Model Context Protocol server for interacting with IDA Pro through remote control. Enables binary analysis capabilities including script execution, string/export/import enumeration, searching, cross-references, and disassembly.
This IDA Pro MCP server has significant definition quality gaps. While all 12 tools are registered with names and basic schemas, most parameter descriptions are trivial (1-5 words), output schemas are completely undocumented, and error handling provides no recovery guidance. Tool names mostly follow verb_noun conventions (good), but descriptions are vague and do not explain WHEN to use each tool or what it returns. Parameters lack constraints (enums, ranges, format specs), and several tools like 'run_ida_command' expose dangerous write capabilities without adequate safeguards in the description. The server treats tool definitions as a direct pass-through to IDA Pro's HTTP plugin rather than optimizing for LLM reasoning.
Get disassembly for an address range
Get the list of exports from the binary
Get the list of functions in the binary
Get the list of strings from the binary
Get cross-references from an address
Get cross-references to an address
Execute an IDA Pro Script (IdaPython, Version IDA 8.3)
Output schemas are completely undocumented. Tools like get_functions, get_exports, and get_strings return data but the MCP server provides no schema describing the response structure (fields, types, pagination). LLMs cannot plan downstream operations or extract nested data without knowing what fields are available.
Parameter descriptions are trivial (1-5 words) and do not include format constraints, valid ranges, or usage context. Example: 'value' param in search_immediate_value has description 'Value to search for (number or string)' but does not explain accepted radix, address format (hex vs decimal), or how to structure multi-byte sequences.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 44 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
(FOR IDE USAGE) Execute an IDA Pro Script (IdaPython, Version IDA 8.3)
Search for a byte sequence in the binary
Search for immediate values in the binary
Search for names/symbols in binary
Search for text in the binary
Tool descriptions lack context for LLM selection. 'Execute an IDA Pro Script (IdaPython, Version IDA 8.3)' does not explain WHEN to use run_ida_command vs run_ida_command_filebased, what the tool returns, or when file-based execution is preferred. Descriptions are 34-40 chars on average (baseline 194 chars) and do not mention prerequisites or error conditions.
Dangerous write capabilities (run_ida_command, run_ida_command_filebased) are not gated by permission checks or confirmation patterns. The MCP server does not validate caller permissions, log execution, or support dry-run modes. Description does not warn of irreversible consequences.
Pagination and result limiting are not implemented. Tools like get_functions, get_exports, and get_strings return unbounded lists. No limit, offset, or page_size parameters. An IDA Pro binary with 10,000+ functions will blow the context window.
Error handling does not guide recovery. No documented error codes, categorization (retryable vs user-fixable), or actionable messages. If search_immediate_value fails with 'radix must be 2-36', the description does not validate this range, so the LLM cannot self-correct.
Address format is ambiguous. Tools accept startAddress and endAddress as strings but do not document whether they expect hex (0x400000), decimal (4194304), or IDA's internal segment:offset format. This forces the LLM to guess and likely causes failures.
get_functions, get_exports, and get_strings have empty input schemas (no properties, no required fields), yet descriptions are minimal (30 chars). These discovery tools should explain what data they reveal and when to call them in a workflow.