Skip to content
aicoolies logo
Ghidra logo

GhidraMCP

MCP server for AI-powered reverse engineering

GhidraMCP is an MCP server that enables LLMs to autonomously perform reverse engineering tasks through NSA's Ghidra disassembly framework. It exposes binary analysis capabilities like decompilation, function listing, cross-references, and symbol analysis as MCP tools, letting AI assistants generate malware reports and analyze compiled binaries.

About GhidraMCP

GhidraMCP bridges the gap between AI assistants and binary analysis by exposing Ghidra's powerful reverse engineering capabilities through the Model Context Protocol. Security researchers and developers can connect their AI assistant to GhidraMCP and ask natural language questions about compiled binaries — 'What does this function do?', 'Find all calls to this API', 'Generate a security report for this binary' — while the MCP server translates those requests into Ghidra operations and returns structured results.

The server exposes key Ghidra operations as MCP tools: listing functions with their addresses and signatures, decompiling functions to pseudo-C code, analyzing cross-references between functions, examining data sections, and navigating symbol tables. This enables AI assistants to perform multi-step reverse engineering workflows autonomously — starting from an entry point, following call chains, identifying suspicious patterns, and synthesizing findings into structured reports without manual intervention.

With 7,900+ GitHub stars, GhidraMCP has attracted significant attention from the security research community. It's particularly valuable for malware analysis, vulnerability research, and binary auditing tasks where AI's ability to rapidly process and summarize large amounts of disassembly output can dramatically accelerate human analysts' workflows. The MCP interface means it works with Claude Desktop, Cursor, and any other MCP-compatible client without custom integration work.

Pricing & Platform Specs

Pricing Summary

Free and 100% open source under the Apache-2.0 license ($0 software cost). GhidraMCP runs locally on developer workstations alongside the open-source NSA Ghidra reverse engineering suite with no subscription fees, paid tiers, or seat licenses.

full pricing breakdown →

Supported Platforms

Ghidra plugin, MCP Server, Claude Desktop, Cursor

Explore categories, tags & use cases

Developer-first security platform

Snyk is the leading developer security platform providing continuous scanning for vulnerabilities in code (SAST), open-source dependencies (SCA), container images, and infrastructure as code. Integrates directly into IDEs, Git repositories, CI/CD pipelines, and container registries. Features AI-powered fix suggestions, license compliance checking, and real-time vulnerability database. Free for individual developers with paid plans for teams. Supports 30+ programming languages.

freemium

Unified code-to-cloud security platform for developers

Aikido Security is an all-in-one AppSec platform unifying SAST, DAST, SCA, CSPM, secrets detection, container scanning, IaC analysis, and runtime protection in a single developer-friendly dashboard. Cuts false positive noise by 95% through reachability analysis that evaluates vulnerabilities in actual deployment context. Features AI AutoFix for one-click remediation, CI/CD gating, and AI-powered pentesting agents. Trusted by 50,000+ organizations. Supports 50+ programming languages.

freemium

Cloud native runtime security for Kubernetes

Falco is a CNCF graduated open-source runtime security tool that detects unexpected behavior and threats across containers, Kubernetes, and cloud workloads in real time. Originally created by Sysdig, Falco monitors Linux kernel syscalls using eBPF and applies customizable detection rules to alert on malicious activity like container escapes, cryptojacking, unauthorized file access, and anomalous network connections. It supports 50+ alert output channels including SIEM integration.

Open Source

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is GhidraMCP?

GhidraMCP is an MCP server that enables LLMs to autonomously perform reverse engineering tasks through NSA's Ghidra disassembly framework. It exposes binary analysis capabilities like decompilation, function listing, cross-references, and symbol analysis as MCP tools, letting AI assistants generate malware reports and analyze compiled binaries.

Is GhidraMCP free?

Yes — GhidraMCP is open source and free to use. Free and 100% open source under the Apache-2.0 license ($0 software cost). GhidraMCP runs locally on developer workstations alongside the open-source NSA Ghidra reverse engineering suite with no subscription fees, paid tiers, or seat licenses.

Is GhidraMCP open source?

Yes — GhidraMCP is open source.

Is GhidraMCP still maintained?

Yes — GhidraMCP is active. Its listing was last verified on September 6, 2026.

What are the best GhidraMCP alternatives?

The first editor-selected GhidraMCP alternatives are Snyk, Aikido Security, Falco.