Release /
IDA Pro MCP commit c133c38
Analyze multiple binaries in persistent IDA sessions from one MCP client.
Share
Before you upgrade to commit c133c38
6 to fixActivate idalib globally and install `uv` for the documented Claude Code, Codex and Kimi Code plugin workflows.
Update tool calls and argument schemas: `decompile_function` → `decompile`, `disassemble_function` → `disasm`, `convert_number` → `int_convert`, and function lookups → `lookup_funcs`; refresh the client’s tool list.
Remove `--unsafe` from `ida-pro-mcp` launches; enable GUI debugger tools using `?ext=dbg` on the MCP URL (or `--ida-rpc` URL). `idalib-mcp` retains its separate `--unsafe` flag.
Read successive `decompile` pages using `cursor.next` as `offset`; the default page is 500 lines. For other truncated tool results, use the returned full-output download link.
The GUI plugin autostarts its server by default; host, port and autostart preferences can be saved per database. The proxy discovers running IDA instances unless `--ida-rpc` is supplied.
Replace removed `--install-plugin` launches with a separate `ida-pro-mcp --install` step. Unattended installs should specify client targets, `--scope` and `--transport` rather than relying on the interactive selector.
Client installation now defaults to project scope and streamable HTTP; running the proxy without a transport still defaults to stdio.
HTTP access now checks Host and Origin; the default CORS policy permits localhost origins, with the policy configurable at `/config.html`.
The README recommends the official Hex-Rays IDA MCP Server. It also says the GUI MCP plugin is no longer recommended and will eventually be deprecated, preferring `idalib-mcp`.
What changed in commit c133c38
`idalib-mcp` manages persistent workers and can adopt GUI sessions; calls identify the database explicitly. The tool API, installer defaults and debugger access differ from 1.4.0.
Also: Batch edits, pattern searches, Python execution, signatures, analysis summaries, tool profiles and saved call history.
Default-branch commit c133c3853faa111a9b00ee615c013b720d0c4acd, dated 2026-09-26; Python 3.11+, IDA Pro and an MCP client. Headless use requires activated idalib; documented plugin installs use uv.
New things you can do
Use `find_bytes`, `find` and `insn_query`; immediate matching handles sign-extended values.
Use `survey_binary`, `analyze_function`, `analyze_component`, and multi-hop `trace_data_flow`.
Use `define_func`, `define_code`, `undefine`, `make_data` and operand-type operations.
`py_eval` returns the result, stdout and stderr and retains locals by default; `new_locals=True` resets them. `py_exec_file` runs a script file.
Export signatures in IDA, x64dbg, mask or bitmask formats.
Read `ida://` resources for IDB state, types, imports, exports and references.
Configure enabled tools at `/config.html`, export `/profile.txt`, or pass `--profile` to `idalib-mcp`; read-only and triage profiles are supplied.
Read the evidence
- mrexodia/ida-pro-mcp/blob/c133c3853faa111a9b00ee615c013b720d0c4acd/src/ida_pro_mcp/ida_mc…
- mrexodia/ida-pro-mcp/blob/c133c3853faa111a9b00ee615c013b720d0c4acd/src/ida_pro_mcp/idalib…
- mrexodia/ida-pro-mcp/blob/c133c3853faa111a9b00ee615c013b720d0c4acd/profiles/readonly.txt
- mrexodia/ida-pro-mcp/blob/c133c3853faa111a9b00ee615c013b720d0c4acd/profiles/triage.txt
Use `idb_save` to save in place or to another destination while retaining the open database’s working files.
Tool-call tracing is always on and records arguments and structured results in the IDB; `ida-mcp-trace-dump` exports JSONL.
Fixed and improved
Open multiple databases with `idb_open`, choose GUI or headless backends, and save or close sessions; detached workers can be reused by later supervisors.
Read paginated pseudocode with optional address markers, inspect basic blocks and bounded call graphs, and export functions as JSON, C headers or prototypes.
Rename and apply types in batches, append comments, add bookmarks, infer types, and compare pseudocode before and after edits.
Read the evidence
- mrexodia/ida-pro-mcp/blob/c133c3853faa111a9b00ee615c013b720d0c4acd/README.md
- mrexodia/ida-pro-mcp/blob/c133c3853faa111a9b00ee615c013b720d0c4acd/src/ida_pro_mcp/ida_mc…
- mrexodia/ida-pro-mcp/blob/c133c3853faa111a9b00ee615c013b720d0c4acd/src/ida_pro_mcp/ida_mc…
- mrexodia/ida-pro-mcp/blob/c133c3853faa111a9b00ee615c013b720d0c4acd/src/ida_pro_mcp/ida_mc…
Patch byte sequences or typed integers in batches in addition to assembly instructions.
Search strings with `find_regex`, including UTF-16 strings, and search disassembly or comments with `search_text`.
Adds documented plugin installs for Claude Code, Codex and Kimi Code, plus configuration support for additional clients and streamable HTTP.
Seeded by @iluxav with Codex, from the release's public sources. Each change links to its evidence.