
MCP server integrating IDA Pro with AI agents, featuring a stateless gateway for multi-session management, a relational SQL query engine for binary analysis, and architecture-agnostic disassembly and patching tools.
This project provides a Model Context Protocol (MCP) server for integrating IDA Pro with AI agents like Gemini, Claude, and Jetski. It features a gateway-based proxy architecture, an embedded relational SQLite query engine, and headless session management to support advanced reverse engineering workflows.
Back in 2025, when we began integrating AI agents with IDA Pro, the upstream
ida-pro-mcp project provided a
great initial starting point. At the time, it did not yet offer multi-session
workflows, which were essential for our daily reverse engineering needs.
To address our internal use cases, we began building experimental solutions:
sqlglot). Because queries execute against SQLite in worker threads, they
support concurrent reads without acquiring IDA's main thread lock or
blocking the UI.Over time, as we added more features, optimizations, and compatibility layers across multiple IDA versions (IDA 7.7 through 9.4) and Python versions, the codebase diverged substantially into an independent project with its own design trade-offs.
We are sharing this project as an alternative, gateway- and SQL-centric approach for connecting AI agents to IDA Pro, and we remain grateful to Duncan Ogilvie and the upstream contributors for the foundational work that inspired this effort.
Key capabilities of this implementation include:
Stateless Gateway: A proxy layer allows agents to interact with multiple IDA Pro instances (GUI and Headless) concurrently. The gateway automatically discovers and manages connections, allowing users to open and close databases without reconfiguring the client.
Headless Mode: Perform analysis in the background without the IDA Pro GUI, suitable for automated workflows. Sessions can be managed directly by the AI agent.
Relational SQL Engine: Integrates a read-only SQLite relational database
populated on-demand and synchronized via IDA event hooks. Tables
(functions, strings, names, imports, segments, local_types,
xrefs, entries) support concurrent background queries without blocking
IDA's main UI thread, while an AST query layer (sqlglot) handles unsigned
64-bit arithmetic, comparison rewriting, and hex literals.
WYSIWYG Disassembly: Disassembly tools (like disassemble_function and
disassemble_code) return formatted text matching the IDA Pro UI, including
opcode bytes, data definitions, and comments. Includes get_ida_view for
viewing arbitrary memory ranges.
Analysis & Modification Tools: Includes tools for UI navigation
(jump_to_address, set_color), memory inspection (hexdump), byte
patching (patch_bytes), database exporting (export_file),
cross-references (get_xrefs_from, get_data_xrefs_from), and structured
data creation.
Context-Aware Assembly Patching: Powered by Keystone at the Gateway
layer, the patch_assembly tool allows assembling and applying instructions
directly at target addresses. It can resolve IDA symbols (function names,
labels, globals) within assembly strings and evaluate basic operand math
across supported architectures (x86/x64, ARM/AArch64, MIPS, PowerPC, etc.),
making it convenient for quick hotpatching, stubbing out checks, or testing
alternative execution paths.
Pagination and Caching: Implements paginated resource iteration for symbol and string listing, reducing memory overhead on large binaries.
Security Dashboard: A web-based interface for managing permissions for "unsafe" tools (e.g., Python code execution), providing control over agent capabilities.
Unix Domain Socket (UDS) Support: In addition to TCP, the server supports UDS for secure local communication in isolated environments (Linux/macOS).
Configurable Tool Exposure (tool_mode): Supports three MCP tool
exposure strategies via FastMCP transforms—"hybrid" (default, pins core
high-frequency tools upfront and exposes the rest on-demand via BM25
search), "code_mode" (collapses tools into sandboxed Python discovery and
execution), and "full" (exposes all ~68 tools upfront).
The core of this project is the Gateway Pattern. A central gateway process acts as a proxy that routes requests from the AI agent to the correct active IDA instance.
database_id, the gateway
forwards it to the corresponding IDA process.This architecture enables a multi-session analysis environment where the agent can work with multiple binaries concurrently.
Most tools in this project have been thoroughly tested and verified across:
Follow these steps to set up the IDA MCP server and configure your client.
1. Quick Setup
# a. Clone the repo
git clone https://github.com/idamcp/idamcp.git
cd idamcp
# b. Install the IDA Pro plugin
python3 install.py plugin
# c. Install the dependencies
python3 -m venv venv_idamcp
# Activate the virtual environment:
# On Linux / macOS:
source venv_idamcp/bin/activate
# On Windows (Command Prompt):
venv_idamcp\Scripts\activate.bat
# On Windows (PowerShell):
venv_idamcp\Scripts\activate.ps1
python3 -m pip install -r requirements.txt
# d. Install IDA Python library module, please update the path accordingly
cd </path/to/IDA/installation/idalib/python>
python3 -m pip install "idapro*.whl"
python3 py-activate-idalib.py
# f. Register the server with your preferred LLM client:
# For google antigravity-cli
python3 install.py agy
# For Codex
python3 install.py codex
# For Claude Code
python3 install.py claude
# For Gemini CLI
python3 install.py gemini
2. Verify the Gateway (Optional / Testing Only)
You can launch the standalone gateway proxy locally to verify that all dependencies are met:
python3 -m gateway.proxy