百科.dev
全部条目AI 编程趋势榜开源项目技术资讯提交条目
登录
< 返回工具列表
G

GhidrAssistMCP

> AI 编程
开源

一个用于 Ghidra 的原生 MCP 服务器扩展

686 stars0 点赞0 次浏览
访问官网GitHub

工具介绍

一个用于 Ghidra 的原生 MCP 服务器扩展

GhidrAssistMCP

A powerful Ghidra extension that provides an MCP (Model Context Protocol) server, enabling AI assistants and other tools to interact with Ghidra's reverse engineering capabilities through a standardized API.

Overview

GhidrAssistMCP bridges the gap between AI-powered analysis tools and Ghidra's comprehensive reverse engineering platform. By implementing the Model Context Protocol, this extension allows external AI assistants, automated analysis tools, and custom scripts to seamlessly interact with Ghidra's analysis capabilities.

Key Features

  • MCP Server Integration: Full Model Context Protocol server implementation using official SDK
  • Dual HTTP Transports: Supports SSE and Streamable HTTP transports for maximum client compatibility
  • 49 Built-in Tools: Comprehensive set of analysis tools with action-based consolidation for cleaner APIs
  • 6 MCP Resources: Static data resources for program info, functions, strings, imports, exports, and segments
  • 7 MCP Prompts: Pre-built analysis prompts for common reverse engineering tasks
  • Result Caching: Intelligent caching system to improve performance for repeated queries
  • Async Task Support: Long-running operations execute asynchronously with task management
  • Multi-Program Support: Work with multiple open programs simultaneously using program_name; use list_binaries Project Path values to disambiguate duplicate filenames
  • Multi-Window Support: Single MCP server shared across all CodeBrowser windows with intelligent focus tracking
  • Active Context Awareness: Automatic detection of which binary window is in focus, with context hints in all tool responses
  • Configurable UI: Easy-to-use interface for managing tools and monitoring activity
  • Real-time Logging: Track all MCP requests and responses with detailed logging
  • Dynamic Tool Management: Enable/disable tools individually with persistent settings

Clients

Shameless self-promotion: GhidrAssist supports GhidrAssistMCP right out of the box.

Screenshots

Installation

Prerequisites

  • Ghidra 11.4+ (tested with Ghidra 12.1 Public)
  • An MCP Client (Like GhidrAssist)

Binary Release (Recommended)

  1. Download the latest release:

    • Go to the Releases page
    • Download the latest .zip file (e.g., GhidrAssistMCP-v1.0.0.zip)
  2. Install the extension:

    • In Ghidra: File → Install Extensions → Add Extension
    • Select the downloaded ZIP file
    • Restart Ghidra when prompted
  3. Enable the plugin:

    • File → Configure → Configure Plugins
    • Search for "GhidrAssistMCP"
    • Check the box to enable the plugin

Building from Source

Source builds require Java 25 or newer. The included Gradle wrapper pins the supported Gradle release; use it instead of a system Gradle installation.

  1. Clone the repository:

    bash
    git clone 
    cd GhidrAssistMCP
  2. Point Gradle at your Ghidra install:

    • Set GHIDRA_INSTALL_DIR (environment variable), or pass -PGHIDRA_INSTALL_DIR= when you run Gradle.
  3. Build + install:

    Ensure Ghidra isn't running and run:

    bash
    ./gradlew installExtension

    This copies the built ZIP into your Ghidra install ([GHIDRA_INSTALL_DIR]/Extensions/Ghidra) and extracts it into your Ghidra user Extensions folder (replacing any existing extracted copy).

    If you need to override that location, pass -PGHIDRA_USER_EXTENSIONS_DIR=.

  4. Restart / verify:

    • Restart Ghidra.
    • If the plugin doesn't appear, enable it via File → Configure → Configure Plugins (search for "GhidrAssistMCP").

Configuration

Initial Setup

  1. Open the Control Panel:

    • Window → GhidrAssistMCP (or use the toolbar icon)
  2. Configure Server Settings:

    • Host: Default is localhost
    • Port: Default is 8080
    • Enable/Disable: Toggle the MCP server on/off

Tool Management

The Configuration tab allows you to:

  • View all available tools (49 total)
  • Enable/disable individual tools using checkboxes
  • Save configuration to persist across sessions
  • Monitor tool status in real-time

Headless Mode Quickstart

GhidrAssistMCP can also be started from Ghidra's analyzeHeadless launcher. This is useful when you want MCP access to a program loaded in headless Ghidra without opening the CodeBrowser UI.

First, build and install the extension so Ghidra can load the compiled classes and bundled dependencies:

bash
cd /path/to/GhidrAssistMCP

export GHIDRA_INSTALL_DIR=/path/to/ghidra_12.1_PUBLIC
./gradlew installExtension

Set paths for your Ghidra install and extracted user extension. On Linux, Ghidra user extensions usually live under ~/.config/ghidra//Extensions:

bash
export GHIDRA_INSTALL_DIR=/path/to/ghidra_12.1_PUBLIC
export GHIDRA_USER_EXTENSIONS_DIR="$HOME/.config/ghidra/ghidra_12.1_PUBLIC/Extensions"
export GHIDRASSISTMCP_EXT="$GHIDRA_USER_EXTENSIONS_DIR/GhidrAssistMCP"

Import a binary and start the MCP server as a headless pre-script:

bash
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /tmp/ghidra-projects McpHeadless \
  -import /path/to/binary \
  -scriptPath "$GHIDRASSISTMCP_EXT/ghidra_scripts" \
  -preScript GAMCPStartServerScript.java "host=127.0.0.1" "port=8080"

