# Does Ghidra have an MCP server?

**Sort of — Community only.** Ghidra does not maintain an official MCP server. Community-built servers exist.

> The most-starred server, LaurieWired/GhidraMCP (~10.2k stars), has had no commits since June 2025.

## Facts

- Verdict: Community only (Sort of)
- Access: Local server — Runs on your machine over stdio, launched by your MCP client.
- Repository: [bethington/ghidra-mcp](https://github.com/bethington/ghidra-mcp) — ★ 4.1k, last push 2026-09-29, Apache-2.0
- Maintainer: Benjamin Ethington
- Language: Java
- Category: [Developer Tools](https://mcpyet.com/category/developer-tools/)
- Verified against vendor docs: 2026-09-29
- GitHub data refreshed: 2026-09-29 (re-checked every 6 hours)

## What it does

> Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.
> — how [bethington/ghidra-mcp](https://github.com/bethington/ghidra-mcp) describes itself

## The receipts

- **Top community server:** [bethington/ghidra-mcp](https://github.com/bethington/ghidra-mcp) — ★ 4.1k, pushed 2026-09-29, Apache-2.0 (active)

## How to connect it

Runs on your machine over stdio, launched by your MCP client.

### Claude Code

```sh
claude mcp add ghidra -- npx -y <package-from-readme>
```

Swap in the exact package and flags from the repo README — most servers need an API key passed as an environment variable. Add `--scope user` to make it available in every project.

### Claude Desktop

Open **Settings → Developer → Edit Config** and add the server to `claude_desktop_config.json`, then restart Claude Desktop:

```json
{
  "mcpServers": {
    "ghidra": {
      "command": "npx",
      "args": [
        "-y",
        "<package-from-readme>"
      ],
      "env": {
        "API_KEY": "…"
      }
    }
  }
}
```

### Cursor

Add to `.cursor/mcp.json` in your project, or `~/.cursor/mcp.json` for every project:

```json
{
  "mcpServers": {
    "ghidra": {
      "command": "npx",
      "args": [
        "-y",
        "<package-from-readme>"
      ],
      "env": {
        "API_KEY": "…"
      }
    }
  }
}
```

### VS Code

Add to `.vscode/mcp.json`, then pick the server from Copilot's agent-mode tools menu:

```json
{
  "servers": {
    "ghidra": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "<package-from-readme>"
      ]
    }
  }
}
```

### ChatGPT

ChatGPT connects to **remote servers only**, and this one runs on your machine. Either expose it through an MCP gateway that gives it a public URL, or use a client with native local support (Claude or Cursor).

## Before you connect this

A community server is unaudited third-party code that will hold your Ghidra API credentials and see whatever data they unlock. Independent research puts SSRF vulnerabilities in roughly a third of public MCP servers, and 41% ship with no authentication at all.

- Read the source before running it — especially any network calls it makes.
- Check who maintains it and whether commits are recent (this one: last push 2026-09-29).
- Issue a scoped, revocable API key rather than an account-wide token.
- Prefer read-only credentials until you trust it with writes.

## How we know

The NSA's Ghidra project ships no MCP server: nothing in the NationalSecurityAgency GitHub org, the 12.x release notes or the MCP Registry, and a request to upstream one (discussion #8648) got no maintainer reply. bethington/ghidra-mcp (~4k stars, releases through Sept 2026) was picked as the strongest server that is still maintained.

- GitHub data refreshed 2026-09-29, then every 6 hours.
- Vendor docs verified on 2026-09-29.
- Corrections: hello@mcpyet.com.

## Also in Developer Tools

- [Chrome DevTools](https://mcpyet.com/mcp/chrome-devtools.md) — Official (Yes)
- [Google AI Studio](https://mcpyet.com/mcp/google-ai-studio.md) — Community only (Sort of)
- [Serena](https://mcpyet.com/mcp/serena.md) — Official (Yes)
- [LangChain](https://mcpyet.com/mcp/langchain.md) — Official (Yes)
- [GitLab](https://mcpyet.com/mcp/gitlab.md) — Official (Yes)
- [n8n](https://mcpyet.com/mcp/n8n.md) — Official (Yes)

---

Source: https://mcpyet.com/mcp/ghidra/ — data refreshed 2026-09-29
