Ghidra Mcp

general MCP Server

Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.

Verified
generalgeneraldocker
9 views2,150 stars10 forksApache-2.0

Why This Matters

Discovered via mcp and last synced 4mo ago.

Verified
Source
mcp
Stars
2,150
Last synced
4mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
26
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (26)

Tier

Behavior

GHIDRA_MCP_FILE_ROOT

When set to a directory path, filesystem-path endpoints (`/import_file`, `/open_project`, `/delete_file`, etc.) canonicalize the input and require it to fall under this root. Prevents path-traversal.

install-ghidra-deps

Install only the Ghidra JARs into `~/.m2`. Useful when the build environment changes.

GET

Check Ghidra Server connection

Metric

Value

8099

HTTP server port

deploy

Copy the built extension into the Ghidra profile and patch `FrontEndTool.xml` for auto-activation.

Library

Source Path

Flag

Description

Command

What it does

install-python-deps

Install only the Python requirements files.

stdio

`stdio` (AI tools), `streamable-http` (web clients), `sse` (deprecated)

ensure-prereqs

Install Python deps + Ghidra Maven JARs in one shot. Start here on a new machine.

run-tests

Run the Java offline test suite (no live Ghidra needed).

off

Load only the default tool groups on connect. Faster startup, but MCP clients that don't support `tools/list_changed` will see an incomplete tool list. Not recommended for Claude Code.

preflight

Validate Python, build tool, Ghidra path, and JAR availability without making changes. Add `--strict` to also check network reachability.

verify-version

Check that version strings are consistent across `pom.xml`, `CHANGELOG.md`, and `README.md`.

INFO

`DEBUG`, `INFO`, `WARNING`, or `ERROR`

GHIDRA_MCP_AUTH_TOKEN

When set, every HTTP request must carry `Authorization: Bearer <token>`. Timing-safe comparison. `/mcp/health`, `/health`, `/check_connection` are exempt.

GHIDRA_MCP_ALLOW_SCRIPTS

Set to `1`, `true`, or `yes` to enable `/run_script_inline` and `/run_ghidra_script`. **Off by default as of v5.4.1** — these endpoints execute arbitrary Java against the Ghidra process.

clean-all

Remove build outputs plus local cache artifacts (`.m2` Ghidra JARs, etc.).

build

Build the plugin JAR and extension ZIP via Maven (or Gradle when `TOOLS_SETUP_BACKEND=gradle`).

start-ghidra

Launch the configured Ghidra installation.

Endpoint

Method

clean

Remove Maven/Gradle build outputs (`target/`, `build/`).

POST

Create a Ghidra project