BinAssistCAUTION
Binary Ninja plugin to provide MCP functionality.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Comprehensive Model Context Protocol (MCP) server for Binary Ninja with AI-powered reverse engineering capabilities
Summary
BinAssistMCP is a powerful bridge between Binary Ninja and Large Language Models (LLMs) like Claude, providing comprehensive reverse engineering tools through the Model Context Protocol (MCP). It enables AI-assisted binary analysis by exposing Binary Ninja's advanced capabilities through Server-Sent Events (SSE) and Streamable HTTP transports.
Key Features
- MCP 2025-11-25 Compliant: Full support for tool annotations, resources, and prompts
- Dual Transport Support: SSE (Server-Sent Events) and Streamable HTTP transports
- 45 Consolidated Tools: Streamlined Binary Ninja API wrapper with unified tool design
- 8 MCP Resources: Browsable, cacheable binary metadata
- 7 Guided Prompts: Pre-built workflows for common reverse engineering tasks
- Multi-Binary Sessions: Concurrent analysis of multiple binaries with intelligent context management
- Context-Rich Code Output: Function signatures and Binary Ninja comments are embedded in code results
- Analysis-Safe Queries: Code retrieval uses already-loaded IL and never forces global reanalysis
- Session-Independent Discovery: Direct tool calls discover open Binary Ninja views without requiring a prior listing call
- Nonblocking Binary Opens: Large binaries and
.bndbdatabases open asynchronously with pollable operation status - Thread-Safe: RLock-based synchronization for concurrent access
- Auto-Integration: Seamless Binary Ninja plugin with automatic startup capabilities
Use Cases
- AI-Assisted Reverse Engineering: Leverage LLMs for intelligent code analysis and documentation
- Protocol Analysis: Trace network data flows and reconstruct protocol structures
- Vulnerability Research: Systematic security audits with guided workflows
- Automated Binary Analysis: Script complex analysis workflows with natura
a4c9c2c556eaOBSERVED · 2026-10-08Exposed tools (47)
35 read · 9 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_function | read | Perform comprehensive analysis of a function |
assemble_code | write | Assemble instruction text at an address and optionally patch it. |
batch_rename | write | Batch rename multiple symbols. |
bookmarks | destructive | Manage bookmarks: list, set, or remove. |
cancel_task | read | Cancel a running async task. |
comments | destructive | Unified comment management (set/get/list/remove comments). |
create_data_var | write | Create a data variable at the specified address |
export_program | read | Export the current binary or Binary Ninja database to disk. |
get_basic_blocks | read | Get basic blocks for a function (CFG). |
get_binary_info | read | Get status information for a specific binary |
get_binary_status | read | Check a queued open operation or a loaded binary. |
get_classes | read | Get all classes/structs/types in the binary |
get_code | read | Get function code in specified format (unified tool). |
get_current_address | read | Get the current address/offset in the binary view |
get_current_function | read | Get the current function (function containing the current address) |
get_data_at | read | Get data at a specific address |
get_data_vars | read | Get all data variables in the binary |
get_entry_points | read | Get entry points of the binary. |
get_exports | read | Get exported symbols |
get_function_analysis_limits | read | Get the effective per-function analysis limit overrides plus current IL availability. |
get_function_low_level_il | read | Get Low Level IL for a function. |
get_function_signature | read | Get the native BinAssist byte signature for a function. |
get_function_stack_layout | read | Get stack frame layout for a function. |
get_function_statistics | read | Get comprehensive statistics about all functions in the binary |
get_functions | read | Get list of all functions in the binary |
get_functions_advanced | read | Get functions with advanced filtering and search capabilities |
get_imports | read | Get imported symbols grouped by module |
get_namespaces | read | Get all namespaces in the binary |
get_sections | read | Get binary sections |
get_segments | read | Get memory segments |
get_strings | read | Get strings found in the binary with pagination |
get_task_status | read | Get status of an async task. |
list_binaries | read | List all currently loaded binary names with auto-refresh from Binary Ninja |
list_tasks | read | List all async tasks, optionally filtered by status. |
open_binary | read | Open a binary file from disk and load it into Binary Ninja for analysis. |
patch_bytes | write | Patch raw bytes in the binary at a given address. |
reanalyze_function | destructive | Force a targeted reanalysis of one function, optionally overriding its |
rename_symbol | write | Rename a function or data variable |
search_bytes | read | Search for byte patterns in the binary. |
search_functions_advanced | read | Advanced function search with multiple search targets |
search_functions_by_name | read | Search functions by name substring |
search_strings | read | Search for strings matching a pattern with pagination. |
start_task | write | Start an asynchronous background task. |
types | write | Unified type management (list/info/create/create_class/create_enum/create_typedef/add_member). |
update_analysis_and_wait | write | Update binary analysis and wait for completion |
variables | write | Unified variable management (list/create/rename/set_type) for local and global variables. |
xrefs | read | Unified cross-reference tool (xrefs + call graph). |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
bookmarks, comments, reanalyze_function
streamable-http
return builtins.bytes.fromhex(normalized)
search_bytes = bytes.fromhex(clean_pattern)
anyio, hypercorn, pydantic, pydantic-settings
Gates applied: no_behavioural_pass.
a4c9c2c556eafull audit observations/trust-audit/mcp-server/symgraph__binassist-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a4c9c2c556ea | CAUTION | B | 89 | first audit |
Questions
What is the BinAssist MCP server?
Binary Ninja plugin to provide MCP functionality.
What tools does BinAssist expose?
47 in total: 35 read-only, 9 that write, and 3 that can delete or overwrite (bookmarks, comments, reanalyze_function). Every one is listed on this page with its risk.
Is BinAssist safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does BinAssist need?
No credential environment variables were found in its source, so it appears to need none.
How does BinAssist run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (a4c9c2c556ea), read on 2026-10-08. The repository is watched and re-audited when it changes.