Reverse engineer a Go binary with Ghidra via MCP
Huli had Cursor drive GhidraMCP to identify a Golang binary, list its routes and find a path traversal, but it missed the SQL injection check.
Done withCursor
- What they did
- Huli built a stripped Golang gin server with a deliberate SQL injection and path traversal, loaded it into Ghidra with the GolangAnalyzerExtension, then connected GhidraMCP to Cursor so the agent could call Ghidra's decompiler itself. Prompted only to identify the binary and its functions, it autonomously queried MCP, then was asked to reconstruct the Go source and check for vulnerabilities.
- How it went
- Using Cursor's composer 1.5, it correctly recovered routes, libraries, and file structure (with minor route-name errors) and found the path traversal bug but reconstructed the SQL injection code as already fixed, missing it. Switching to Opus 4.6 on the same prompt caught both vulnerabilities but still mislabeled some routes.
- Worth knowing
- Results varied heavily by model: a weaker model (composer 1.5) missed the SQL injection that a stronger model (Opus 4.6) caught with the same prompt.
Try it yourself with Cursor
Connect to Ghidra via MCP and analyze this Go binary [path/name] to identify its routes and endpoints, then look for vulnerabilities like path traversal or SQL injection. Give me a report of what it found, and flag anything uncertain for me to double check manually.
Source: blog.huli.tw · Mar 1, 2026
Five of these in your inbox every morning
The best things people got an AI agent to do, each with the prompt to try it.
More like this
Keep coding agents running autonomously for long stretches
Cursor's write-up on scaling long-running autonomous coding.
Run a scheduled personal assistant that builds a task dashboard
A Rippling engineer's Cursor cron agent runs every two hours, reading Slack notes, GitHub PRs, Jira issues and mentions, deduplicating them and posting a dashboard.
Build a homepage from Figma designs via MCP
The author connected Figma to Cursor over MCP to build a new homepage for a font archive, with great results after Lovable disappointed.
Find a Linux vulnerability hidden for 23 years
An account of Claude Code uncovering a long-standing vulnerability in Linux.
Control and calibrate a robotic hand with OpenClaw
An OpenClaw agent running Claude drove a 16-joint printed hand, checked its actions with a USB camera, calibrated firmware and narrated in Telegram.
Open recent protein-ligand structures in PDB
A researcher had Comet find the three latest GSK3B protein-ligand complexes in the PDB and open each in Ligand Interaction view.