Skip to main content

bindiff-mcp

MCP server that gives reverse-engineering agents binary diffing: export binaries to BinExport v2 and compare two builds with BinDiff.

IDA is driven through ida-nexus, so a binary already open in the IDA GUI is exported from that database (renames and annotations included); otherwise a headless idalib worker is spawned and released again when the export finishes. Export and diff parsing reuse python-binexport and python-bindiff.

Prerequisites

  • IDA Pro 9.x with idalib enabled (idapyswitch), IDADIR pointing at the install
  • The BinExport IDA plugin (binexport12_ida.so) in $IDAUSR/plugins
  • The BinDiff differ (bindiff) in PATH, in $BINDIFF_PATH, default at /opt/zynamics/BinDiff/bin
  • libmagic (used by python-binexport through python-magic)

Install

uv pip install .

Run

bindiff-mcp stdio                              # stdio transport (default)
bindiff-mcp http --host 127.0.0.1 --port 8745  # Streamable HTTP at /mcp

Register with Claude Code:

claude mcp add bindiff -- bindiff-mcp stdio
claude mcp add bindiff --transport http http://127.0.0.1:8745/mcp

Tools

binexport(binary, output_results_dir=".")

Exports binary to <output_results_dir>/<binary name>.BinExport. An export that is at least as new as the binary is reused instead of re-analyzing it. Returns JSON:

{
  "binary": "/work/httpd",
  "binexport": "/work/out/httpd.BinExport",
  "reused": false,
  "name": "httpd",
  "architecture": "x86-64",
  "sha256": "...",
  "functions": 2317
}

bindiff_compare(primary_binary, secondary_binary, output_results_dir=".")

Exports both binaries in parallel (into primary/ and secondary/ subdirectories, so identical file names cannot collide), runs the differ, and writes four JSON files into output_results_dir:

File Content
matched_similar.json matched functions with similarity 1.0 (identical)
matched_different.json matched functions that changed, most divergent first
primary_only.json functions only in the primary binary
secondary_only.json functions only in the secondary binary

Match entries carry both addresses and names, the similarity and confidence scores and the BinDiff algorithm that produced the match; unmatched entries carry address, name and function type. The tool returns JSON with the overall similarity and confidence, the .BinDiff database path, per-list counts and the path of every file written.

Environment

Variable Default Meaning
BINDIFF_MCP_OPEN_TIMEOUT 600 Seconds to wait for IDA to open a database
BINDIFF_MCP_EXPORT_TIMEOUT 1800 Seconds for one export, excluding autoanalysis
BINDIFF_PATH — Directory containing the bindiff differ

Metadata

Release files for bindiff-mcp 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bindiff-mcp 1.0.0
File Size Uploaded
bindiff_mcp-1.0.0.tar.gz 14.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for bindiff-mcp 1.0.0
File Interpreter ABI Platform
bindiff_mcp-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 28.5 kB

Release files / bindiff_mcp-1.0.0.tar.gz

Download URL bindiff_mcp-1.0.0.tar.gz
Size 14.8 kB
Tags Source
SHA-256 checksum
How to use checksums
ab56a59f7c555a0fcd24c5e448dec5e84e08ae7e5ebb303eaa986df1d53d5a1d
BLAKE2b-256 checksum
How to use checksums
f7bd27092ffcc7ff27434808c461101a1b6797e9e626f7f8a84e136caa90926c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / bindiff_mcp-1.0.0-py3-none-any.whl

Download URL bindiff_mcp-1.0.0-py3-none-any.whl
Size 13.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cee9c744593ee25f7755bcd9e0e6ac6094b59ea0058165acb7f175920ea6de84
BLAKE2b-256 checksum
How to use checksums
33b975bac55a6baa7460b68e356544c6c43b255d2dd77cc7317ce2e2daa4e4b7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page