Pyghidra MCP Server

Token-efficient Ghidra RE: decompilation, Swift/ObjC, ELF/Mach-O, async progress

Local serverstdioPython

What is the Pyghidra MCP server?

Pyghidra MCP server exists for a simple reason — assistants are far more useful when they can act on Pyghidra directly instead of describing what you should do. Token-efficient Ghidra RE: decompilation, Swift/ObjC, ELF/Mach-O, async progress.

What you get

Token-efficient MCP server for Ghidra-based reverse engineering. Analyze ELF, Mach-O, and PE binaries with Swift, Objective-C, and Hermes support.

Setting it up

Installation goes through your MCP client rather than a global install: point it at pyghidra-lite on PyPI and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

What the assistant can call

Once Pyghidra is connected, these are the calls the assistant has available:

  • load — Import and analyze binary
  • delete — Remove binary and cancel jobs
  • binaries — List binaries + job status
  • info — Binary overview
  • functions — List/search functions
  • code — Decompile or disassemble
  • xrefs — References and call graphs
  • search — Find strings, bytes, symbols
  • Examples — The Examples tool exposed by this server

Configuration and credentials

You will need 2 environment variables: GHIDRA_INSTALL_DIR, PYGHIDRA_LITE_AUTH_TOKEN. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

Before you rely on it

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • With 9 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch Pyghidra.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the pyghidra mcp server does with a few real requests.

Choosing this one

Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. Pyghidra's toolset — load, delete, binaries and 6 more — is a fair guide to whether it matches your workflow. It is maintained by johnzfitch; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Available tools

ToolWhat it does
loadImport and analyze binary
deleteRemove binary and cancel jobs
binariesList binaries + job status
infoBinary overview
functionsList/search functions
codeDecompile or disassemble
xrefsReferences and call graphs
searchFind strings, bytes, symbols
ExamplesThe Examples tool exposed by this server.

How to install the Pyghidra MCP server

#### With explicit Ghidra path

```json
{
  "mcpServers": {
    "pyghidra-lite": {
      "command": "pyghidra-lite",
      "args": [
        "serve",
        "--ghidra-dir", "/path/to/ghidra"
      ]
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Configuration

VariableDescriptionRequired
GHIDRA_INSTALL_DIRFilesystem location the server is allowed to use.Optional
PYGHIDRA_LITE_AUTH_TOKENCredential the server authenticates with.Yes

Example prompts to try

  • Use Pyghidra to load.
  • Use Pyghidra to delete.
  • Use Pyghidra to binaries.

Frequently asked questions

It connects Pyghidra to MCP-compatible AI assistants such as Claude and Cursor, exposing 9 tools (load, delete, binaries, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Pyghidra directly.