GhidraMCP

MCP.Pizza Chef: LaurieWired

Reverse engineering means working out what a program does when nobody has its original code. This add-on hands that job to an assistant: it can turn machine code back into something readable, list the functions, classes, and outside libraries a file uses, and replace cryptic auto-generated names with meaningful ones. The work runs through Ghidra, the free analysis tool you install first, plus a small Python bridge. Claude Desktop, Cline, and 5ire are all documented.

Unmaintained · No commits in 15 months.
Coding

Use This MCP server To

Read what an unknown program actually does Turn machine code back into readable functions Rename cryptic functions to something meaningful List the classes and functions inside a file Investigate a suspicious file before running it

README

License GitHub release (latest by date) GitHub stars GitHub forks GitHub contributors Follow @lauriewired

ghidra_MCP_logo

ghidraMCP

ghidraMCP is an Model Context Protocol server for allowing LLMs to autonomously reverse engineer applications. It exposes numerous tools from core Ghidra functionality to MCP clients.

ghidraMCP_demo.mp4

GhidraMCP FAQ

Do I need Ghidra installed?
Yes — Ghidra must be installed and running, with this project's extension added to it.
Which apps does this work in?
Claude Desktop, Cline, and 5ire are shown in the instructions, and other MCP apps should work too.
Can I use this to figure out what a mystery program does?
Yes — the assistant can pull it apart, read the recovered code, and explain what it finds.
How hard is setup?
Fairly involved: install Ghidra, add the extension, install Python, then point your assistant at a small bridge script.
Does it need a paid account?
No — Ghidra and this add-on are both free and open source.
Can it rename things for me?
Yes — it can rename functions and data as it works out what each one is for.