ida-pro-mcp

MCP.Pizza Chef: mrexodia

This plugin gives a chat assistant a view of the file you have open in IDA Pro: reading decompiled code, listing the text and names it finds, following where a value is used, then renaming functions and variables, correcting types and leaving comments as it goes. Debugger controls exist too, behind an unsafe flag you have to switch on. It works with Claude, Cursor, VS Code, Cline, Roo Code and Windsurf. A paid IDA Pro licence, version 8.3 or newer, is required — IDA Free will not do.

Coding

Use This MCP server To

Ask what an unfamiliar function is really doing Rename cryptic variables to something readable Add comments as I work through a program Find every place a value gets used Get a written summary of what a program does

README

IDA Pro MCP

Simple MCP Server to allow vibe reversing in IDA Pro.

ida-pro-mcp-success.mp4

The binaries and prompt for the video are available in the mcp-reversing-dataset repository.

Available functionality:

  • check_connection(): Check if the IDA plugin is running.
  • get_metadata(): Get metadata about the current IDB.
  • get_function_by_name(name): Get a function by its name.
  • get_function_by_address(address): Get a function by its address.
  • get_current_address(): Get the address currently selected by the user.
  • get_current_function(): Get the function currently selected by the user.
  • convert_number(text, size): Convert a number (decimal, hexadecimal) to different representations.
  • list_functions(offset, count): List all functions in the database (paginated).
  • list_globals_filter(offset, count, filter): List matching globals in the database (paginated, filtered).
  • list_globals(offset, count): List all globals in the database (paginated).
  • list_strings_filter(offset, count, filter): List matching strings in the database (paginated, filtered).
  • list_strings(offset, count): List all strings in the database (paginated).
  • list_local_types(): List all Local types in the database.
  • decompile_function(address): Decompile a function at the given address.
  • disassemble_function(start_address): Get assembly code (address: instruction; comment) for a function.
  • get_xrefs_to(address): Get all cross references to the given address.
  • get_xrefs_to_field(struct_name, field_name): Get all cross references to a named struct field (member).
  • get_entry_points(): Get all entry points in the database.
  • set_comment(address, comment): Set a comment for a given address in the function disassembly and pseudocode.
  • rename_local_variable(function_address, old_name, new_name): Rename a local variable in a function.
  • rename_global_variable(old_name, new_name): Rename a global variable.
  • set_global_variable_type(variable_name, new_type): Set a global variable's type.
  • rename_function(function_address, new_name): Rename a function.
  • set_function_prototype(function_address, prototype): Set a function's prototype.
  • declare_c_type(c_declaration): Create or update a local type from a C declaration.
  • set_local_variable_type(function_address, variable_name, new_type): Set a local variable's type.

Unsafe functions (--unsafe flag required):

  • dbg_get_registers(): Get all registers and their values. This function is only available when debugging.
  • dbg_get_call_stack(): Get the current call stack.
  • dbg_list_breakpoints(): List all breakpoints in the program.
  • dbg_start_process(): Start the debugger.
  • dbg_exit_process(): Exit the debugger.
  • dbg_continue_process(): Continue the debugger.
  • dbg_run_to(address): Run the debugger to the specified address.
  • dbg_set_breakpoint(address): Set a breakpoint at the specified address.
  • dbg_delete_breakpoint(address): del a breakpoint at the specified address.
  • dbg_enable_breakpoint(address, enable): Enable or disable a breakpoint at the specified address.

ida-pro-mcp FAQ

Do I need IDA Pro?
Yes — version 8.3 or newer, and IDA Free is not supported.
Which apps does it work in?
Claude, Cursor, VS Code, Cline, Roo Code, Windsurf and other MCP clients.
Do I need a key?
No key for the plugin; you supply Python 3.11 or newer and your own assistant.
Can I use this to tidy up names while I work?
Yes — it renames functions and variables, sets types and leaves comments directly in your open file.
Can it run the program being examined?
Only when started with the unsafe option, which unlocks the debugger controls.
How hard is setup?
Install the package with pip, run its install command, then fully restart IDA and your assistant.