Model or dataset
mrexodia/ida-pro-mcp avatar
mrexodia/ida-pro-mcp

IDA Pro MCP: Connecting IDA Pro to Language Models for AI-Assisted Reverse Engineering

AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

12,374 stars1,463 forksPythonMIT

At a glance

What is it?
IDA Pro MCP is a Python MCP server that bridges IDA Pro's decompiler and analysis database with LLM-based coding assistants. The README opens with an explicit recommendation to use the official Hex-Rays IDA MCP server instead, which is a significant consideration before adopting this project.
Who is it for?
Reverse engineers who want to experiment with LLM-assisted analysis in IDA Pro have two concrete options: this community project and the official Hex-Rays IDA MCP server. The README for this project explicitly recommends the official server.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 3 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

The Official Recommendation and What This Project Still Offers

The very first item in the README is a callout advising users to use the Official Hex-Rays IDA MCP Server at github.com/HexRaysSA/ida-mcp instead of this project. That is an unusual opener for a project's own documentation and worth taking at face value: the project maintainer believes the official server is the better choice for most users.

Despite this recommendation, the project continues to receive updates. The last push was on 2026-09-26. The project supports a wider list of MCP clients than the official server may cover at the time of evaluation, including Amazon Q Developer CLI, Augment Code, Claude Code, Codex, Cline, Cursor, Gemini CLI, Kilo Code, Kiro, LM Studio, Opencode, Roo Code, Trae, VS Code, VS Code Insiders, Warp, Windsurf, Zed, and Kimi Code, among others. Teams already using one of these clients who have tested this project and found it works for their specific workflow have a reason to continue with it.

The core use case the README describes is what it calls vibe reversing: giving an LLM access to IDA Pro's decompiler output and analysis database, then asking the LLM to rename variables, add comments, change types, and explain functionality, all through the MCP protocol rather than through manual copy-paste.

How the idalib Architecture Works

IDA Pro MCP uses idalib, a headless library mode of IDA Pro introduced in recent versions, as its primary operating mode. idalib allows the IDA database and decompiler to run without the graphical user interface, which means the MCP server can process a binary in the background while the LLM client sends requests over the protocol.

Before the MCP server can use idalib, the idalib Python bindings must be activated globally using a script shipped with IDA Pro. The commands differ by platform:

bash
# windows
uv run "C:\Program Files\IDA Professional 9.3\idalib\python\py-activate-idalib.py"
# macos
uv run "/Applications/IDA Professional 9.3.app/Contents/MacOS/idalib/python/py-activate-idalib.py"
# linux
uv run "/path/to/idapro-9.3/idalib/python/py-activate-idalib.py"

This step registers the idalib environment with uv, which is the package manager used to run the MCP server. The MCP server itself is implemented as a Python package named ida-pro-mcp (package version 2.0.0 in pyproject.toml), with two entry points: ida-pro-mcp for the main server and idalib-mcp for the headless idalib supervisor. Running an SSE transport for browser-based UI clients uses:

sh
uv run ida-pro-mcp --transport http://127.0.0.1:8744/sse

The GUI plugin mode, which runs inside the IDA Pro graphical interface rather than as a headless process, is described as deprecated in the README and will eventually be removed.

Installing IDA Pro MCP for Claude Code and Other Clients

Installation differs by MCP client. For Claude Code:

bash
claude plugin marketplace add mrexodia/claude-marketplace
claude plugin uninstall ida-pro-mcp@mrexodia
claude plugin install ida-pro-mcp@mrexodia

For Codex:

bash
codex plugin marketplace add mrexodia/codex-marketplace
codex plugin remove ida-pro-mcp@mrexodia
codex plugin add ida-pro-mcp@mrexodia

For clients not listed with a dedicated install path, the README provides a fallback: running ida-pro-mcp --config prints the JSON configuration block needed for that client's MCP server list.

The GUI plugin install path (now deprecated) used pip to install directly from GitHub:

sh
pip install https://github.com/mrexodia/ida-pro-mcp/archive/refs/heads/main.zip

Followed by ida-pro-mcp --install to configure the IDA plugin. The README warns that after this install, both IDA Pro and the MCP client must be fully restarted, including quitting clients like Claude that run in the system tray rather than closing with the window.

The hard prerequisites for all installation paths are: Python 3.11 or higher (confirmed via idapyswitch if the wrong version is active in IDA), IDA Pro 8.3 or higher with version 9 recommended, and uv installed and available on the path. IDA Free is explicitly unsupported.

Prompt Engineering for Accurate Decompiler Analysis

The README dedicates a section to prompt engineering because LLMs produce poor results on reverse engineering tasks without specific guidance. The main failure modes named are hallucinating numeric conversions between integer and byte representations, and poor performance on obfuscated code.

