The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Ida Pro MCP listing page.
Simple MCP Server to allow vibe reversing in IDA Pro.
https://github.com/user-attachments/assets/6ebeaa92-a9db-43fa-b756-eececce2aca0
The binaries and prompt for the video are available in the mcp-reversing-dataset repository.
idapyswitch to switch to the newest Python versionida-pro-mcp --config to get the JSON config for your client.Note: This requires having idalib activated globally and uv installed:
To install the latest IDA Pro MCP in Claude Code:
To install the latest IDA Pro MCP in Codex:
To install the latest IDA Pro MCP in Kimi Code, run this slash command in the chat:
This installs the idalib MCP server and the idapython skill. Plugins are copied to
$KIMI_CODE_HOME/plugins/managed/, so uv must be on your PATH. The first session after
installing is slower, because uv resolves the dependencies before the server responds.
Note: the MCP plugin is no longer recommended and will eventually be deprecated. Use idalib-mcp instead.
If you want to configure the MCP server manually from the IDA GUI:
Configure the MCP servers and install the IDA Plugin:
Important: Make sure you completely restart IDA and your MCP client for the installation to take effect. Some clients (like Claude) run in the background and need to be quit from the tray icon.
LLMs are prone to hallucinations and you need to be specific with your prompting. For reverse engineering the conversion between integers and bytes are especially problematic. Below is a minimal example prompt, feel free to start a discussion or open an issue if you have good results with a different prompt:
This prompt was just the first experiment, please share if you found ways to improve the output!
Another prompt by @can1357:
Live stream discussing prompting and showing some real-world malware analysis:
Large Language Models (LLMs) are powerful tools, but they can sometimes struggle with complex mathematical calculations or exhibit "hallucinations" (making up facts). Make sure to tell the LLM to use the int_convert MCP tool and you might also need math-mcp for certain operations.
Another thing to keep in mind is that LLMs will not perform well on obfuscated code. Before trying to use an LLM to solve the problem, take a look around the binary and spend some time (automatically) removing the following things:
You should also use a tool like Lumina or FLIRT to try and resolve all the open source library code and the C++ STL, this will further improve the accuracy.
You can run an SSE server to connect to the user interface like this:
After installing idalib you can also run a headless MCP server. You can start with an initial binary:
Or start without a binary and open arbitrary files later with idb_open(...):
For stdio-based clients, use:
Database workers are persistent: each one runs as a detached process that
outlives the supervisor that spawned it. When a new supervisor (over stdio
or HTTP) calls idb_open for a binary that is already open under a worker
on this host, the supervisor adopts that worker transparently — there is
no separate "shared" mode to enable. Workers self-exit when no request has
hit them for an idle interval.
Note: The idalib feature was contributed by Willi Ballenthin.
idalib-mcp is a supervisor that keeps each open database in its own idalib worker process. Workers register themselves in a host-local discovery directory and outlive the supervisor that spawned them; any subsequent supervisor that wants the same path adopts the running worker. A worker self-exits when no request has hit it for its idle TTL (default 1 hour). Call idb_close to release a worker eagerly (freeing a slot toward --max-workers), adopted GUI/worker instances are detached rather than killed.
idb_open picks the backend via its mode parameter:
prefer_headless (default): spawn an idalib worker (or adopt one that already has the file open).force_headless: same, but never adopt a running GUI even if one has the file.prefer_gui: adopt a running GUI for the file; otherwise spawn an idalib worker.force_gui: adopt a running GUI for the file; otherwise launch a new IDA GUI process.Every tool call must carry an explicit database argument. There is no implicit "current database" — callers name the session they want to operate on.
Typical flow:
database must be the session ID returned by idb_open (or shown in idb_list); filenames and paths are not accepted.
idb_open(input_path, mode="prefer_headless", run_auto_analysis=True, build_caches=True, init_hexrays=True, preferred_session_id=""): Open a binary, warm up subsystems (strings cache, Hex-Rays), and return its session ID. If a worker or GUI for this path is already running on the host, that instance is adopted and preferred_session_id is ignored.idb_list(): List open sessions and running GUI IDA instances. Each entry has adopted (True if this supervisor manages it, False for GUIs/workers discovered but not yet opened via idb_open), backend (worker or gui), is_active, and process IDs.idb_close(database, save=True): Save (optionally), unregister the session, and terminate its owned worker, freeing a slot toward --max-workers. Adopted GUI/worker instances are detached, not killed.idb_save(session_id, path=""): Save a session's IDB to disk. Forwarded as a regular worker tool (database=<id> injected) — same signature in both backends.server_health(database=<id>) (forwarded). idb_list() reports is_active from the supervisor's TCP/RPC probe.Worker controls:
--max-workers N: maximum simultaneous database workers (0 = unlimited, default 4).IDA_MCP_MAX_WORKERS: environment default for --max-workers.The bundled Codex plugin forwards the runtime's IDA_MCP_* configuration variables from the Codex host environment:
IDA_MCP_MAX_WORKERS, IDA_MCP_OPEN_TIMEOUT, IDA_MCP_WEDGED_GRACE_SEC, IDA_MCP_WORKER_CALL_TIMEOUT.IDA_MCP_HEALTH_TCP_TIMEOUT, IDA_MCP_HEALTH_RPC_TIMEOUT, IDA_MCP_HEALTH_RETRIES, IDA_MCP_HEALTH_RETRY_BACKOFF.IDA_MCP_TOOL_TIMEOUT_SEC, IDA_MCP_ANALYSIS_PROMPT, IDA_MCP_URL.IDA_MCP_LOG_REQUESTS, IDA_MCP_LOG_SKIP_METHODS.Resources represent browsable state (read-only data) following MCP's philosophy.
