Atlas / MCP servers / signal-slot / Mcp-Gdb

Mcp-GdbBLOCK

mcp/signal-slot/mcp-gdb
Verdict
BLOCK
Grade
D
Trust score
65 /100
Exposed tools
19 13r · 5w · 1d
Transport
stdio
License
—
Stars
159
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/mcp-gdb) [](https://github.com/signal-slot/mcp-gdb/blob/main/LICENSE)

A Model Context Protocol (MCP) server that provides GDB debugging functionality for use with Claude or other AI assistants.

Features

  • Start and manage GDB debugging sessions
  • Load programs and core dumps for analysis
  • Set breakpoints, step through code, and examine memory
  • View call stacks, variables, and registers
  • View source code with VS Code integration
  • Execute arbitrary GDB commands

Installation

Claude Code

claude mcp add gdb -- npx -y mcp-gdb

Claude Desktop

Add the following to your Claude Desktop MCP configuration:

{
"mcpServers": {
"gdb": {
"command": "npx",
"args": ["-y", "mcp-gdb"]
}
}
}

Install from Source

git clone https://github.com/signal-slot/mcp-gdb.git
cd mcp-gdb
npm install
npm run build

Usage

Example Commands

Here are some examples of using the GDB MCP server through Claude:

Starting a GDB session

Use gdb_start to start a new debugging session

Loading a program

Use gdb_load to load /path/to/my/program with the sessionId that was returned from gdb_start

Setting a breakpoint

Use gdb_set_breakpoint to set a breakpoint at main in the active GDB session

Running the program

Use gdb_continue to start execution

Examining variables

Use gdb_print to evaluate the expression "my_variable" in the current context

Getting a backtrace

Use gdb_backtrace to see the current call stack

Terminating the session

Use gdb_terminate to end the debugging session

Supported GDB Commands

  • gdb_start: Start a new GDB session
  • gdb_load: Load a program into GDB
  • gdb_command: Execute an arbitrary GDB command
  • gdb_terminate: Terminate a GDB
Read from source at commit d219d597ecc4OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-gdb -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-gdb": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (19)

13 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
gdb_attachreadAttach to a running process
gdb_backtracereadShow call stack
gdb_commandwriteExecute a GDB command
gdb_continuereadContinue program execution
gdb_examinereadExamine memory
gdb_finishwriteExecute until the current function returns
gdb_info_registersreadDisplay registers
gdb_list_sessionsreadList all active GDB sessions
gdb_list_sourcereadList source code at current location or specified location, with VS Code integration
gdb_loadreadLoad a program into GDB
gdb_load_corereadLoad a core dump file
gdb_nextreadStep over function calls
gdb_printreadPrint value of expression
gdb_reverse_continuereadReverse continue program execution
gdb_set_breakpointwriteSet a breakpoint
gdb_startwriteStart a new GDB session
gdb_stepreadStep program execution
gdb_terminatedestructiveTerminate a GDB session
gdb_watchwriteSet a watchpoint on a memory address or expression
04

Trust audit

BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
install.sh:18
echo "On Ubuntu/Debian: sudo apt-get install gdb"
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
install.sh:19
echo "On Fedora/RHEL: sudo dnf install gdb"
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
install.sh:20
echo "On Arch Linux: sudo pacman -S gdb"
Why it matters. asks for elevated privileges
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
gdb_terminate
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, tsc-watch, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha d219d597ecc4full audit observations/trust-audit/mcp-server/signal-slot__mcp-gdb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d219d597ecc4BLOCKD65first audit
06

Questions

What tools does Mcp-Gdb expose?

19 in total: 13 read-only, 5 that write, and 1 that can delete or overwrite (gdb_terminate). Every one is listed on this page with its risk.

Is Mcp-Gdb safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (65/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mcp-Gdb need?

No credential environment variables were found in its source, so it appears to need none.

How does Mcp-Gdb run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-gdb at 0.1.3.

How current is this page?

The grade is for one exact copy of the source (d219d597ecc4), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement