Model Context Protocol integration for IDA Pro, enabling AI assistants to interact with IDA's disassembler and decompiler
The IDA Pro MCP server has solid tool definitions with clear naming and comprehensive parameter schemas. Both tools (idb_open, idb_list) follow verb-noun conventions and include full input schemas with type information. However, parameter descriptions lack sufficient depth for LLM reasoning, and output schemas are defined as TypedDict but not exposed in tool metadata. Error handling exists but provides minimal recovery guidance. The server demonstrates good foundational quality but falls short of A-grade rigor in description completeness and LLM-optimized messaging.
List open IDA sessions.
Open a binary, activate it, and warm up subsystems in one call.
Parameter descriptions lack actionable context. E.g., 'run_auto_analysis' says 'Run automatic analysis on the binary' but does not explain when an LLM should set it to false, what trade-offs exist (speed vs completeness), or what 'analysis' includes (symbolic recovery, decompilation hints, etc.). Similarly, 'idle_ttl_sec' lacks guidance on reasonable values (600 default suggests ~10 min, but no min/max or rationale is stated).
Output schemas (IdalibOpenResult, IdalibListResult) are defined as TypedDict in Python but not exposed in the tool's JSON schema metadata. The MCP tool decorator does not emit a documented return schema visible to the client. LLMs cannot plan downstream operations or validate response structure without explicit schema documentation.
Error messages are minimal and do not guide recovery. E.g., idb_open catches FileNotFoundError, RuntimeError, ValueError and returns {'error': str(e)}. No structured error classification (retryable vs. user-fixable vs. fatal), no suggestions for follow-up actions, and no list of available sessions when a file path is invalid. An LLM seeing 'No such file or directory' has no guidance on what to do next.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 77 | 2025-06-18+ | v2 |
| 2026-03-09 | C | 65 | - | v1 |
Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are not present. idb_open is marked as WRITE risk and clearly mutates state (opens a binary, activates session, warms subsystems), but this is not declared in the tool schema. idb_list is READ_ONLY, also undeclared. Tool annotations enable clients to reason about safety and compose tools correctly.
idb_open parameter 'preferred_session_id' accepts a free-form string with no validation hints or constraints. The description says 'auto-generated if empty' but does not explain the format, length, or character restrictions. An LLM has no guidance on what a valid session ID looks like, risking malformed inputs.
idb_open returns a success boolean in the response but error cases return only {'error': str(e)} with no 'success' field. This inconsistent structure forces the LLM to check for 'error' presence rather than rely on a consistent 'success' flag, increasing parsing complexity and error likelihood.