Token-efficient Ghidra RE: decompilation, Swift/ObjC, ELF/Mach-O, async progress
Pyghidra MCP server exists for a simple reason — assistants are far more useful when they can act on Pyghidra directly instead of describing what you should do. Token-efficient Ghidra RE: decompilation, Swift/ObjC, ELF/Mach-O, async progress.
Token-efficient MCP server for Ghidra-based reverse engineering. Analyze ELF, Mach-O, and PE binaries with Swift, Objective-C, and Hermes support.
Installation goes through your MCP client rather than a global install: point it at pyghidra-lite on PyPI and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.
Once Pyghidra is connected, these are the calls the assistant has available:
load — Import and analyze binarydelete — Remove binary and cancel jobsbinaries — List binaries + job statusinfo — Binary overviewfunctions — List/search functionscode — Decompile or disassemblexrefs — References and call graphssearch — Find strings, bytes, symbolsExamples — The Examples tool exposed by this serverYou will need 2 environment variables: GHIDRA_INSTALL_DIR, PYGHIDRA_LITE_AUTH_TOKEN. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.
Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. Pyghidra's toolset — load, delete, binaries and 6 more — is a fair guide to whether it matches your workflow. It is maintained by johnzfitch; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| load | Import and analyze binary |
| delete | Remove binary and cancel jobs |
| binaries | List binaries + job status |
| info | Binary overview |
| functions | List/search functions |
| code | Decompile or disassemble |
| xrefs | References and call graphs |
| search | Find strings, bytes, symbols |
| Examples | The Examples tool exposed by this server. |
#### With explicit Ghidra path
```json
{
"mcpServers": {
"pyghidra-lite": {
"command": "pyghidra-lite",
"args": [
"serve",
"--ghidra-dir", "/path/to/ghidra"
]
}
}
}Configuration as documented by the project. Restart the client after saving.
| Variable | Description | Required |
|---|---|---|
| GHIDRA_INSTALL_DIR | Filesystem location the server is allowed to use. | Optional |
| PYGHIDRA_LITE_AUTH_TOKEN | Credential the server authenticates with. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.