Atlas / MCP servers / stass / Lldb

LldbSAFE

mcp/stass/lldb

LLDB MCP server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
28 19r · 6w · 3d
Transport
—
License
BSD-2-Clause
Stars
114
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

See it in acton here, automatically debugging a buffer overflow: https://x.com/full_duplex/status/1904770477698277847

Overview

LLDB-MCP is a tool that integrates the LLDB debugger with Claude's Model Context Protocol (MCP). This integration allows Claude to start, control, and interact with LLDB debugging sessions directly, enabling AI-assisted debugging workflows.

The tool provides a comprehensive set of commands for working with LLDB, including:

  • Starting and managing LLDB sessions
  • Loading programs for debugging
  • Setting breakpoints and watchpoints
  • Controlling program execution
  • Examining memory, registers, and variables
  • Analyzing stack traces and program state

Features

  • Create and manage multiple LLDB debugging sessions
  • Load executables and attach to running processes
  • Load core dump files for post-mortem analysis
  • Execute arbitrary LLDB commands
  • Fine-grained control over program execution
  • Memory examination and disassembly
  • Thread and stack frame inspection

Installation

  1. Clone the repository:
git clone https://github.com/stass/lldb-mcp.git
cd lldb-mcp
  1. Install dependencies:
pip install mcp
  1. Configure Claude to use the LLDB-MCP server:
  2. Open the Claude desktop app configuration
  3. Add the following to your MCP configuration:
"mcpServers": {
"lldb-mcp": {
"command": "python3",
"args": ["/path/to/lldb-mcp/lldb_mcp.py"],
"disabled": false
}
}

Usage

Once installed and configured, you can interact with LLDB through Claude using natural language.

Basic Workflow

  1. Start a new LLDB session
  2. Load a program
  3. Set breakpoints
  4. Run the program
  5. Inspect variables and memory
  6. Control execution (continue, step, next, etc.)
  7. Terminate the session when done

Example Commands

Here are some examples of how to interact with LLDB-MCP through Claude:

  • "Start a new LLDB sessi
Read from source at commit 7646f773b6a7OBSERVED · 2026-10-07
02

Exposed tools (28)

19 read · 6 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
lldb_attachreadAttach to a running process
lldb_backtracereadShow call stack
lldb_breakpoint_deletedestructiveDelete a breakpoint
lldb_breakpoint_listreadList all breakpoints
lldb_commandwriteExecute an LLDB command
lldb_continuereadContinue program execution
lldb_disassemblereadDisassemble code
lldb_examinereadExamine memory
lldb_expressionreadEvaluate an expression in the current frame
lldb_finishwriteExecute until the current function returns
lldb_frame_inforeadGet detailed information about a stack frame
lldb_helpreadGet help for LLDB commands
lldb_info_registersreadDisplay registers
lldb_killdestructiveKill the running process
lldb_list_sessionsreadList all active LLDB sessions
lldb_loadreadLoad a program into LLDB
lldb_load_corereadLoad a core dump file
lldb_nextreadStep over function calls
lldb_printreadPrint value of expression
lldb_process_inforeadGet information about the current process
lldb_runwriteRun the loaded program
lldb_set_breakpointwriteSet a breakpoint
lldb_startwriteStart a new LLDB session
lldb_stepreadStep program execution
lldb_terminatedestructiveTerminate an LLDB session
lldb_thread_listreadList all threads in the current process
lldb_thread_selectreadSelect a specific thread
lldb_watchpointwriteSet a watchpoint on a variable or memory address
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
lldb_breakpoint_delete, lldb_kill, lldb_terminate
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 7646f773b6a7full audit observations/trust-audit/mcp-server/stass__lldb.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-077646f773b6a7SAFEB89first audit
05

Questions

What is the Lldb MCP server?

LLDB MCP server

What tools does Lldb expose?

28 in total: 19 read-only, 6 that write, and 3 that can delete or overwrite (lldb_breakpoint_delete, lldb_kill, lldb_terminate). Every one is listed on this page with its risk.

Is Lldb safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Lldb need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (7646f773b6a7), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement