_sectionsread使用 rz-bin -j -S 输出节区信息。
rizin_stringsread使用 rz-bin -zz 输出 raw strings 文本行,可限制返回数量。
rizin_write_byteswrite使用 Rizin raw write 在 patches 副本上写入十六进制字节。
run_ctf_toolwrite运行 CTF 工具。tool: sqlmap/dirsearch/jwt_tool/tplmap。args: 命令行参数。
run_sqlmap_requestwrite用 sqlmap -r 运行已保存的 raw HTTP request。
sample_autopilot_roundread从 battleplan manifest 自动规划/执行下一轮逆向动作:补 Ghidra、生成函数断点、行为断点、unpacking 断点和 Procmon 视图。
sample_full_workupread一键自动逆向工作流:triage、可选 Ghidra、重点函数队列、x64dbg/Procmon 计划、IOC、YARA/Sigma 草案和总控 manifest。
search_patternread按十六进制 pattern 搜索文件,支持 ?? 通配。
solve_crypto_from_evidenceread从 Frida key/IV/input/output evidence 自动尝试常见解密/hash/HMAC,落盘命中结果并可继续 carve PE/DEX。
toolbox_launchread启动 allowlist 中的 GUI/交互工具,可选打开目标文件;不提供任意 shell。
toolbox_listread列出 ReverseLab allowlist 工具箱:DiE、Rizin/Cutter、Ghidra、PE-bear、Procmon、x64dbg。
toolbox_versionread对 allowlist 中支持安全版本探测的 CLI 工具执行版本查询。
triage_peread组合 hash、DiE、rz-bin info/sections/imports/strings,生成只读初筛结果。
triage_to_notesread根据 triage 和可选的 Ghidra summary 生成分析笔记骨架,写入 notes\\*.md。
workspace_copy_artifactread复制 notes/reports/scripts/exports/patches/projects 下的文件或目录。
workspace_delete_artifactdestructive删除 notes/reports/scripts/exports/patches/projects 下的文件或目录;默认 dry_run=True。
workspace_move_artifactwrite移动或重命名 notes/reports/scripts/exports/patches/projects 下的文件或目录。
workspace_read_textread读取 notes/reports/scripts/exports 下的文本文件内容,适合 AI 后续处理。
workspace_write_textwrite在 notes/reports/scripts/exports 下创建或更新文本文件。
04

Trust audit

BLOCKgrade F · trust 28/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (18 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
.claude/workflows/ctf-vuln-discovery.js:158
'Check for: location.hash/search → innerHTML/document.write, eval() with user input, jQuery .html()/.append() without sanitation, postMessage without origin check.',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
.claude/workflows/ctf-attack-file_ssrf.js:21
'http://169.254.169.254/',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
.claude/workflows/ctf-vuln-discovery.js:31
'http://169.254.169.254/',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
scripts/ctf-website/payment_lost_update_probe.py:45
p.add_argument("--insecure", action="store_true", help="关闭 TLS 证书校验")
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
kb/general/techniques/attack-network.md:95
JAILBREAK["Jailbreak<br/>ai-security"]
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
kb/general/techniques/attack-network.md:224
PROMPT_INJECT -->|system prompt leak| JAILBREAK
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
kb/general/techniques/attack-network.md:225
JAILBREAK -->|bypass restrictions| TOOL_ABUSE
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
kb/general/techniques/attack-network.md:229
GUARDRAIL_BYPASS -->|DAN/encoding| JAILBREAK
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
kb/general/techniques/attack-network.md:296
### 路径 6: AI/LLM 安全 (Endpoint→Prompt→Jailbreak→Tool Abuse→Data)
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
kb/ctf-website/techniques/12-payment/payment-bypass.md:1084
"log_inject": "PAID\n2024-01-01 00:00:00 [ADMIN] order_id=ALL status=refund",
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
scripts/windows/av-evasion/shellcode-obfuscate.py:87
choice = random.choice(list(combiners.keys()))
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/workflows/ctf-attack-file_ssrf.js:19
'http://127.0.0.1/',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/workflows/ctf-attack-file_ssrf.js:21
'http://169.254.169.254/',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/workflows/ctf-vuln-discovery.js:29
'http://127.0.0.1/',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/workflows/ctf-vuln-discovery.js:31
'http://169.254.169.254/',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/workflows/ctf-vuln-discovery.js:32
'http://100.100.100.200/',
MEDIUMObfuscation / stealth · obf.anti_debug · CWE-506, CWE-94
tools/skills/mcp/ReverseLabToolsMCP/reverselab_mcp/tools/debug_scripts.py:115
"IsDebuggerPresent",
MEDIUMObfuscation / stealth · obf.anti_debug · CWE-506, CWE-94
tools/skills/mcp/ReverseLabToolsMCP/reverselab_mcp/tools/ghidra_summary.py:267
"IsDebuggerPresent",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/ctf-website/ctf_toolcheck.ps1:1
<#
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/misc/check_mcp.ps1:1
<#
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/misc/install_tools.ps1:1
<#
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/misc/start_here.ps1:1
<#
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
kb/ctf-website/techniques/02-auth/jwt/03-weak-key-bruteforce.md:112
输入: token = "header.payload.signature"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
kb/ctf-website/techniques/09-cve/04-nezha-path-traversal-jwt.md:62
secret = "leaked_jwt_secret_key"
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
site/404.md:25
<a :href="home" style="display: inline-block; padding: 8px 20px; background: var(--rl-primary); color: #fff; border-radius: 10px; text-decoration: none">{{ homeLabel }}</a>

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha 83231f9154d0full audit observations/trust-audit/mcp-server/ling71671__reverselab.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2683231f9154d0BLOCKF28first audit
06

Questions

What is the ReverseLab MCP server?

Open-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware research, with 100+ MCP tools and a 194-article runnable knowledge base.

What tools does ReverseLab expose?

124 in total: 94 read-only, 24 that write, and 6 that can delete or overwrite (android_clear_logcat, android_force_stop, android_uninstall_package, delete_generated_artifact, delete_sample). Every one is listed on this page with its risk.

Is ReverseLab safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (28/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ReverseLab need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (83231f9154d0), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement