PluginBench
MCP Server
Maintained
MIT

io.github.johnzfitch/pyghidra-lite MCP Server

io.github.johnzfitch/pyghidra-lite

Token-efficient Ghidra reverse engineering for AI agents—decompile, xrefs, and annotate ELF/Mach-O/PE binaries with Swift/ObjC support.

What is the io.github.johnzfitch/pyghidra-lite MCP server?

The pyghidra-lite MCP server is a read-only-by-default Ghidra integration for reverse engineering binaries via Claude and other AI agents. It provides decompilation, cross-reference analysis, and optional human-confirmed annotation (rename/comment/prototype) for ELF, Mach-O, and PE formats, with auto-detection of Swift, Objective-C, and Hermes code.

pyghidra-lite lets AI agents analyze compiled binaries using Ghidra's decompilation and analysis engine while keeping token usage minimal and maintaining security through read-only defaults and human-in-the-loop write confirmation. It auto-detects binary format and language, supports parallel analysis of multiple binaries, and persists findings in a shared project store.

How to install io.github.johnzfitch/pyghidra-lite

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • GHIDRA_INSTALL_DIR

    Path to Ghidra installation directory

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "python",
      "args": [
        "pyghidra-lite"
      ],
      "env": {
        "GHIDRA_INSTALL_DIR": "<YOUR_GHIDRA_INSTALL_DIR>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • load — Import and analyze a binary with configurable analysis profile (fast/default/deep), optional bootstrap from prior build, and fresh re-analysis.
  • delete — Remove a binary and cancel any in-progress analysis jobs.
  • binaries — List loaded binaries with job status and optional ranking by source.
  • info — Get binary overview with configurable detail level (summary/full/format/sections/entropy).
  • functions — List or search functions with filtering by type (all/swift/objc/imports/exports).
  • code — Decompile or disassemble a target with optional control-flow graph (CFG).
  • xrefs — Analyze references and call graphs with configurable direction, depth, and diff mode.
  • search — Find strings, bytes, or symbols with optional background execution.
  • annotate — Rename, comment, or set prototype for a function or symbol (write-only, opt-in via --allow-write, requires human confirmation).

Use cases

  • Decompile and analyze obfuscated binaries to understand malware or proprietary code behavior.
  • Track function renames and signatures across binary versions using bootstrap mode for version-to-version comparison.
  • Search for hardcoded credentials, API keys, or suspicious strings across compiled applications.
  • Map call graphs and cross-references to identify entry points and data flow in complex binaries.
  • Persist reverse-engineering findings (function names, comments, prototypes) back to the Ghidra project with human approval.

io.github.johnzfitch/pyghidra-lite MCP server FAQ

What is pyghidra-lite?

pyghidra-lite is an MCP server that exposes Ghidra's reverse-engineering capabilities (decompilation, cross-references, symbol search) to Claude and other AI agents. It supports ELF, Mach-O, and PE binaries with auto-detection of Swift, Objective-C, and Hermes code.

Is pyghidra-lite free?

Yes, pyghidra-lite is MIT-licensed and free. It requires JDK 21+ and Ghidra 11.x, both of which are free and open-source.

How do I install it in Claude Desktop?

Add pyghidra-lite to your Claude Desktop config at ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows) with the command 'uvx' and args ['pyghidra-lite']. Ghidra is auto-detected; set GHIDRA_INSTALL_DIR in env if needed.

How do I install it in Claude Code?

Create .mcp.json in your project (or ~/.claude.json globally) with the command 'pyghidra-lite'. For explicit Ghidra path, use args ['serve', '--ghidra-dir', '/path/to/ghidra'].

Is pyghidra-lite read-only by default?

Yes. All tools are read-only by default. The annotate tool (rename/comment/prototype) is disabled unless you start the server with --allow-write, and every change requires human confirmation via MCP elicitation before it's committed.

What authentication is required?

None for local use. For network access (HTTP/SSE transport on non-loopback), a bearer token (--auth-token) and --restrict-path are required, with optional DNS-rebinding protection via --allowed-host.

README (reference)

Source of truth, from the repository.

pyghidra-lite

PyPI Python License MCP

<!-- mcp-name: io.github.johnzfitch/pyghidra-lite -->

Token-efficient MCP server for Ghidra-based reverse engineering. Analyze ELF, Mach-O, and PE binaries with Swift, Objective-C, and Hermes support.

Bottom line: a lean, security-first Ghidra MCP. It is read-only by default — analysis tools never mutate your binaries or the server's configuration (which is frozen for the life of the process). The one tool that writes, annotate (rename / comment / prototype), is opt-in (--allow-write) and human-confirmed: every change is approved by you through an MCP elicitation prompt before it's committed, and it fails closed if your client can't ask. You get an analyst-agent that can persist its findings — under supervision — without giving up the read-only safety story.

Quick Start

1. Prerequisites

JDK 21+ and Ghidra 11.x are required.

# macOS
brew install openjdk@21
brew install ghidra

# Ubuntu/Debian
sudo apt install openjdk-21-jdk
# Download Ghidra from https://ghidra-sre.org

# Arch Linux
sudo pacman -S jdk21-openjdk
yay -S ghidra

Ghidra installed via Homebrew (brew install ghidra) or to /opt/ghidra or ~/ghidra is found automatically. Set GHIDRA_INSTALL_DIR only for non-standard paths.

2. Install pyghidra-lite

pip install pyghidra-lite

3. Add to Claude Code

Create .mcp.json in your project (or ~/.claude.json for global):

{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "pyghidra-lite"
    }
  }
}

4. Use it

You: Analyze the binary at /path/to/binaries/app

Claude: [calls load, info, code...]

Installation

PyPI (recommended)

pip install pyghidra-lite

Arch Linux (AUR)

yay -S python-pyghidra-lite

From source

git clone https://github.com/johnzfitch/pyghidra-lite
cd pyghidra-lite
pip install -e .

MCP Configuration

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "uvx",
      "args": ["pyghidra-lite"]
    }
  }
}

uvx auto-installs pyghidra-lite from PyPI on first run. Ghidra is auto-detected; set GHIDRA_INSTALL_DIR in env if needed:

{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "uvx",
      "args": ["pyghidra-lite"],
      "env": {
        "GHIDRA_INSTALL_DIR": "/path/to/ghidra"
      }
    }
  }
}

Claude Code

Create .mcp.json in your project (or ~/.claude.json for global):

{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "pyghidra-lite"
    }
  }
}

Direct mode (skip proxy)

For single-session use or debugging, run the server directly:

{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "pyghidra-lite",
      "args": ["serve"]
    }
  }
}

With explicit Ghidra path

{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "pyghidra-lite",
      "args": [
        "serve",
        "--ghidra-dir", "/path/to/ghidra"
      ]
    }
  }
}

Restrict to specific paths

By default, pyghidra-lite can load binaries from any path (the MCP client handles permissions). Use --restrict-path to lock down access:

{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "pyghidra-lite",
      "args": [
        "serve",
        "--restrict-path", "/home/user/binaries",
        "--restrict-path", "/opt/targets"
      ]
    }
  }
}

Shared HTTP transport (network access)

The HTTP/SSE transports are shared and apply DNS-rebinding protection (Host/Origin validation). Binding to a non-loopback address additionally requires both --restrict-path and a bearer token:

pyghidra-lite serve -t streamable-http --host 0.0.0.0 \
  --restrict-path /opt/targets \
  --auth-token "$PYGHIDRA_LITE_AUTH_TOKEN" \
  --allowed-host re.example.com:8000   # if fronted under another hostname

Clients then send Authorization: Bearer <token> on every request. Terminate TLS at a reverse proxy for remote access.

Tools (9)

pyghidra-lite provides 8 read-only analysis tools plus 1 opt-in write tool, all auto-detecting format (ELF/Mach-O/PE) and language (Swift/ObjC/Hermes):

ToolPurposeKey Parameters
loadImport and analyze binarypath, profile?, fresh?, bootstrap?, bootstrap_mode?
deleteRemove binary and cancel jobsname
binariesList binaries + job statusjobs?, rank_sources?
infoBinary overviewbinary, detail? (summary/full/format/sections/entropy)
functionsList/search functionsbinary, query?, type? (all/swift/objc/imports/exports)
codeDecompile or disassemblebinary, target, what? (decompile/asm), cfg?
xrefsReferences and call graphsbinary, target, direction?, depth?, diff?
searchFind strings, bytes, symbolsbinary, query, type?, mode?, bg?
annotate 🔒Rename / comment / set prototypebinary, target, action, name?/comment?/prototype?

🔒 annotate is the only tool that writes. It is disabled unless the server is started with --allow-write, and every change requires interactive confirmation (MCP elicitation) before it is committed — clients that can't confirm get a preview only. See Writing back.

Examples

# Import and analyze
load("/path/to/binary", profile="fast")

# Version-track from a prior build, including synthetic IDs for unnamed code
load("/path/to/new.bin", profile="deep", bootstrap="old.bin", bootstrap_mode="all")

# Get overview with full triage
info("mybinary", detail="full")

# List Swift functions
functions("mybinary", type="swift")

# Decompile with CFG
code("mybinary", "main", cfg=True)

# Search strings in background
search("mybinary", ["password", "api_key"], bg=True)

# Get cross-references
xrefs("mybinary", "malloc", depth=2)

Auto-Detection

All tools automatically detect:

  • Format: ELF, Mach-O, PE
  • Language: Swift, Objective-C, Hermes/React Native
  • Runtime: Bun, Node.js, Electron, PyInstaller

Use the type and detail parameters to access format/language-specific features.

Bootstrap Modes

  • bootstrap_mode="named": transfer only meaningful source names (default).
  • bootstrap_mode="all": also assign stable synthetic labels to source FUN_* functions during transfer, which is useful for large version-to-version bootstrap workflows where uniqueness matters more than semantics.

Writing back

By default pyghidra-lite is read-only — no tool mutates your binaries. To let an agent persist findings (rename a function, attach a comment, fix a prototype), start the server with --allow-write:

pyghidra-lite serve --allow-write          # or PYGHIDRA_LITE_ALLOW_WRITE=1

Then the annotate tool becomes usable:

annotate("mybinary", target="FUN_00401000", action="rename", name="parse_header")
annotate("mybinary", target="parse_header", action="comment", comment="validates the v2 header")
annotate("mybinary", target="parse_header", action="prototype", prototype="int parse_header(char *buf, int len)")

Every call is human-confirmed: the server sends an MCP elicitation prompt showing the exact old -> new change, and only commits if you accept. If the server was started without --allow-write, the tool refuses; if your MCP client doesn't support elicitation, the tool returns a preview with applied: false and writes nothing (fail closed). Confirmed changes are written in a single Ghidra transaction and saved to the on-disk project.

Audit journal. Because MCP elicitation ultimately trusts the client (an autonomous "auto-approve" client can self-confirm), every write is recorded in annotate_audit.jsonl next to the projects — and every declined or failed attempt is logged too. Each line records old -> new, so the journal is both an accountability trail and an undo log; a flood of entries is your signal that an auto-agent is churning, and the server also nudges (ctx.warning) as write volume climbs. The journal is fail-closed and hardened: a write is recorded before it's applied (if it can't be journaled, it isn't committed), the file is created 0o600 and opened with O_NOFOLLOW (a symlinked journal is refused), and it rotates by size so it can't grow without bound.

Analysis Profiles

ProfileUse Case
fastQuick triage, disables 20 slow analyzers (default)
defaultBalanced, full Ghidra analysis
deepThorough analysis for obfuscated code

The server defaults to fast to stay within MCP timeout limits. Use load(fresh=True) to run deeper analysis when needed:

# Default import uses fast profile
load("/path/to/binary")

# Re-analyze with deep profile
load("/path/to/binary", profile="deep", fresh=True)

Token Efficiency

pyghidra-lite is designed for minimal token usage:

  • Compact output by default - functions(binary, type="all") returns minimal {name, addr} pairs
  • Opt-in detail - use info(detail="full"), code(cfg=True), or richer type/what modes only when needed
  • Progress reporting - large imports report progress every 10% or 60s
  • Truncated strings - long strings capped at 500 chars

Architecture

By default, pyghidra-lite runs as a lightweight stdio proxy (~10MB) that forwards to a persistent shared HTTP backend (~500MB JVM). Multiple sessions share a single JVM instead of each spawning their own.

Claude Code session 1 ──stdio──> proxy ──┐
Claude Code session 2 ──stdio──> proxy ──┼──HTTP──> shared backend (1 JVM)
Claude Code session 3 ──stdio──> proxy ──┘        localhost:19101

The proxy auto-starts the backend on first use and the backend auto-exits after 30 minutes of idle. A file lock prevents concurrent proxy starts from spawning duplicate backends.

CommandWhat it does
pyghidra-liteStdio proxy (default) -- auto-starts backend
pyghidra-lite serveDirect stdio server (1 JVM per session)
pyghidra-lite serve -t streamable-httpStart persistent HTTP backend manually
pyghidra-lite stopStop the shared backend

Set PYGHIDRA_LITE_NO_AUTOSTART=1 to disable auto-start (useful with systemd).

Multi-Agent Support

Each binary gets its own Ghidra project, enabling:

  • Parallel analysis of different binaries
  • Shared results across agents
  • Persistent analysis (survives restarts)
  • Content-addressed storage (same binary = same analysis)

Projects stored in ~/.local/share/pyghidra-lite/projects/.

Links

License

MIT

Related MCP servers

KAKalshi MCP Server logo

Self-hosted MCP server for Kalshi prediction market trading via DFlow on Solana

1
TypeScript
View repository →

MCP server for Limitless Exchange prediction markets on Base

0
TypeScript
View repository →

Self-hosted MCP server for AI agent trading on Polymarket prediction markets

0
TypeScript
View repository →

FCoP Core adapter with 25 canonical tools and 6 read-only resources for durable agent work.

2
Python
MIT
View repository →

smartfetch direct-URL fetch, smartsearch web discovery, smartcrawl sites, and docs export MCP.

View repository →

Browser tasks, sessions, and recipes for MCP and HTTP automation.

View repository →