Atlas / MCP servers / smadi0x86 / GDB

GDBSAFE

mcp/smadi0x86/gdb

Multi Debugger MCP server that enables LLMs to interact with GDB and LLDB for binary debugging and analysis.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
GPL-3.0
Stars
74
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/smadi0x86/MDB-MCP/actions/workflows/ci.yml)

An MCP server that gives your AI assistant a real debugger. It drives GDB or LLDB, so the assistant can set breakpoints, run your program, read memory and walk the stack the same way you would.

Install

You need uv and at least one debugger:

# Debian / Ubuntu
sudo apt install gdb lldb python3-lldb

# macOS (LLDB ships with the Xcode command line tools)
xcode-select --install

Then add the server to your client. For Claude Code:

claude mcp add mdb -- uvx --from git+https://github.com/smadi0x86/MDB-MCP mdb-mcp

For Claude Desktop, Cursor or Windsurf:

{
"mcpServers": {
"mdb": {
"command": "uvx",
"args": ["--from", "git+https://github.com/smadi0x86/MDB-MCP", "mdb-mcp"]
}
}
}

VS Code takes the same entry under "servers" in .vscode/mcp.json, with "type": "stdio" added. On Windows with WSL, set "command": "wsl" and put the full path to uvx at the start of args.

Tools

debugger_status      which debuggers are usable, and the open sessions
debugger_start       start a gdb or lldb session, optionally loading a program
debugger_command     run any gdb or lldb command
debugger_interrupt   pause a running program, like Ctrl-C
debugger_terminate   kill the program and close the session

Everything else is a normal debugger command, so break main, bt, x/16gx $sp and frame variable all work. Commands that resume the program wait for it to stop (10 seconds by default, adjustable per call). If it is still running after that, the assistant can interrupt it or keep waiting.

GDB is the default on Linux and LLDB on macOS. Either can be picked explicitly. GDB loads your ~/.gdbinit, so p

Read from source at commit 5c31dfb3c6acOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mdb-mcp -- uvx mdb-mcp
claude-desktop
{
  "mcpServers": {
    "mdb-mcp": {
      "command": "uvx",
      "args": [
        "mdb-mcp"
      ]
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
debugger_interruptreadPause a running target (like Ctrl-C) and show where it stopped.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 5c31dfb3c6acfull audit observations/trust-audit/mcp-server/smadi0x86__gdb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-085c31dfb3c6acSAFEB89first audit
06

Questions

What is the GDB MCP server?

Multi Debugger MCP server that enables LLMs to interact with GDB and LLDB for binary debugging and analysis.

What tools does GDB expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is GDB safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does GDB need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (5c31dfb3c6ac), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement