A minimal MCP (Model Context Protocol) server embedded as an IDA Pro plugin that exposes a tight set of reverse-engineering tools to LLM agents over Streamable HTTP.
IDA Fast MCP demonstrates strong naming conventions and clear intent across all 18 tools. All tools have descriptions and explicit input schemas with typed parameters. Tool names follow verb_noun patterns (list_*, get_*, set_*) and are highly specific. Descriptions are adequate but many fall short of the 50-200 char LLM-optimized range established in production baselines. Several parameter descriptions lack format/constraint guidance. Output schemas are not explicitly documented in the code, only implied by implementation. Error handling is minimal; no guidance on recovery strategies or classification (retryable vs fatal). No tool annotations (readOnlyHint/destructiveHint/idempotentHint) despite clear risk profiles (READ_ONLY, WRITE, DESTRUCTIVE). Security model is robust (loopback-only default, Host header validation, no secrets in params), but no per-tool scope declarations.
Decompile a function or address to pseudocode with per-line addresses.
Read bytes from an address.
Get the comment at an address.
Get detailed information about a function.
Get the type/signature of a symbol.
List functions in the binary, optionally filtered.
List imported functions.
List all open IDA instances and their binary names, paths, and PIDs.
Missing tool annotations (readOnlyHint/destructiveHint/idempotentHint) despite clear risk profiles
Parameter descriptions lack format/constraint guidance (e.g., 'address' accepts symbol names OR hex addresses, but this is not documented in param descriptions)
Output schemas are not explicitly documented; LLMs cannot predict response structure for downstream tool composition
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 68 | 2026-07-28+ | v2 |
List memory segments in the binary.
List strings in the binary.
List user-defined types (structs, enums, etc.).
List cross-references to or from an address.
Execute arbitrary Python code in IDA's context with a timeout.
Search for byte patterns in the binary.
Write bytes to an address.
Set the comment at an address.
Rename a symbol at an address.
Set the type of a symbol (function signature, struct, etc.).
Error handling lacks recovery guidance and error classification (retryable vs fatal); stack traces would confuse LLMs
Tool descriptions are below LLM-optimized range (50-200 chars); 'Read bytes from an address' is too terse for effective agent reasoning
run_python tool offers no confirmation/dry-run pattern for destructive code execution
No per-tool scope/permission declarations; agents cannot reason about least-privilege access control