The README provides a minimal example prompt for crackme analysis:

md
Your task is to analyze a crackme in IDA Pro. You can use the MCP tools to retrieve information. In general use the following strategy:

- Inspect the decompilation and add comments with your findings
- Rename variables to more sensible names
- Change the variable and argument types if necessary (especially pointer and array types)
- Change function names to be more descriptive
- If more details are necessary, disassemble the function and add comments with your findings
- NEVER convert number bases yourself. Use the `int_convert` MCP tool if needed!
- Do not attempt brute forcing, derive

The int_convert MCP tool is specifically called out as the correct mechanism for base conversions: the LLM should not perform these calculations itself. For cases requiring more complex arithmetic, the README also recommends a separate math-mcp project.

A second prompt contributed by a collaborator adds a structured methodology with steps for decompilation analysis, variable renaming, and type correction. The README notes this approach was used in a live stream demonstrating real-world malware analysis.

Where This Tool Does Not Work Well

The README is direct about the limitations of LLM-assisted reverse engineering. Obfuscated code is the primary failure case. Before using an LLM on a binary, the README recommends manually or automatically removing string encryption, import hashing, control flow flattening, code encryption, and anti-decompilation tricks. An LLM that receives heavily obfuscated decompiler output will not perform well even with good prompt engineering.

The README also recommends using Lumina or FLIRT to resolve open-source library code and C++ STL symbols before asking the LLM for analysis. Without symbol resolution, the LLM works with unnamed functions and produces analysis that is harder to verify.

The project requires IDA Pro, which is a commercial product from Hex-Rays. IDA Free is explicitly unsupported. Teams without an IDA Pro licence cannot use this project at all, regardless of which MCP client they have.

LLM hallucinations are a documented risk throughout the README. The int_convert tool exists because the README specifically identifies numeric base conversion as a reliable hallucination trigger. Any analysis produced by the LLM requires human review; the README does not frame this tool as producing verified output.

Maintenance, Project Status, and MIT Licensing

The last push to the repository was on 2026-09-26, two days before the time of writing. The most recent tagged release is 1.4.0 from 2025-10-06. The project continues to receive updates despite the maintainer's recommendation to use the official Hex-Rays server. The repository includes test infrastructure, CI configuration under .github/, and a profiles directory that likely contains different MCP capability profiles for clients, though the README does not describe these in detail.

The pyproject.toml classifies the project as Development Status 5 (Production/Stable), which contrasts with the recommendation to prefer the official server. The two entry points idalib-mcp and ida-pro-mcp are both registered as console scripts, and the package is named ida-pro-mcp at version 2.0.0.

The project is licensed under the MIT licence, which permits commercial use, modification, and redistribution without copyleft obligations. The authors listed in pyproject.toml are mrexodia, can1357, and the IDA Pro MCP Contributors.

Editorial conclusion

Reverse engineers who want to experiment with LLM-assisted analysis in IDA Pro have two concrete options: this community project and the official Hex-Rays IDA MCP server. The README for this project explicitly recommends the official server. If you choose this project because it supports a specific MCP client or workflow, verify that idalib is activated globally with the py-activate-idalib.py script before attempting installation, since that step is a hard prerequisite. IDA Free is not supported by either the idalib approach or the GUI plugin.

Frequently asked questions

What is IDA Pro MCP?

IDA Pro MCP is a Python MCP server that connects IDA Pro's decompiler and analysis database to LLM-based coding assistants, allowing the LLM to inspect decompiler output, rename variables, add comments, and change types through the Model Context Protocol. The project's README recommends using the official Hex-Rays IDA MCP server instead.

How do I install IDA Pro MCP?

First activate idalib globally using the py-activate-idalib.py script shipped with IDA Pro 9.x, running it with uv. Then install for your MCP client: for Claude Code, run the three claude plugin commands listed in the README; for other clients, run ida-pro-mcp --config to get the JSON configuration block.

How do I use IDA Pro MCP for reverse engineering?

After installation, open a binary in IDA Pro and ask your LLM client to analyze it using the MCP tools. The README recommends providing a structured prompt that directs the LLM to inspect decompiler output, rename variables, and use the int_convert MCP tool for any base conversions rather than calculating them itself.

Official sources

  1. License: MIT
  2. mrexodia/ida-pro-mcp on GitHub
  3. Project website
  4. README
  5. Releases
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/mrexodia-ida-pro-mcp.svg)](https://hysenlabs.com/projects/mrexodia-ida-pro-mcp)
Community notes

Community notes