osfeed.dev
Projects/mrexodia / ida-pro-mcp

IDA Pro MCP

An MCP server for reverse engineering with IDA Pro

Get it on GitHub
Unclaimed

Written by @iluxav from the project's code and releases, not by its maintainers. Last updated , so it may lag behind newer releases.

Are you @mrexodia?Claim it, and your coding agent keeps it current with each release
Updated 22 things you can do 10 changes to know before upgrading

Analyze binaries, annotate disassembly, and control IDA Pro from an MCP client.

What you can do with IDA Pro MCP

Inspect functions, disassembly, pseudocode, and cross-references in an IDA database.

Present at 1.2.0
Good to know

Decompilation needs the appropriate Hex-Rays decompiler.

Share
Wrong?

Rename functions and local variables, set their types, and add analysis comments.

Present at 1.2.0
Good to know

Pseudocode and local-variable operations still depend on a decompiler; disassembly comments do not.

Share
Wrong?

Inspect binary metadata, entry points, and the current IDA selection.

Present at 1.2.0
Good to know

Cursor information requires the IDA GUI.

Share
Wrong?

Convert numbers between decimal, hexadecimal, and other representations.

Present at 1.2.0
Good to know

-

Share
Wrong?

Connect an MCP client to an open IDA Pro database.

Present at 1.2.0
Good to know

Load an IDA database and start the plugin server.

Share
Wrong?

Connect Linux MCP clients to IDA Pro.

Since 1.3.0
Good to know

Claude desktop is excluded on Linux in this release.

Share
Wrong?

Analyze a binary without opening the IDA Pro GUI.

Since 1.4.0
Good to know

Requires activated idalib. Every analysis call needs a database session ID; default capacity is four workers, with a one-hour idle TTL.

Share
Wrong?
Show all 22

Control a debugged program and inspect registers, call stacks, and breakpoints.

Since 1.4.0
Good to know

Debugger tools are hidden until the `dbg` extension is enabled; a configured IDA debugger is required.

Share
Wrong?

Read bytes, integers, strings, and known global-variable values from an IDA database.

Since 1.4.0
Good to know

Global values must be known at compile time.

Share
Wrong?

Inspect structures, their field values, and references to their fields.

Since 1.4.0
Good to know

Structure reads require an address and a known structure type.

Share
Wrong?

Inspect, create, rename, retype, and delete stack-frame variables.

Since 1.4.0
Good to know

Operations use IDA stack-frame offsets and type names.

Share
Wrong?

Patch assembly instructions in an IDA database.

Since 1.4.0
Good to know

Instruction assembly depends on IDA’s assembler support.

Share
Wrong?

Find byte patterns, instruction operands, constants, and code or data references.

Since commit c133c38
Good to know

Searches are bounded by query limits and pagination.

Share
Wrong?

Survey a binary and inspect related functions in combined analysis reports.

Since commit c133c38
Good to know

Summaries cap selected strings, functions and other results; cross-reference traversal is depth-limited.

Share
Wrong?

Correct code, function, and data definitions in an IDA database.

Since commit c133c38
Good to know

Changes alter the open IDA database.

Share
Wrong?

Run Python expressions or script files in the IDA analysis context.

Since commit c133c38
Good to know

Python execution is marked unsafe; headless workers require `--unsafe`.

Share
Wrong?

Generate byte signatures for functions, address ranges, or cross-references.

Since commit c133c38
Good to know

Signature generation has configurable length and wildcard limits.

Share
Wrong?

Browse binary metadata, segments, types, structures, and GUI state as MCP resources.

Since commit c133c38
Good to know

The client must support MCP resources; GUI state requires the GUI.

Share
Wrong?

Select which analysis tools an MCP client can access.

Since commit c133c38
Good to know

A tool profile restricts tool names; it does not sandbox the process.

Share
Wrong?

Save an analyzed database or a compressed copy through MCP.

Since commit c133c38
Good to know

The destination must be writable by IDA.

Share
Wrong?

Export the MCP tool-call history stored with an IDA database.

Since commit c133c38
Good to know

Trace records are batched before being stored in the database.

Share
Wrong?

Before you upgrade IDA Pro MCP

Newest first
commit c133c38

Update tool calls and argument schemas: `decompile_function` → `decompile`, `disassemble_function` → `disasm`, `convert_number` → `int_convert`, and function lookups → `lookup_funcs`; refresh the client’s tool list.

Action requiredInferredAffects: Clients, prompts and scripts using the 1.4.0 tool API
Read the evidence
Share
Wrong?
Show 7 older
commit c133c38

Remove `--unsafe` from `ida-pro-mcp` launches; enable GUI debugger tools using `?ext=dbg` on the MCP URL (or `--ida-rpc` URL). `idalib-mcp` retains its separate `--unsafe` flag.

Action requiredInferredAffects: Users launching the GUI proxy with 1.4.0’s `--unsafe` option
Read the evidence
Share
Wrong?
commit c133c38

Read successive `decompile` pages using `cursor.next` as `offset`; the default page is 500 lines. For other truncated tool results, use the returned full-output download link.

Action requiredInferredAffects: Automation expecting complete analysis results in one response
Read the evidence
Share
Wrong?
commit c133c38

The GUI plugin autostarts its server by default; host, port and autostart preferences can be saved per database. The proxy discovers running IDA instances unless `--ida-rpc` is supplied.

Behavior changedInferred
Read the evidence
Share
Wrong?
commit c133c38

Replace removed `--install-plugin` launches with a separate `ida-pro-mcp --install` step. Unattended installs should specify client targets, `--scope` and `--transport` rather than relying on the interactive selector.

Action requiredInferredAffects: Scripts using legacy installation flags or unattended installation
Read the evidence
Share
Wrong?
IDA Pro MCP release history 4
commit c133c38

Analyze multiple binaries in persistent IDA sessions from one MCP client.

Details

`idalib-mcp` manages persistent workers and can adopt GUI sessions; calls identify the database explicitly. The tool API, installer defaults and debugger access differ from 1.4.0.

Also: Batch edits, pattern searches, Python execution, signatures, analysis summaries, tool profiles and saved call history.

Default-branch commit c133c3853faa111a9b00ee615c013b720d0c4acd, dated 2026-09-26; Python 3.11+, IDA Pro and an MCP client. Headless use requires activated idalib; documented plugin installs use uv.

Limit lifted / inferred: Analyze a binary without opening the IDA Pro GUI.Action required / inferredAction required / inferredAction required / inferredAction required / inferred: Control a debugged program and inspect registers, c…Improved / inferred: Inspect functions, disassembly, pseudocode, and cro…Action required / inferredImproved / inferred: Rename functions and local variables, set their typ…Improved / inferred: Patch assembly instructions in an IDA database.Improved / inferred: List and search strings in an IDA database.Added / inferred: Find byte patterns, instruction operands, constants…Added / inferred: Survey a binary and inspect related functions in co…Added / inferred: Correct code, function, and data definitions in an…Added / inferred: Run Python expressions or script files in the IDA a…Added / inferred: Generate byte signatures for functions, address ran…Added / inferred: Browse binary metadata, segments, types, structures…Added / inferred: Select which analysis tools an MCP client can acces…Added / inferred: Save an analyzed database or a compressed copy thro…Added / inferred: Export the MCP tool-call history stored with an IDA…Improved / inferred: Connect an MCP client to an open IDA Pro database.Behavior changed / inferredAction required / inferredBehavior changed / inferredBehavior changed / inferredBehavior changed

Seeded by @iluxav with Codex

Read the evidence
1.4.0

Analyze binaries through MCP without opening the IDA Pro GUI.

Details

Adds `idalib-mcp` for headless analysis and debugger tools enabled with `--unsafe`. String-search calls and disassembly response formats change.

Also: Debugger control, memory reads, stack and structure inspection, assembly patches, and more client integrations.

Use tag 1.4.0 with Python 3.11+ and IDA Pro 8.3+; headless analysis needs idalib. IDA Free is unsupported.

Added: Analyze a binary without opening the IDA Pro GUI.Added: Control a debugged program and inspect registers, c…Added: Read bytes, integers, strings, and known global-var…Added: Inspect structures, their field values, and referen…Added: Inspect, create, rename, retype, and delete stack-f…Added: Patch assembly instructions in an IDA database.Improved: Inspect binary metadata, entry points, and the curr…Improved: Inspect functions, disassembly, pseudocode, and cro…Limit lifted: Rename functions and local variables, set their typ…Action required / inferred: List and search strings in an IDA database.Action required / inferred: Inspect functions, disassembly, pseudocode, and cro…Improved: Connect an MCP client to an open IDA Pro database.Behavior changed / inferred: Connect an MCP client to an open IDA Pro database.

Seeded by @iluxav with Codex

Read the evidence
1.3.0

Find strings in an IDA database from an MCP client.

Details

Adds `list_strings`, `search_strings`, global-variable renaming and typing, and `declare_c_type`. Python 3.11 is now required.

Also: Global-variable edits, C type declarations, Linux and Cursor setup, and metadata compatibility.

Use tag 1.3.0 with Python 3.11+, IDA Pro 8.3+ and an MCP client; restart IDA and the client after installation.

Added: List and search strings in an IDA database.Improved: Rename functions and local variables, set their typ…Added: Connect Linux MCP clients to IDA Pro.Improved: Connect an MCP client to an open IDA Pro database.Now works: Inspect binary metadata, entry points, and the curr…Action requiredNow works: Rename functions and local variables, set their typ…

Seeded by @iluxav with Codex

Read the evidence
1.2.0
Starting point

Inspect a binary’s disassembly and decompiled functions from an MCP client.

Details

The baseline exposes function lookup, disassembly, decompilation, cross-references, IDB metadata, and annotation tools. It also converts numeric representations.

Use tag 1.2.0 with Python 3.10+, IDA Pro 8.3+ and a supported MCP client; install the plugin with `ida-pro-mcp --install`.

Added: Inspect functions, disassembly, pseudocode, and cro…Added: Rename functions and local variables, set their typ…Added: Inspect binary metadata, entry points, and the curr…Added: Convert numbers between decimal, hexadecimal, and o…Added: Connect an MCP client to an open IDA Pro database.

Seeded by @iluxav with Codex

Read the evidence

Share

LinkedIn takes the link and its card only; write your text there.

X LinkedIn Reddit Hacker News Bluesky