Core IDB State:
ida://idb/metadata - IDB file info (path, arch, base, size, hashes)ida://idb/segments - Memory segments with permissionsida://idb/entrypoints - Entry points (main, TLS callbacks, etc.)UI State:
ida://cursor - Current cursor position and functionida://selection - Current selection rangeType Information:
ida://types - All local typesida://structs - All structures/unionsida://struct/{name} - Structure definition with fieldsLookups:
ida://import/{name} - Import details by nameida://export/{name} - Export details by nameida://xrefs/from/{addr} - Cross-references from addresslookup_funcs(queries): Get function(s) by address or name (auto-detects, accepts list or comma-separated string).int_convert(inputs): Convert numbers to different formats (decimal, hex, bytes, ASCII, binary).list_funcs(queries): List functions (paginated, filtered).list_globals(queries): List global variables (paginated, filtered).imports(offset, count): List all imported symbols with module names (paginated).decompile(addr): Decompile function at the given address.disasm(addr): Disassemble function with full details (arguments, stack frame, etc).xrefs_to(addrs): Get all cross-references to address(es).xrefs_to_field(queries): Get cross-references to specific struct field(s).callees(addrs): Get functions called by function(s) at address(es).add_bookmark(addr, name, prefix): Add or replace the IDA bookmark at an address; set prefix="" for no prefix.set_comments(items): Set comments at address(es) in both disassembly and decompiler views.patch_asm(items): Patch assembly instructions at address(es).declare_type(decls): Declare C type(s) in the local type library.define_func(items): Define function(s) at address(es). Optionally specify end for explicit bounds.define_code(items): Convert bytes to code instruction(s) at address(es).undefine(items): Undefine item(s) at address(es), converting back to raw bytes. Optionally specify end or size.get_bytes(addrs): Read raw bytes at address(es).get_int(queries): Read integer values using ty (i8/u64/i16le/i16be/etc).get_string(addrs): Read null-terminated string(s).get_global_value(queries): Read global variable value(s) by address or name (auto-detects, compile-time values).stack_frame(addrs): Get stack frame variables for function(s).declare_stack(items): Create stack variable(s) at specified offset(s).delete_stack(items): Delete stack variable(s) by name.read_struct(queries): Read structure field values at specific address(es).search_structs(filter): Search structures by name pattern.Debugger tools are hidden by default. Enable with ?ext=dbg query parameter:
Control:
dbg_start(): Start debugger process.dbg_exit(): Exit debugger process.dbg_continue(): Continue execution.dbg_run_to(addr): Run to address.dbg_step_into(): Step into instruction.dbg_step_over(): Step over instruction.Breakpoints:
dbg_bps(): List all breakpoints.dbg_add_bp(addrs): Add breakpoint(s).dbg_delete_bp(addrs): Delete breakpoint(s).dbg_toggle_bp(items): Enable/disable breakpoint(s).Registers:
dbg_regs(): All registers, current thread.dbg_regs_all(): All registers, all threads.dbg_regs_remote(tids): All registers, specific thread(s).dbg_gpregs(): GP registers, current thread.dbg_gpregs_remote(tids): GP registers, specific thread(s).dbg_regs_named(names): Named registers, current thread.dbg_regs_named_remote(tid, names): Named registers, specific thread.Stack & Memory:
dbg_stacktrace(): Call stack with module/symbol info.dbg_read(regions): Read memory from debugged process.dbg_write(regions): Write memory to debugged process.py_eval(code): Execute arbitrary Python code in IDA context (returns dict with result/stdout/stderr, supports Jupyter-style evaluation).analyze_funcs(addrs): Comprehensive function analysis (decompilation, assembly, xrefs, callees, callers, strings, constants, basic blocks).find_regex(queries): Search strings with case-insensitive regex (paginated).find_bytes(patterns, limit=1000, offset=0): Find byte pattern(s) in binary (e.g., "48 8B ?? ??"). Max limit: 10000.find_insns(sequences, limit=1000, offset=0): Find instruction sequence(s) in code. Max limit: 10000.find(type, targets, limit=1000, offset=0): Advanced search (immediate values, strings, data/code references). Max limit: 10000.basic_blocks(addrs): Get basic blocks with successors and predecessors.set_type(edits): Apply type(s) to functions, globals, locals, or stack variables.infer_types(addrs): Infer types at address(es) using Hex-Rays or heuristics.export_funcs(addrs, format): Export function(s) in specified format (json, c_header, or prototypes).callgraph(roots, max_depth): Build call graph from root function(s) with configurable depth.rename(batch): Unified batch rename operation for functions, globals, locals, and stack variables (accepts dict with optional func, data, local, stack keys).patch(patches): Patch multiple byte sequences at once.put_int(items): Write integer values using ty (i8/u64/i16le/i16be/etc).Key Features:
[{..., error: null|string}, ...]cursor: {next: offset} or {done: true} (default limit: 1000, enforced max: 10000 to prevent token overflow)build_strlist calls in large projectsAdding new features is a super easy and streamlined process. All you have to do is add a new @tool function to the modular API files in src/ida_pro_mcp/ida_mcp/api_*.py and your function will be available in the MCP server without any additional boilerplate! Below is a video where I add the get_metadata function in less than 2 minutes (including testing):
https://github.com/user-attachments/assets/951de823-88ea-4235-adcb-9257e316ae64
To test the MCP server itself:
This will open a web interface at http://localhost:5173 and allow you to interact with the MCP tools for testing.
For testing I create a symbolic link to the IDA plugin and then POST a JSON-RPC request directly to http://localhost:13337/mcp. After enabling symbolic links you can run the following command:
Generate the changelog of direct commits to main: