CLI tool
blacktop/ida-mcp-rs avatar
blacktop/ida-mcp-rs

ida-mcp-rs: a headless IDA Pro MCP server for AI agents that read binaries

Headless IDA Pro MCP Server

848 stars61 forksRustMIT

At a glance

What is it?
blacktop/ida-mcp-rs wraps IDA Pro's libraries in a Model Context Protocol server so Claude Code, Codex CLI, Gemini CLI or Cursor can open an IDB, list functions, disassemble and decompile. It requires a licensed IDA Pro 9.4 install and ships as versioned binaries that must match the IDA release they link against.
Who is it for?
Adopt ida-mcp-rs if you already hold an IDA Pro 9.4 licence, work on macOS, Linux or Windows with a standard install path, and want an agent to call list_functions, disasm_by_name, strings, analyze_funcs and decompile instead of you clicking through the GUI. Skip it if you have no IDA licence, if you need IDA Free or a plugin inside the IDA window, or if you cannot keep the ida-mcp version matched to your IDA release.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 7 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What ida-mcp-rs solves, and who it is written for

IDA Pro is a desktop application. Its analysis engine, however, is available as a library, and ida-mcp-rs is a Rust binary that links that library and exposes it over the Model Context Protocol. The README calls it a "Headless IDA Pro MCP server for AI-powered reverse engineering." The practical effect is that an agent can open a database, list functions, disassemble by name, pull strings, run function analysis in the background and decompile an address without a human driving the GUI.

The audience is narrow and specific. The prerequisites section lists one item: IDA Pro 9.4 with a valid license. There is no free tier, no Ghidra backend and no bundled disassembler. If you do not already own IDA Pro, this project has nothing to offer you. If you do own it and you already use an MCP-capable agent, the value is that the agent gets structured access to the same analysis results you would otherwise read off the screen.

The repository topics describe the scope precisely: headless, idalib, idapro, mcp, mcp-server, rust. It is not an IDA plugin and does not appear inside the IDA window. It is a separate process that an MCP client launches.

How the server is put together: idalib, rmcp and a task model

The dependency list in Cargo.toml is the clearest description of the architecture. The idalib crate is pulled from blacktop's fork on the sdk-9.4.0 branch, and idalib-build is a build dependency, which means the IDA SDK is involved at compile time, not only at runtime. The MCP layer is rmcp 3.3 with the server, client, transport-io, transport-child-process, transport-streamable-http-server, elicitation, request-state and schemars features enabled. axum 0.8 and tokio are present for the HTTP and async runtime side. sha2 is there for the input hashing described in the README.

That hashing matters more than it looks. The README states that an existing output database is reused only when IDA's recorded input SHA-256 matches the current file, and that rebuild: true can overwrite only a database whose hash or recorded input path proves it belongs to the input. This is a guard against the classic mistake of analyzing one binary and reading results that belong to another. It also means the server tracks provenance per database rather than treating the .i64 file as a cache key.

The task model is the other design decision worth noting. open_idb returns quickly because analysis runs separately, and analyze_funcs accepts background: true, returning a task_id that you poll with task_status. For xrefs and decompilation on large binaries, that split is what keeps the agent responsive. It also means the agent has to manage state across calls, and a client that fires analyze_funcs and then immediately asks for xrefs will get incomplete answers.

Installing ida-mcp and running a first analysis

Installation is a package manager command on each platform. On macOS and Linux the Homebrew tap is the documented route, and the README notes that ida-mcp versions mirror IDA Pro versions, so v9.4.x is for IDA 9.4. The tap also publishes versioned casks for older releases on Apple Silicon.

bash
brew install blacktop/tap/ida-mcp        # Latest (IDA 9.4)
brew install blacktop/tap/[email protected]    # IDA 9.3/9.3sp1
brew install blacktop/tap/[email protected]    # IDA 9.2

After installing, register the server with your agent. The README gives the same one-line form for Claude Code, Codex CLI and Gemini CLI; the Claude Code variant is shown here.

bash
claude mcp add ida -- ida-mcp

If macOS reports Library not loaded: @rpath/libida.dylib, the fix in the README is to point DYLD_LIBRARY_PATH at the IDA application directory. Linux uses IDADIR instead, with a resolution order of $IDADIR, then ~/ida-pro-9.4, then /opt/ida-pro-9.4 and other RUNPATH fallbacks.

bash
claude mcp add ida -e DYLD_LIBRARY_PATH='/path/to/IDA.app/Contents/MacOS' -- ida-mcp

For clients configured by file rather than command, Cursor reads .cursor/mcp.json, and the README's example is minimal.

json
{
  "mcpServers": {
    "ida": { "command": "ida-mcp" }
  }
}

Once the server is registered, the first useful sequence is to open a binary and then call tools that need no analysis. The README's own example uses list_functions, disasm_by_name and strings, and notes that these work immediately.

text
open_idb(path: "~/samples/malware")
list_functions(limit: 20)
disasm_by_name(name: "main", count: 20)
strings(limit: 10)

For anything that needs cross-references or decompilation on a large binary, the README instructs you to run analysis in the background and poll it. decompile additionally requires Hex-Rays and completed analysis.

text
analyze_funcs(background: true)   # returns task_id
task_status(task_id: "analyze-<random>")
decompile(address: "0x100000f00")

Two practical details from the README are easy to miss. Raw blobs save to <input>.i64 by default, and idb_out redirects the database elsewhere, which matters when the input directory is read only. The README's example writes to a working directory instead.

text
open_idb(path: "/System/example", idb_out: "~/ida-work/example.i64")

Windows needs more care. The binary requires ida.dll and idalib.dll to be discoverable before it starts, and the README's simplest option is copying ida-mcp.exe into the IDA directory so the DLLs load from the same folder. Scoop installs set IDADIR automatically. There is also a Nix route through github:blacktop/nur#ida-mcp, and prebuilt archives on the releases page.

Where ida-mcp-rs breaks or is the wrong choice

The hardest constraint is the version pairing. ida-mcp versions mirror IDA Pro versions, and the README states that a version mismatch is detected at startup with a clear error message. That is a good failure mode, but it means an IDA upgrade forces a matching ida-mcp upgrade before anything works. Scoop and the Nix flake publish only the latest version, so older IDA releases on those channels have no supported install path; the README points those users at a matching GitHub release or, on Apple Silicon only, a versioned Homebrew cask. On Windows and Linux with an older IDA, the fallback is a manual download.

Library discovery is the second failure surface. The binary links IDA's libraries at runtime rather than bundling them, so a non-standard install location produces a load error unless you set DYLD_LIBRARY_PATH, IDADIR or PATH correctly. Windows is the worst case because it needs both build-time discovery through IDADIR and runtime DLL loading through PATH, and the README's own PowerShell snippet for that is long enough that mistakes are likely.

Decompilation is conditional. The README is explicit that decompile requires Hex-Rays plus completed analysis, so an IDA edition or licence without Hex-Rays cannot decompile at all, and calling it before analysis finishes will not give you source. The background task model adds a second failure mode: an agent that does not poll task_status will act on partial results without any error being raised.

Finally, this is not an IDA plugin. If your workflow depends on interacting with the GUI, on IDA's own scripting console, or on visual navigation of a graph view, a headless server is the wrong shape for the job. The README also does not document rollback of a rebuild, so overwriting a database with rebuild: true should be treated as one-way based on what is written down.

Alternatives and how their approach differs

The obvious comparison in reverse engineering is Ghidra. Ghidra is free and open source, with its own decompiler, and it can be scripted headlessly. The difference is not quality but licensing and integration: ida-mcp-rs assumes you have paid for IDA Pro 9.4 and links its proprietary libraries, while a Ghidra-based server has no licence prerequisite but works against a different analysis engine with different decompiler output. If your reason for wanting an MCP server is that you cannot justify an IDA licence, ida-mcp-rs is disqualified at the prerequisites line and a Ghidra-backed tool is the direction to look.

Within the IDA ecosystem, the alternative is a plugin that runs inside IDA and exposes tools from there. That keeps the GUI available alongside the agent and avoids the runtime library discovery problem entirely, because IDA is already loaded. The trade-off is that IDA must be running and a human must keep it that way, which defeats the point of a headless server for batch or automated work. ida-mcp-rs chooses the opposite: no GUI, no window to keep alive, but you own library path configuration and version matching yourself.

