
Headless Binary Ninja MCP server — giving AI agents deep reverse-engineering capabilities via 180 tools.
A headless Binary Ninja server that speaks MCP (Model Context Protocol), giving AI agents full access to deep reverse-engineering workflows — disassembly, IL, patching, types, xrefs, and more — without a GUI.
Designed to run in the same Docker container as the agent runtime. No sidecars, no extra services.
This entire project---code, tests, and documentation---is 100% vibe coded.
Existing Binary Ninja MCP servers are either GUI-bound or expose a limited tool surface. This server is headless-only and designed for agent-driven workflows in sandboxed VM/container environments: the agent gets full control over the analysis system, automating large parts of reverse engineering while you interactively discuss and steer the process.
The goal is an interface where agents can inspect, refine, and extend an analysis over time — updating types, symbols, and metadata, improving the analysis database incrementally, applying patches and iterating safely with undo/redo, and running custom scripts when a workflow needs something bespoke.
binja.eval and binja.call for anything the tool catalog doesn't cover.3.11+binaryninja Python module importable in your runtime (for real analysis)git clone https://github.com/mrphrazer/binary-ninja-headless-mcp.git
cd binary-ninja-headless-mcp
pip install .
Or install directly from the repo root without cloning:
pip install git+https://github.com/mrphrazer/binary-ninja-headless-mcp.git
Stdio transport (default):
python3 binary_ninja_headless_mcp.py
TCP transport:
python3 binary_ninja_headless_mcp.py --transport tcp --host 127.0.0.1 --port 8765
Fake backend mode (no Binary Ninja required):
python3 binary_ninja_headless_mcp.py --fake-backend
This server speaks standard MCP over stdio (default) or tcp, so any MCP-capable agent host can use it.
claude mcp add binary_ninja_headless_mcp -- python3 /path/to/binary-ninja-headless-mcp/binary_ninja_headless_mcp.py
Or add it to your project's .mcp.json:
{
"mcpServers": {
"binary_ninja_headless_mcp": {
"command": "python3",
"args": ["binary_ninja_headless_mcp.py"],
"cwd": "/path/to/binary-ninja-headless-mcp"
}
}
}
codex mcp add binary_ninja_headless_mcp -- python3 binary_ninja_headless_mcp.py
binary_ninja_headless_mcp.python3 with args ["binary_ninja_headless_mcp.py"] when cwd is the repo root, or use an absolute script path in args.cwd to the repo path if you want relative paths like samples/ls to resolve correctly.--fake-backend.health.ping, then session.open.Recommended deployment model: run the agent process and this MCP server in the same container image.
Example baseline:
FROM python:3.11-slim
WORKDIR /app
COPY . /app
RUN python -m pip install --upgrade pip && pip install ruff pytest
CMD ["python3", "binary_ninja_headless_mcp.py"]
If you need real Binary Ninja analysis in-container, add your Binary Ninja runtime + license setup in this same image and start the agent with this MCP server configured.
initializepingtools/listtools/callshutdowntools/list behavior:
offset or limit is provided, uses paginated output (offset=0, limit=50 default in paged mode).prefix (for example binary.)query (substring match against tool name/description)offset, limit, total, has_more.has_more=true), includes next_offset and a notice hint.Tool call response behavior:
structuredContent is the canonical full payload.content[0].text is a compact summary string (not full JSON duplication).This repository is well tested and has enforced quality gates.
pytest --collect-only -q for the current collected test count.ruff format --check .ruff check .pytestBINARY_NINJA_HEADLESS_MCP_FAKE_BACKEND=1 so checks run without requiring Binary Ninja installation.read_only=true).binary.basic_blocks_at and function.basic_blocks are paginated (offset/limit).memory.read has a hard response cap: length <= 65536.stdio/tcp) is unauthenticated by default.binja.eval and broad API access via binja.call.ruff format --check .
ruff check .
BINARY_NINJA_HEADLESS_MCP_FAKE_BACKEND=1 pytest -q
Use the built-in MCP feature fuzzer to exercise a broad tool surface against samples/ls.
Real Binary Ninja backend:
python3 -m binary_ninja_headless_mcp.fuzzer --binary samples/ls --iterations 120 --seed 1337
Fake backend smoke run:
python3 -m binary_ninja_headless_mcp.fuzzer --binary samples/ls --fake-backend --iterations 20
Write a JSON coverage report:
python3 -m binary_ninja_headless_mcp.fuzzer --binary samples/ls --report-json /tmp/mcp-fuzzer-report.json
Useful flags:
--min-success-tools N: exits non-zero if fewer than N tools succeeded.--verbose: print each tool call while fuzzing.--update-analysis: open the seed session with update_analysis=true.The server currently exposes 181 tools across 36 feature groups.
analysis.status: Get analysis status.analysis.progress: Get analysis progress snapshot.analysis.update: Trigger async analysis update.analysis.update_and_wait: Run analysis update and wait for completion.analysis.abort: Abort analysis.analysis.set_hold: Hold/release analysis queue.