GhidraMCP: Connecting Ghidra and LLMs via MCP for Autonomous Binary Reverse Engineering

GhidraMCP, an open-source tool by LaurieWired, exposes Ghidra decompilation, symbol renaming, and exports through Model Context Protocol for Claude Desktop and

tau · October 6, 2026

#Ghidra #GhidraMCP #MCP #ReverseEngineering #BinaryAnalysis #ClaudeDesktop #Cline #Security

GhidraMCP: Connecting Ghidra and LLMs via MCP for Autonomous Binary Reverse Engineering

Reverse engineering compiled binaries for vulnerability research, malware triage, and legacy system audits has traditionally required deep specialized expertise and extensive manual review. An open-source project by LaurieWired, GhidraMCP (LaurieWired/GhidraMCP), is drawing significant interest across developer and security communities by exposing core capabilities of the Ghidra framework as a Model Context Protocol (MCP) server, allowing large language models to autonomously inspect and navigate binaries.

Interface diagram showing GhidraMCP bridging Ghidra binary analysis with LLMs

Image source: @_vmlops via X

Historically, reverse engineers had to sit in the Ghidra GUI to manually trace assembly instructions, cross-reference decompiler output, and label cryptic function stubs one by one. GhidraMCP bridges this workflow into the modern AI ecosystem by translating Ghidra's internal analysis engine into standardized MCP tool interfaces, enabling standard-compliant AI clients such as Anthropic's Claude Desktop and VS Code's Cline to programmatically decompile functions, inspect structures, and rename symbols.

Ghidra Plugin and Python MCP Bridge: Architecture and Core Analysis Capabilities

The core architecture of GhidraMCP relies on a two-part decoupled design: a Java plugin running inside the Ghidra runtime and a lightweight Python bridge script (bridge_mcp_ghidra.py) that speaks the Model Context Protocol to AI clients.

The Java plugin hosts a local HTTP server (defaulting to port 8080) with direct access to Ghidra's Program database, while the Python bridge translates incoming MCP tool requests into corresponding HTTP queries. Through this integration, GhidraMCP exposes key analytical capabilities:

  • Binary Decompilation and Logic Inspection: AI clients can query specific functions within a loaded binary, retrieve reconstructed C pseudocode directly from Ghidra's decompiler, and analyze algorithmic control flow.
  • Autonomous Method and Data Renaming: Based on decompiled pseudocode analysis, the LLM infers the underlying semantics of default identifiers (such as FUN_00401000 or generic data labels) and programmatically renames them inside Ghidra to establish clear program documentation.
  • Symbol Table and Structure Exploration: The model can inspect class structures, method lists, and import/export tables to rapidly assess external library dependencies, API calls, and execution entry points.

Supported MCP Clients and Setup: Integrating Claude Desktop, Cline, and 5ire

GhidraMCP distributes both the Ghidra plugin archive and the Python client via its official GitHub repository (LaurieWired/GhidraMCP). It adheres to standard MCP protocols, ensuring compatibility across multiple agent environments.

Users begin by downloading the latest release package, importing the plugin directly into Ghidra as an extension, and configuring their preferred AI client to interface with the Python bridge.

  • Claude Desktop Configuration: Add an entry under mcpServers inside claude_desktop_config.json, pointing the command to python and specifying the absolute path to bridge_mcp_ghidra.py along with --ghidra-server http://127.0.0.1:8080/.
  • Cline Integration: When connecting from Cline inside VS Code, run the Python bridge using the SSE transport: python bridge_mcp_ghidra.py --transport sse --mcp-host 127.0.0.1 --mcp-port 8081 --ghidra-server http://127.0.0.1:8080/. Then, under Cline's MCP Servers panel, register a Remote Server at http://127.0.0.1:8081/sse.
  • 5ire Setup: For the multi-model 5ire client, navigate to Tools, create a new entry with tool key ghidra, set the name to GhidraMCP, and assign the launch command to python /ABSOLUTE_PATH_TO/bridge_mcp_ghidra.py.

Operational Value and Technical Caveats for Security Workflows

GhidraMCP significantly reduces repetitive mechanical effort during initial binary triage by offloading symbol labeling and pseudocode reading to conversational AI models. However, integrating automated reverse engineering into production workflows requires acknowledging critical constraints:

  • Ghidra and Java Runtime Dependency: GhidraMCP is not a standalone static analysis engine. The target binary must be pre-imported and analyzed within a local Ghidra installation, requiring a properly configured local Java environment.
  • LLM Hallucination and Inference Risks: Large language models may misinterpret decompiled code or generate speculative function names, especially in obfuscated or stripped binaries. Security analysts must treat AI-generated annotations as informed proposals and perform manual verification on sensitive code paths.
  • Project State Modifications and Backups: Because autonomous renaming modifies Ghidra's active program database, analysts should always preserve backups of original Ghidra project files before running bulk automated renaming passes.

Sources