Skip to main content

idamesh

A Model Context Protocol (MCP) server for IDA Pro. It exposes IDA's disassembler and the Hex-Rays decompiler to MCP clients (Claude and others) as tools and resources, with a supervisor that fronts multiple databases behind one endpoint so several agents can work in parallel.

What it does

  • Read — decompile (Hex-Rays), disassemble, cross-references, call graphs, type and struct inspection, memory reads, and string / byte / text search.
  • Query — structured filters over functions, instructions, xrefs, types, imports.
  • Analyze — survey / triage, crypto and dangerous-API detection, vulnerability heuristics, stack-string reconstruction, and dataflow / taint tracing.
  • Mutate — rename, comment, retype, define code and data, edit stack frames, patch bytes / assembly, bookmarks, and annotation export / import.
  • Parallelize — open each database over a private copy so multiple agents can work the same binary at once, and merge their edits back into one database.

Read-only IDB state is also projected as ida://… MCP resources.

Requirements

  • Python 3.9+
  • A licensed IDA Pro install providing the idapro / idalib Python API. Point the IDADIR environment variable at your IDA installation directory.

Install

pip install -e .          # runtime (zero third-party dependencies)
pip install -e .[dev]     # + pytest, to run the test suite

This provides the idamesh command with three subcommands: worker, supervisor, and install.

Usage

Headless worker — one database on stdio (the client launches it):

idamesh worker /path/to/target.exe

Supervisor — one HTTP endpoint fronting many databases:

idamesh supervisor                       # http://127.0.0.1:8745/mcp

Open and close databases behind it with the idb_open / idb_list / idb_close tools; route any tool to a session with an optional database key (omit it when a single database is open). Opening the same binary twice yields two independent sessions; idb_merge reconciles their edits.

GUI plugin — serve MCP over your live, open IDA database:

idamesh install     # deploy the plugin into IDA's user directory, then restart IDA

Run idamesh supervisor (or set IDAMESH_AUTOLAUNCH_SUPERVISOR=1 to have the plugin start one), then open a binary in IDA — the supervisor adopts the live session and routes to it.

Both the worker (--transport http) and the supervisor speak MCP Streamable HTTP at a single /mcp endpoint, loopback-bound with Origin validation.

Connect from Claude Code

claude mcp add --scope user --transport http idamesh http://127.0.0.1:8745/mcp

Or launch a single stdio worker directly:

claude mcp add --scope user -e IDADIR=/path/to/IDA-Pro \
  idamesh -- idamesh worker /path/to/target.exe

Tests

pip install -e .[dev]
python -m pytest -q

The live idalib end-to-end tests skip cleanly when IDA is unavailable (no IDADIR), so the suite is green without an IDA install.

License

MIT.

Metadata

Release files for idamesh 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for idamesh 1.0.0
File Size Uploaded
idamesh-1.0.0.tar.gz 297.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for idamesh 1.0.0
File Interpreter ABI Platform
idamesh-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 773.0 kB

Release files / idamesh-1.0.0.tar.gz

Download URL idamesh-1.0.0.tar.gz
Size 297.6 kB
Tags Source
SHA-256 checksum
How to use checksums
97cf68a4261fe7d77063ece21b8fd475543c81e2805164554c4e0c34ce5360a7
BLAKE2b-256 checksum
How to use checksums
9759dac072e4345455ceb7b961f2384908d2e5b3eaee28de8ad6d432f30637d4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.10

Release files / idamesh-1.0.0-py3-none-any.whl

Download URL idamesh-1.0.0-py3-none-any.whl
Size 475.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
06e75848f903424d3771aa3b4c0b0eddb63ed6b5450d693de7108fa39d10433f
BLAKE2b-256 checksum
How to use checksums
a22d7b8fe06145d6bd9bbde8271676bf4ded65cd9f837eb9caa821aa22f983b2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.10

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page