bindiff-mcp
MCP server that gives reverse-engineering agents binary diffing: export binaries to BinExport v2 and compare two builds with BinDiff.
IDA is driven through ida-nexus, so a binary already open in the IDA GUI is exported from that database (renames and annotations included); otherwise a headless idalib worker is spawned and released again when the export finishes. Export and diff parsing reuse python-binexport and python-bindiff.
Prerequisites
- IDA Pro 9.x with idalib enabled (
idapyswitch),IDADIRpointing at the install - The BinExport IDA plugin (
binexport12_ida.so) in$IDAUSR/plugins - The BinDiff differ (
bindiff) inPATH, in$BINDIFF_PATH, default at/opt/zynamics/BinDiff/bin libmagic(used by python-binexport through python-magic)
Install
uv pip install .
Run
bindiff-mcp stdio # stdio transport (default)
bindiff-mcp http --host 127.0.0.1 --port 8745 # Streamable HTTP at /mcp
Register with Claude Code:
claude mcp add bindiff -- bindiff-mcp stdio
claude mcp add bindiff --transport http http://127.0.0.1:8745/mcp
Tools
binexport(binary, output_results_dir=".")
Exports binary to <output_results_dir>/<binary name>.BinExport. An export
that is at least as new as the binary is reused instead of re-analyzing it.
Returns JSON:
{
"binary": "/work/httpd",
"binexport": "/work/out/httpd.BinExport",
"reused": false,
"name": "httpd",
"architecture": "x86-64",
"sha256": "...",
"functions": 2317
}
bindiff_compare(primary_binary, secondary_binary, output_results_dir=".")
Exports both binaries in parallel (into primary/ and secondary/
subdirectories, so identical file names cannot collide), runs the differ, and
writes four JSON files into output_results_dir:
| File | Content |
|---|---|
matched_similar.json |
matched functions with similarity 1.0 (identical) |
matched_different.json |
matched functions that changed, most divergent first |
primary_only.json |
functions only in the primary binary |
secondary_only.json |
functions only in the secondary binary |
Match entries carry both addresses and names, the similarity and confidence
scores and the BinDiff algorithm that produced the match; unmatched entries
carry address, name and function type. The tool returns JSON with the overall
similarity and confidence, the .BinDiff database path, per-list counts and the
path of every file written.
Environment
| Variable | Default | Meaning |
|---|---|---|
BINDIFF_MCP_OPEN_TIMEOUT |
600 |
Seconds to wait for IDA to open a database |
BINDIFF_MCP_EXPORT_TIMEOUT |
1800 |
Seconds for one export, excluding autoanalysis |
BINDIFF_PATH |
— | Directory containing the bindiff differ |
Metadata
Release files for bindiff-mcp 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| bindiff_mcp-1.0.0.tar.gz | 14.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| bindiff_mcp-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 28.5 kB
Release files / bindiff_mcp-1.0.0.tar.gz
| Download URL | bindiff_mcp-1.0.0.tar.gz |
|---|---|
| Size | 14.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ab56a59f7c555a0fcd24c5e448dec5e84e08ae7e5ebb303eaa986df1d53d5a1d
|
|
BLAKE2b-256 checksum How to use checksums |
f7bd27092ffcc7ff27434808c461101a1b6797e9e626f7f8a84e136caa90926c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / bindiff_mcp-1.0.0-py3-none-any.whl
| Download URL | bindiff_mcp-1.0.0-py3-none-any.whl |
|---|---|
| Size | 13.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cee9c744593ee25f7755bcd9e0e6ac6094b59ea0058165acb7f175920ea6de84
|
|
BLAKE2b-256 checksum How to use checksums |
33b975bac55a6baa7460b68e356544c6c43b255d2dd77cc7317ce2e2daa4e4b7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|