For a binary that is already imported into the project, use -process instead:

bash
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /tmp/ghidra-projects McpHeadless \
  -process binary_name \
  -scriptPath "$GHIDRASSISTMCP_EXT/ghidra_scripts" \
  -preScript GAMCPStartServerScript.java "host=127.0.0.1" "port=8080"

To keep a headless MCP session open after analysis completes, run the server as a post-script with wait mode:

bash
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /tmp/ghidra-projects McpHeadless \
  -process binary_name \
  -scriptPath "$GHIDRASSISTMCP_EXT/ghidra_scripts" \
  -postScript GAMCPStartServerScript.java "host=127.0.0.1" "port=8080" "wait=true"

MCP clients can connect to:

SSE:             http://127.0.0.1:8080/sse
SSE messages:    http://127.0.0.1:8080/message
Streamable HTTP: http://127.0.0.1:8080/mcp

The headless MCP server runs inside the analyzeHeadless JVM and uses the loaded currentProgram. The server holds a program consumer while it is running so MCP requests do not race against program database closure. Use wait=true when you want analyzeHeadless to stay open for interactive MCP clients. A harness can also pass completion_file=/workspace/control/session.complete; creating that file closes the MCP server cleanly and lets Ghidra save and exit normally.

Disposable static-analysis labs may pass tool_profile=agent_lab. This enables sandbox-local program export while arbitrary path import and Ghidra scripts remain disabled because they can expose process secrets or spawn processes. The harness owns artifact imports. Unknown profiles are rejected.

Available Tools

GhidrAssistMCP provides 49 tools organized into categories. Several tools use an action-based API pattern where a single tool provides multiple related operations.

Binary & Program Management

Tool Description
get_binary_info Get basic program information (name, architecture, compiler, etc.)
list_binaries List all open programs across all CodeBrowser windows, including Project Path values for unambiguous program_name targeting
open_program List/open project programs in CodeBrowser, with optional analysis prompt suppression and analysis-after-open task submission
close_program Close an open CodeBrowser program; changed programs require save=true or ignore_changes=true
import_file Import a host file into the current Ghidra project and optionally open it (disabled by default)
project_files List or delete files/folders in the active Ghidra project; deletion requires confirm=true
scripts List/read/create/delete/run Ghidra scripts (disabled by default)
assemble_code Assemble instruction text at an address and optionally patch it into program memory
patch_bytes Patch raw bytes in program memory at a given address
export_program Export the current program to disk (binary or original_file) (disabled by default)

Security-sensitive tools: import_file, scripts, and export_program are disabled by default because they interact with the host filesystem or execute script code. Enable them explicitly in the plugin configuration UI when needed. project_files deletes entries from the active Ghidra project database, not the original imported host files, and requires confirm=true.

Auto Analysis

Tool Description
analysis_options List/set/reset Auto Analysis options and save/apply/list/delete option presets for the current program
analyze_program Run Auto Analysis on the current program or all open programs; supports full re-analysis, pending-changes analysis, address ranges, and option overrides
analysis_control Query Auto Analysis status or request cancellation of queued analysis tasks

Function Discovery & Analysis

Tool Description
get_functions List functions with optional pattern filtering and pagination
search_functions_by_name Find functions by name pattern
get_function_statistics Comprehensive statistics for all functions
analyze_function Get detailed function information (signature, variables, etc.)
get_current_function Get function at current cursor position
get_function_stack_layout Get stack frame layout with variable offsets
get_basic_blocks Get basic block information for a function
create_function Create/define a function at an address, optionally clearing existing data/code first
disassemble_at Disassemble code at an address, optionally clearing existing data/code in the range first

Binary Information

Tool Description
get_imports List imported functions/symbols
get_exports List exported functions/symbols
get_strings List string references with optional filtering
search_strings Search strings by pattern
get_segments List memory segments
get_namespaces List namespaces in the program
get_relocations List relocation entries
get_entry_points List all binary entry points

Data Analysis

Tool Description
get_data_vars List data definitions in the program
get_data_at Get hexdump/data at a specific address
create_data_var Define data variables at addresses
get_current_address Get current cursor address

Consolidated Tools

These tools bundle related operations behind a discriminator parameter (e.g., action, target, target_type, or format).

get_code - Code Retrieval Tool

Parameter Values Description
format decompiler, disassembly, pcode Output format
raw boolean Only affects format: "pcode" (raw pcode ops vs grouped by basic blocks)

classes - Class Operations Tool

Action Description
list List classes with optional pattern filtering and pagination
get_info Get detailed class information (methods, fields, vtables, virtual functions)

xrefs - Cross-Reference Tool

Parameter Description
address Find all references to/from a specific address
function Find all cross-references for a function
include_calls Include callers/callees (replaces separate call graph tool)

struct - Structure Operations Tool

Action Description
`crea

Issues· 0 开放

查看全部 Issues在 GitHub 打开

暂无开放 Issues,或尚未同步最近议题。

> 标签

Javaghidraghidra-extensionghidra-pluginllm

暂无评论,来聊聊你的看法吧

> 工具信息

发布日期2026年8月1日
最后更新2026年9月17日
分类AI 编程
定价开源

> 相关工具

G
GitHub Copilot
GitHub 官方 AI 编程助手,覆盖补全、Chat 与 Agent 模式。
C
Cursor
AI 原生代码编辑器,对话改代码、多文件 Agent 与规则体系是其核心。
S
skills
Skills for Real Engineers. Straight from my .agents directory.