█

AI/TLDR

IDA Pro MCP

Let an LLM read and annotate a binary inside your IDA database

Security AgentsOpen source
Language
Python
License
MIT

Overview

IDA Pro MCP connects IDA Pro to an LLM client over the Model Context Protocol. It installs as an IDA plugin and exposes the parts of the disassembler an analyst actually uses — decompilation, disassembly, cross-references, the call graph, basic blocks, byte and string reads — as MCP tools an agent can call while you work.

Crucially it is not read-only. The server also exposes the annotation side of reverse engineering: renaming functions and variables, setting comments, declaring and inferring types, defining functions and code, editing stack frames and reading structures. That means an agent can work through an unfamiliar binary and leave its conclusions in the IDA database, where they persist for you rather than living in a chat log.

An optional debugger extension adds runtime control — starting and exiting the debugger, continuing, stepping, and managing breakpoints — so the same agent can drive dynamic analysis alongside the static view.

What it does

  • Static analysis tools: decompile, disasm, lookup_funcs, xrefs_to, callees, callgraph and basic_blocks
  • Search across the database: find_regex, find_bytes, find_insns and a general find
  • Write-back annotation: rename, set_comments, set_type, infer_types, declare_type, define_func and define_code
  • Memory and data access: get_bytes, get_int, get_string, get_global_value and struct reads
  • Optional debugger extension for breakpoints, stepping and reading or writing live memory
  • Works with any MCP client; ships a Claude Code plugin via the author's marketplace

Getting started

IDA Pro MCP needs IDA Pro 8.3 or newer (9 recommended — IDA Free is not supported), Python 3.11+ inside IDA, the uv package manager, and idalib activated globally.

Activate idalib for your IDA install

Run the activation script that ships with IDA. Adjust the path to match your version and platform.

bashbash
# macOS
uv run "/Applications/IDA Professional 9.3.app/Contents/MacOS/idalib/python/py-activate-idalib.py"
# Linux
uv run "/path/to/idapro-9.3/idalib/python/py-activate-idalib.py"
# Windows
uv run "C:\Program Files\IDA Professional 9.3\idalib\python\py-activate-idalib.py"

Install the plugin and wire up your MCP client

The --install flag registers the IDA plugin and writes the MCP configuration for the clients it detects.

bashbash
pip install https://github.com/mrexodia/ida-pro-mcp/archive/refs/heads/main.zip
ida-pro-mcp --install

Or install it as a Claude Code plugin

The author publishes a marketplace entry, which is the quickest route if Claude Code is your client.

bashbash
claude plugin marketplace add mrexodia/claude-marketplace
claude plugin install ida-pro-mcp@mrexodia

Open a binary and ask

With a database open in IDA, the MCP tools become available to your client. Ask it to decompile a function, trace callers, or rename and comment a region it has worked out — the changes land in the IDA database.

Commands and code are distilled from the project's own documentation — always check the official repo for the latest.

When to use it

  • Reach for it when triaging an unfamiliar binary and you want a first pass of named functions and comments before you read it yourself
  • Reach for it for malware analysis, where an agent can follow cross-references and summarise what each branch does
  • Reach for it when recovering types and structures, using infer_types and declare_type to rebuild a struct layout
  • Reach for it in CTF reversing, where the loop of decompile, rename, re-read is exactly what an agent can iterate quickly

How IDA Pro MCP compares

IDA Pro MCP alongside other open-source security agents tools AI/TLDR tracks, ranked by GitHub stars.

ToolStarsWhat it does
PentAGI★ 25.2kPentAGI is a self-hosted AI security platform that plans and runs penetration tests autonomously using a team of agents and 20+ built-in pentesting tools.
PentestGPT★ 15.7kAn open-source agent that uses large language models to run penetration tests and solve security challenges, either fully autonomously or with a human in the loop.
IDA Pro MCP★ 12.4kLet an LLM read and annotate a binary inside your IDA database
HexStrike AI★ 12.3kAn MCP server that gives an AI agent a single interface to 150+ installed security tools — Nmap, Nuclei, SQLMap, Ghidra, Hashcat and more — so it can drive reconnaissance, scanning and binary analysis itself.
CAI★ 9.8kCAI (Cybersecurity AI) is an open-source Python framework for building AI agents that automate offensive and defensive security tasks like recon, vulnerability discovery, and exploitation.
AI-Infra-Guard★ 6.7kTencent Zhuque Lab's AI red teaming platform: scans agents, Agent Skills and MCP servers, checks AI infra against a CVE library, fingerprints API relays and runs jailbreak evaluations.
T3MP3ST★ 6.3kA multi-agent offensive-security harness for authorised testing that drives an already-installed coding agent, or a local OpenAI-compatible model, through recon, exploitation and reporting from a localhost War Room or the CLI.
RedAmon★ 2.9kA Docker-deployed offensive-security platform for authorised testing that chains parallel recon, exploitation and post-exploitation into a Neo4j attack graph, then triages the findings and opens remediation pull requests on your repository.