GhidraMCP

MCP.Pizza Chef: 13bm

Seventy actions are advertised and all seventy really are wired up. Forty-five only look: list functions, strings, and imports, turn machine code back into readable C, follow which code calls what, and hunt for encryption routines or hidden text. The other twenty-five change things, including renaming, commenting, defining data shapes, and rewriting raw bytes, with no confirmation step and no look-but-do-not-touch mode. Edits land in your Ghidra project rather than the original file, and Ghidra's undo still covers them.

Coding
Data

Use This MCP server To

Ask what an unfamiliar program actually does Get readable C code for a function I am inspecting Find hard-coded web addresses and text hidden inside a file Rename confusing function names to something meaningful Trace which parts of a program call a suspicious routine Look for encryption or deliberate obfuscation in a file

README

GhidraMCP

Build License

A Ghidra extension that exposes 70 reverse-engineering tools to AI assistants through the Model Context Protocol (MCP). Open a binary in Ghidra, enable the plugin, and let Claude (or any MCP client) decompile functions, rename symbols, annotate code, search for vulnerabilities, and more.

Architecture

 AI Client (Claude Desktop / CLI)
        |  stdio + MCP JSON-RPC
        v
   Go MCP Bridge  (mcp_bridge)
        |  TCP, length-prefixed JSON-RPC
        v
   Ghidra Plugin  (MCPServerPlugin)
        |
        v
   Ghidra Program API

The Ghidra plugin (Java) starts a TCP server inside Ghidra and auto-launches the Go bridge binary. The bridge speaks MCP over stdio to the AI client and forwards calls to the Java plugin over a local TCP socket with 4-byte length-prefixed JSON-RPC framing. Optional API-key authentication protects the TCP channel.

Features

  • 70 MCP tools spanning query, mutation, analysis, malware triage, IoT/embedded security, structure management, async decompilation, and multi-instance support
  • Easy setup -- plugin auto-starts the bridge; use MCP > Settings > Write to Claude Config to configure your MCP client
  • Cross-platform -- prebuilt bridge binaries for Linux x86_64, Windows x86_64, macOS x86_64 and macOS ARM64
  • Configurable -- port, localhost-only binding, API-key auth, auto-start, bridge enable/disable via GhidraMCP.properties
  • Multi-instance -- work with multiple Ghidra windows simultaneously using target_port to route tool calls
  • Async decompilation -- decompile large functions without blocking; poll for results later
  • Connection retry -- the bridge reconnects automatically if Ghidra restarts or the connection drops
  • Pagination -- large result sets (functions, strings, imports, ...) support offset/limit for safe incremental retrieval
  • CI/CD -- automated builds, Go + Java tests, Ghidra integration tests, and auto-release when a new Ghidra version drops

Quick Start

Prerequisites

GhidraMCP FAQ

Do I need an account or a paid key?
No. The optional key in the setup notes is a password you invent yourself to lock the local connection between Ghidra and the bridge program. Nothing is sent to any outside service.
What do I need installed first?
Ghidra 12.0.3 or newer and Java 21 or newer, both free. Ready-built bridge programs are supplied for Windows, Linux, and both kinds of Mac.
Can I use this to understand a program I have no source code for?
Yes, that is the whole point. It turns compiled code into readable C and lets you ask questions about it in plain English.
Can it damage my file?
Not the original on disk. Twenty-five of the seventy actions do edit your Ghidra project, including rewriting bytes and changing memory permissions, and none of them ask first. Ghidra's own undo covers them.
Is there a look-but-do-not-touch mode?
No. Each action is labelled as read-only or not, but that label is only a hint passed to your assistant app; the server itself will run the editing actions regardless.
Does it expose anything to my network?
Not by default. It listens only on your own machine, and if you change that it logs a loud warning. The optional password is genuinely checked, with a limit of three wrong guesses.
How hard is setup?
Real work. Install Ghidra, add the extension file, restart, tick the plugin on, then use its own menu to write the settings into your assistant app for you.
Is the project still looked after?
Yes. It was updated in June 2026 and ships automated tests that fail if the advertised count of seventy actions ever drifts from reality.