A third option is to skip MCP and script idalib directly. That gives full control and no protocol layer, but you lose the tool catalogue that agents discover at runtime, which is the part that makes an agent useful without hand-written glue.

Maintenance, licence and upgrade cost

The repository is not archived, and the last push was on 2026-09-05. The most recent release listed is v9.4.3 from 2026-08-29, preceded by v9.4.2 on 2026-08-15 and v9.4.1 on 2026-07-15. The cadence tracks IDA's own release train rather than an independent feature roadmap, which is consistent with the versioning scheme the README describes. The justfile shows the maintainer's own workflow, including a release recipe that deliberately disables a build cache because of upstream restore-time bugs, and a tools-doc recipe that regenerates docs/TOOLS.md from the Rust registry. That last detail is worth knowing: the tool inventory is generated from code, so docs/TOOLS.md is the place to check what tools actually exist rather than trusting a stale list.

The upgrade cost is the version pairing. Moving IDA from 9.3 to 9.4 means moving ida-mcp to the matching v9.4.x build, which on Homebrew means a different cask and on Scoop or Nix means you are already on latest. There is no documented compatibility mode that lets a 9.3 binary talk to a 9.4 install; the README says the mismatch is detected at startup. Budget the upgrade as a coordinated pair, not two independent updates.

The licence situation is layered. ida-mcp-rs itself is MIT, per both the README badge and the license field in Cargo.toml. IDA Pro is commercial and separately licensed, and the README lists a valid IDA Pro 9.4 license as a prerequisite. The MIT licence on this server does not grant you any right to IDA's libraries, and the idalib dependency comes from a separate repository on a specific SDK branch. Anyone redistributing a build needs to think about what the linked IDA libraries imply, which is a question for your own counsel rather than something this article can settle.

Editorial conclusion

Adopt ida-mcp-rs if you already hold an IDA Pro 9.4 licence, work on macOS, Linux or Windows with a standard install path, and want an agent to call list_functions, disasm_by_name, strings, analyze_funcs and decompile instead of you clicking through the GUI. Skip it if you have no IDA licence, if you need IDA Free or a plugin inside the IDA window, or if you cannot keep the ida-mcp version matched to your IDA release. Before wiring it into an agent, verify two things: that the binary starts against your IDA installation without a library load error, and that decompile returns output on one of your own binaries, because Hex-Rays and completed analysis are both required for that call.

Frequently asked questions

What is IDA MCP?

It is a Model Context Protocol server that exposes IDA Pro's analysis capabilities to an AI agent. In this project the server is ida-mcp, a Rust binary that links IDA's libraries through idalib and lets the agent call tools such as open_idb, list_functions, disasm_by_name, strings, analyze_funcs and decompile.

How do I set up IDA MCP?

Install the binary with a package manager, then register it with your agent. The README shows brew install blacktop/tap/ida-mcp followed by claude mcp add ida -- ida-mcp, with DYLD_LIBRARY_PATH on macOS or IDADIR on Linux if the IDA libraries are not in a standard location.

Which IDA Pro version does ida-mcp-rs require?

IDA Pro 9.4 with a valid license is the stated prerequisite, and ida-mcp versions mirror IDA Pro versions, so v9.4.x pairs with IDA 9.4. A version mismatch is detected at startup with a clear error message, and older IDA releases need the matching ida-mcp build.

Does ida-mcp-rs work with IDA Free?

The README lists only IDA Pro 9.4 with a valid license as a prerequisite, and the binary links IDA's libraries at runtime. Nothing in the documentation describes support for IDA Free or for editions without Hex-Rays, and decompile is documented as requiring Hex-Rays.

Can ida-mcp-rs decompile without running analysis first?

No. The README states that decompile requires Hex-Rays plus completed analysis, and for xrefs or decompilation on large binaries it instructs you to run analyze_funcs with background: true and poll task_status using the returned task_id.

Official sources

  1. blacktop/ida-mcp-rs on GitHub
  2. Issues
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/blacktop-ida-mcp-rs.svg)](https://hysenlabs.com/projects/blacktop-ida-mcp-rs)