re-mcp-ghidra
Ghidra backend for RE-MCP — a headless Ghidra MCP server using pyghidra. Exposes Ghidra's analysis capabilities over the Model Context Protocol, letting LLMs drive reverse engineering directly.
This is a standalone server, not a Ghidra plugin. It uses pyghidra to run Ghidra's analysis engine without a GUI.
Requirements
- Python 3.12+
- Ghidra 12+
- JDK 21+
- macOS, Windows, or Linux
Installation
uv tool install re-mcp-ghidra
Or with pip:
pip install re-mcp-ghidra
Finding Ghidra
The server looks for your Ghidra installation in the following order:
GHIDRA_INSTALL_DIRenvironment variable — set this if Ghidra is in a non-standard location.- Config file —
ghidra-install-dirin~/.ghidra/ghidra-config.json. - Platform-specific default paths (e.g.
/Applications/ghidra_*on macOS).
See the main documentation for the full list of default search paths per platform.
Usage
# Run the server (direct stdio mode)
re-mcp-ghidra
# Or with uvx (no install needed)
uvx re-mcp-ghidra
MCP client configuration
{
"mcpServers": {
"ghidra": {
"command": "uvx",
"args": ["re-mcp-ghidra"]
}
}
}
CLI subcommands
| Command | Description |
|---|---|
re-mcp-ghidra (or re-mcp-ghidra stdio) |
Direct stdio mode — single-session, workers die on disconnect (default) |
re-mcp-ghidra proxy |
Stdio proxy that auto-spawns a persistent HTTP daemon |
re-mcp-ghidra serve |
Start the HTTP daemon directly |
re-mcp-ghidra stop |
Gracefully shut down a running daemon |
re-mcp-ghidra backends |
List installed backends |
Environment variables
| Variable | Default | Description |
|---|---|---|
GHIDRA_INSTALL_DIR |
(auto-detected) | Path to Ghidra installation directory |
GHIDRA_MCP_MAX_WORKERS |
(unlimited) | Maximum simultaneous databases (1-8) |
GHIDRA_MCP_LOG_LEVEL |
WARNING |
Logging level |
GHIDRA_MCP_LOG_DIR |
(unset) | Directory for per-run log files |
GHIDRA_MCP_IDLE_TIMEOUT |
300 |
Auto-shutdown timeout in seconds (0 to disable) |
Features
- Full decompilation and disassembly
- Function, type, and structure management
- Cross-reference and call graph analysis
- String and byte pattern search
- Binary patching and instruction assembly
- Function ID and data type archive support
- Multi-database support with concurrent analysis
- MCP resources for structured read-only access
See the main documentation for the full tool catalog, multi-database workflows, and detailed usage.
License
Dual-licensed under MIT and Apache-2.0.
Metadata
Release files for re-mcp-ghidra 3.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| re_mcp_ghidra-3.0.3.tar.gz | 62.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| re_mcp_ghidra-3.0.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 168.0 kB
Release files / re_mcp_ghidra-3.0.3.tar.gz
| Download URL | re_mcp_ghidra-3.0.3.tar.gz |
|---|---|
| Size | 62.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
cc3c13a45d4947032cd6d38eb7badf150d1a8038d83a31c9e4fe564ddf0b1a84
|
|
BLAKE2b-256 checksum How to use checksums |
90067b0e8f57d529bca615e710db8cb186fc45aa4a761dd2a8d595fd6fa9d047
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 15, 2026.
Transparency logRelease files / re_mcp_ghidra-3.0.3-py3-none-any.whl
| Download URL | re_mcp_ghidra-3.0.3-py3-none-any.whl |
|---|---|
| Size | 105.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0839e539b9d59786a4ab4b5fb22c8561c319d36a77f9df58aa2e0cf78d442ee5
|
|
BLAKE2b-256 checksum How to use checksums |
59d18438e3478c82f0d48d05135e3717460aa4ddb08c50de69a665d68bc207ef
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 15, 2026.
Transparency log