agentusecasesAll 965 use cases
Security, Science & Hardware

Reverse-engineer binaries in Ghidra

An MCP server exposing 110 Ghidra tools for AI-assisted reverse engineering.

Done with a custom-built or unnamed agent

What they did
A Ghidra plugin starts an HTTP server on localhost, and a Python bridge exposes it to MCP clients such as Claude or Cursor. The agent decompiles functions, follows call graphs and cross-references, and renames, retypes and comments in batches. A person builds and deploys the plugin and enables it in CodeBrowser.
How it went
The README now lists 253 tools, not 110. It claims 93% fewer API calls from batching, and says it was refined over hundreds of documented functions. It gives no benchmark of results.
Worth knowing
Lazy tool loading is on by default because Gemini rejects the full tool list. Script-running endpoints are off unless you set GHIDRA_MCP_ALLOW_SCRIPTS, and the server has no authentication on localhost.

Try it yourself with Claude Code

Connect to the Ghidra MCP server I have set up and open the binary at [path to binary]. Identify its main functions, rename them based on what they do, and list any suspicious behavior such as network calls or file writes. Finish with a short written summary of what the program does and the functions that support that conclusion.

Read the original ↗

Discussion on HN · Feb 4, 2026

Five of these in your inbox every morning

The best things people got an AI agent to do, each with the prompt to try it.

More like this