MCP server for IDA SDK API workflow retrieval
ida-api-mcp has 8 well-named, verb-led tools with descriptions and documented input schemas. However, critical gaps reduce quality: (1) All tools return unstructured string responses rather than JSON objects with documented field schemas, agents cannot extract structured data or chain calls predictably. (2) Output schemas are completely undocumented, no type definitions for response fields. (3) Error handling is minimal; many tools return error text strings rather than categorized, actionable error responses with recovery guidance. (4) No pagination support despite tools like get_workflows and get_api_doc returning lists that could exceed context windows. (5) Tool descriptions lack specificity about parameter formats, constraints, and dependencies. (6) No input validation or range constraints on numeric parameters (max_files in initialize_index). (7) No security scoping or permission gates on destructive tools (clear_index, initialize_index). Naming and basic descriptions are solid, but lack of structured output, output schema documentation, and error handling guidance prevent this from reaching 70+.
Delete index collections for one indexed SDK version.
Look up IDA SDK API documentation for a function, struct, or class. Supports fuzzy and partial matching — no fully qualified name needed. Requires an initialized index. If no index exists, returns initialization instructions. Use get_versions() to check availability, or initialize_index() to build one.
Return metadata about the currently indexed SDK version. Shows version, build timestamp, and counts for workflows and API docs.
List all indexed IDA SDK versions and show which is currently active. Returns a list of available SDK versions with the active one marked. Call this first to verify the index is ready before using query tools. If no versions are indexed, returns instructions for initializing.
Search for IDA SDK API workflows matching a task description. Returns ranked workflow call chains showing the correct API call sequence for accomplishing the described task. Each result includes ordered API calls with data-flow dependencies and source code. Requires an initialized index. If no index exists, returns initialization instructions. Use get_versions() to check availability, or initialize_index() to build one.
All tools return unstructured string responses instead of JSON objects with documented field schemas. LLMs cannot extract structured data, parse results programmatically, or chain calls reliably. E.g., get_workflows returns markdown-formatted text; agents cannot extract workflow IDs, trust levels, or API call sequences for downstream processing.
No output schema documentation. Tools return results but the schema field shows only input constraints. Response structure (field names, types, nested objects) is undocumented, agents must infer structure from unstructured text, causing parsing errors and wasted reasoning cycles.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 63 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 50 | - | v1 |
Build the IDA SDK workflow index.
Find IDA SDK APIs commonly used alongside a given function or type. Returns co-occurring APIs based on real usage patterns in SDK source code. Requires an initialized index. If no index exists, returns initialization instructions. Use get_versions() to check availability, or initialize_index() to build one.
Switch to a specific indexed IDA SDK version.
Error responses are plain strings with no categorization. Queries that fail (e.g., 'No matching workflows found') return untyped text. Agents cannot distinguish retryable errors (transient failure) from user-fixable errors (bad query) from fatal errors (index not initialized). Recovery paths are not offered programmatically.
Destructive tools (clear_index, initialize_index) have no permission gates, dry-run mode, or confirmation workflow. An agent with access can delete entire indexed versions without safeguards. No audit trail or scope declaration, tools do not declare required permissions (e.g., 'admin:index').
No pagination for list-returning tools. get_workflows and get_api_doc hardcode n_results=3 and n_results=5 internally. If results exceed the limit, agents see truncated output with no way to fetch additional pages. Large result sets risk context window exhaustion.
Parameter descriptions lack format constraints and ranges. initialize_index accepts max_files as an integer with no documented minimum, maximum, or meaning of 0. select_version accepts a version string with no documented format (is it '84', 'v84', '8.4', 'IDA84'?). Agents cannot validate input constraints and are prone to invalid calls.
No input validation or error messages for invalid parameters. If an agent calls select_version with a non-existent version, it gets a plain text error. No enum definition in schema, LLMs cannot predict valid versions without calling get_versions first.
Dependency hints scattered across descriptions rather than formalized. get_workflows says 'Use get_versions() to check availability', but this instruction is in prose, not a structured constraint. If index is not initialized, agents see the long _NO_INDEX_MESSAGE text string, not a structured error with a recovery action.