Ebpf MCP Server

`ebpf-mcp` is a secure **Model Context Protocol (MCP)** server that exposes **a minimal set of structured tools** to interact with eBPF — optimized

Local serverstdio

What is the Ebpf MCP MCP server?

Ebpf MCP becomes available to MCP clients through the ebpf mcp mcp server. ebpf-mcp is a secure Model Context Protocol (MCP) server that exposes a minimal set of structured tools to interact with eBPF — optimized for safe AI control, automation agents, and human operators.

What Ebpf MCP does

ebpf-mcp is a secure Model Context Protocol (MCP) server that exposes a minimal set of structured tools to interact with eBPF — optimized for safe AI control, automation agents, and human operators.

Tools it exposes

Once connected, the assistant can call these 6 tools directly:

  • info — ✅
  • load_program — ✅
  • attach_program — ✅
  • inspect_state — ✅
  • stream_events — ✅
  • trace_errors — ✅

Installing the ebpf mcp mcp server

The server is distributed via npm as @modelcontextprotocol/inspector, so most clients can run it without a manual build step. Add it to your MCP client's configuration and restart the client to pick it up — the copy-paste configs for Claude Desktop, Claude Code and Cursor are on this page.

Where it fits

Developer-tool servers are usually the first ones people connect, because they turn "help me with this code" into an assistant that can actually read the repo and act on it. Ebpf MCP sits in that group, and the shape of its toolset — info, load_program, attach_program among others — tells you what it is really for. Worth comparing against the other developer tools servers in this directory before you commit to one, since several overlap in scope but differ sharply in setup cost and permissions.

Practical notes

  • This server runs locally, so it operates with whatever access your machine and its credentials already have. Scope that deliberately rather than by default.
  • Maintained by sameehj.
  • MCP clients ask for confirmation before each tool call by default. Keep that on while you learn what the ebpf mcp mcp server actually does with your data.
  • Every entry in this directory is reviewed by hand before it goes live, and details are checked against the project's own documentation.

Available tools

ToolWhat it does
info
load_program
attach_program
inspect_state
stream_events
trace_errors

How to install the Ebpf MCP MCP server

{
  "mcpServers": {
    "ebpf": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/inspector"]
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Example prompts to try

  • Use Ebpf MCP to info.
  • Use Ebpf MCP to load program.
  • Use Ebpf MCP to attach program.

Frequently asked questions

It connects Ebpf MCP to MCP-compatible AI assistants such as Claude and Cursor, exposing 6 tools (info, load_program, attach_program, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Ebpf MCP directly.