Atlas / MCP servers / symgraph / BinAssist

BinAssistCAUTION

mcp/symgraph/binassist-2

Binary Ninja plugin to provide MCP functionality.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
47 35r · 9w · 3d
Transport
streamable-http
License
MIT
Stars
51
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Comprehensive Model Context Protocol (MCP) server for Binary Ninja with AI-powered reverse engineering capabilities

Summary

BinAssistMCP is a powerful bridge between Binary Ninja and Large Language Models (LLMs) like Claude, providing comprehensive reverse engineering tools through the Model Context Protocol (MCP). It enables AI-assisted binary analysis by exposing Binary Ninja's advanced capabilities through Server-Sent Events (SSE) and Streamable HTTP transports.

Key Features

  • MCP 2025-11-25 Compliant: Full support for tool annotations, resources, and prompts
  • Dual Transport Support: SSE (Server-Sent Events) and Streamable HTTP transports
  • 45 Consolidated Tools: Streamlined Binary Ninja API wrapper with unified tool design
  • 8 MCP Resources: Browsable, cacheable binary metadata
  • 7 Guided Prompts: Pre-built workflows for common reverse engineering tasks
  • Multi-Binary Sessions: Concurrent analysis of multiple binaries with intelligent context management
  • Context-Rich Code Output: Function signatures and Binary Ninja comments are embedded in code results
  • Analysis-Safe Queries: Code retrieval uses already-loaded IL and never forces global reanalysis
  • Session-Independent Discovery: Direct tool calls discover open Binary Ninja views without requiring a prior listing call
  • Nonblocking Binary Opens: Large binaries and .bndb databases open asynchronously with pollable operation status
  • Thread-Safe: RLock-based synchronization for concurrent access
  • Auto-Integration: Seamless Binary Ninja plugin with automatic startup capabilities

Use Cases

  • AI-Assisted Reverse Engineering: Leverage LLMs for intelligent code analysis and documentation
  • Protocol Analysis: Trace network data flows and reconstruct protocol structures
  • Vulnerability Research: Systematic security audits with guided workflows
  • Automated Binary Analysis: Script complex analysis workflows with natura
Read from source at commit a4c9c2c556eaOBSERVED · 2026-10-08
02

Exposed tools (47)

35 read · 9 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_functionreadPerform comprehensive analysis of a function
assemble_codewriteAssemble instruction text at an address and optionally patch it.
batch_renamewriteBatch rename multiple symbols.
bookmarksdestructiveManage bookmarks: list, set, or remove.
cancel_taskreadCancel a running async task.
commentsdestructiveUnified comment management (set/get/list/remove comments).
create_data_varwriteCreate a data variable at the specified address
export_programreadExport the current binary or Binary Ninja database to disk.
get_basic_blocksreadGet basic blocks for a function (CFG).
get_binary_inforeadGet status information for a specific binary
get_binary_statusreadCheck a queued open operation or a loaded binary.
get_classesreadGet all classes/structs/types in the binary
get_codereadGet function code in specified format (unified tool).
get_current_addressreadGet the current address/offset in the binary view
get_current_functionreadGet the current function (function containing the current address)
get_data_atreadGet data at a specific address
get_data_varsreadGet all data variables in the binary
get_entry_pointsreadGet entry points of the binary.
get_exportsreadGet exported symbols
get_function_analysis_limitsreadGet the effective per-function analysis limit overrides plus current IL availability.
get_function_low_level_ilreadGet Low Level IL for a function.
get_function_signaturereadGet the native BinAssist byte signature for a function.
get_function_stack_layoutreadGet stack frame layout for a function.
get_function_statisticsreadGet comprehensive statistics about all functions in the binary
get_functionsreadGet list of all functions in the binary
get_functions_advancedreadGet functions with advanced filtering and search capabilities
get_importsreadGet imported symbols grouped by module
get_namespacesreadGet all namespaces in the binary
get_sectionsreadGet binary sections
get_segmentsreadGet memory segments
get_stringsreadGet strings found in the binary with pagination
get_task_statusreadGet status of an async task.
list_binariesreadList all currently loaded binary names with auto-refresh from Binary Ninja
list_tasksreadList all async tasks, optionally filtered by status.
open_binaryreadOpen a binary file from disk and load it into Binary Ninja for analysis.
patch_byteswritePatch raw bytes in the binary at a given address.
reanalyze_functiondestructiveForce a targeted reanalysis of one function, optionally overriding its
rename_symbolwriteRename a function or data variable
search_bytesreadSearch for byte patterns in the binary.
search_functions_advancedreadAdvanced function search with multiple search targets
search_functions_by_namereadSearch functions by name substring
search_stringsreadSearch for strings matching a pattern with pagination.
start_taskwriteStart an asynchronous background task.
typeswriteUnified type management (list/info/create/create_class/create_enum/create_typedef/add_member).
update_analysis_and_waitwriteUpdate binary analysis and wait for completion
variableswriteUnified variable management (list/create/rename/set_type) for local and global variables.
xrefsreadUnified cross-reference tool (xrefs + call graph).
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bookmarks, comments, reanalyze_function
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/binassist_mcp/tools.py:205
return builtins.bytes.fromhex(normalized)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/binassist_mcp/tools.py:2938
search_bytes = bytes.fromhex(clean_pattern)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
anyio, hypercorn, pydantic, pydantic-settings
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha a4c9c2c556eafull audit observations/trust-audit/mcp-server/symgraph__binassist-2.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a4c9c2c556eaCAUTIONB89first audit
05

Questions

What is the BinAssist MCP server?

Binary Ninja plugin to provide MCP functionality.

What tools does BinAssist expose?

47 in total: 35 read-only, 9 that write, and 3 that can delete or overwrite (bookmarks, comments, reanalyze_function). Every one is listed on this page with its risk.

Is BinAssist safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does BinAssist need?

No credential environment variables were found in its source, so it appears to need none.

How does BinAssist run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (a4c9c2c556ea), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement