IDA Pro MCP fusion with cache queries and multi-binary headless analysis.
io.github.rison1337/ida-pro-mcp-fusion — Model Context Protocol (MCP) server
IDA Pro MCP fusion provides Model Context Protocol access for multi-binary headless analysis, with cache queries. It is positioned for binary reverse-engineering workflows that integrate disassembly/decompilation tooling and supports an SQLite cache for reuse of query results.
🛠️ Key Features
IDA Pro MCP fusion
Cache queries
Multi-binary headless analysis
🚀 Use Cases
Multi-binary reverse-engineering
Headless analysis pipelines
Binary analysis and decompiler/disassembler-based workflows
Malware-analysis-oriented research
⚡ Developer Benefits
Integrates MCP with IDA Pro components (including IDA libraries)
Supports agentic-reverse-engineering patterns
Uses SQLite and an SQLite-cache to support cached lookups
⚠️ Limitations
Focused on IDA Pro workflows and headless analysis rather than general-purpose MCP tooling
IDA Pro MCP Fusion connects MCP-compatible coding agents to IDA Pro and turns a single connection into a practical reverse-engineering workspace. It combines live IDA analysis with a persistent SQLite index and a supervisor that can keep several binaries open in isolated headless workers.
Use it to decompile and disassemble functions, trace cross-references, query types, rename symbols, patch data, create signatures, inspect multiple samples, and reuse cached analysis without repeatedly walking IDA's single-threaded APIs.
IMPORTANT
This project requires a local, licensed installation of IDA Pro. IDA Free is not supported. The server does not provide IDA, Hex-Rays, or a hosted analysis service.
Why Fusion
Capability
What it changes
⚡
Persistent SQLite cache
Functions, strings, globals, imports, xrefs, and call-graph edges remain queryable across repeated investigations.
◈
Multi-binary supervisor
Open, address, and close several GUI or headless databases through one MCP endpoint.
⛓
Persistent workers
A later supervisor can discover and adopt an existing worker for the same database.
◎
Batch-first workflow
Warm analysis and build caches for a collection of samples with one idb_batch_open call.
The cache lives beside the IDB as <database>.mcp.sqlite. Freshness is checked against the IDB modification time and cache schema, so stale rows are not silently reused.
The codebase registers 75 IDA-facing analysis tools, plus the supervisor's multi-session controls. The exact number visible to a client intentionally varies: debugger tools are an extension, dangerous operations are disabled unless explicitly enabled, and a profile can expose a smaller allowlist.
Restart IDA and the MCP client after installation.
Safety notes
The server binds to loopback by default. Do not expose it to an untrusted network.
Mutating and arbitrary-Python tools are marked unsafe and are not enabled by default.
py_eval, py_exec_file, debugger controls, and patching operations can execute code or permanently change an IDB. Enable them only for trusted clients and inputs.
Analyze untrusted binaries inside the same isolation boundary you would use for manual malware analysis.
Enable unsafe worker tools only when the workflow requires them:
bash
idalib-mcp --stdio --unsafe
Troubleshooting
uvx is not recognized
Install uv with python -m pip install uv, open a new terminal, and confirm with uvx --version.
Python / IDA version mismatch
Run Hex-Rays idapyswitch, select a Python 3.11+ installation, then activate idalib again with py-activate-idalib.py.
A database call says that database is required
Call idb_list() and pass the returned session_id as database=. Paths and filenames are not accepted in place of a session ID.
The worker limit has been reached
Close an unused session with idb_close, raise --max-workers, or use close_after_cache=True for corpus indexing.
Development
Clone the repository and run the platform-independent test suite:
Run the IDA-backed suite in an activated IDA environment:
bash
uv run ida-mcp-test tests/typed_fixture.elf -q
New IDA tools live in src/ida_pro_mcp/ida_mcp/api_*.py and register through the @tool decorator. Supervisor and worker lifecycle tests live under tests/.
The project builds on the MIT-licensed mrexodia/ida-pro-mcp codebase. Its persistent cache and headless orchestration also incorporate ideas developed in QiuChenly/ida-pro-mcp-enhancement and winmin/ida-headless-mcp. Attribution is retained here and in the source history; Fusion's packaging, cache tooling, batch workflow, session lifecycle, and public identity are maintained in this repository.
License
Distributed under the MIT License. IDA Pro and Hex-Rays are trademarks of Hex-Rays SA and are not included with this project.
IDA Pro MCP Fusion подключает MCP-совместимых агентов к IDA Pro и превращает одно соединение в полноценное рабочее место для реверсинга. Живой анализ IDA объединён с постоянным SQLite-индексом и supervisor-процессом, который может держать несколько бинарников в изолированных headless-воркерах.
Можно декомпилировать и дизассемблировать функции, исследовать перекрёстные ссылки, типы и граф вызовов, переименовывать символы, патчить данные, создавать сигнатуры и повторно использовать уже построенный анализ.
IMPORTANT
Нужна локальная лицензированная установка IDA Pro. IDA Free не поддерживается. Сервер не содержит IDA, Hex-Rays и не отправляет бинарники во внешний сервис.
Почему Fusion
Возможность
Что это даёт
⚡
Постоянный SQLite-кэш
Функции, строки, глобальные переменные, импорты, xref и call graph доступны между запусками.
◈
Мульти-бинарный supervisor
Несколько GUI- или headless-баз управляются через одну MCP-точку.
⛓
Живущие воркеры
Следующее подключение может найти и принять уже запущенный worker для той же базы.
◎
Пакетный анализ
Открытие образцов и построение кэшей выполняется одним idb_batch_open.
⛨
Контролируемый интерфейс
Read-only-профили, лимит воркеров, тайм-ауты и opt-in для опасных инструментов.
Кэш лежит рядом с IDB в файле <database>.mcp.sqlite. Актуальность проверяется по времени изменения IDB и версии схемы, поэтому устаревшие данные не выдаются незаметно.
MCP-клиент, который умеет запускать локальный stdio-сервер
Установите uv, если его ещё нет:
bash
python -m pip install uv
Один раз активируйте headless Python от IDA:
powershell
# Windows — при необходимости измените версию и путь к IDA
uv run "C:\Program Files\IDA Professional 9.3\idalib\python\py-activate-idalib.py"
bash
# macOS — при необходимости измените версию и путь к IDA
uv run "/Applications/IDA Professional 9.3.app/Contents/MacOS/idalib/python/py-activate-idalib.py"
2. Добавьте MCP-сервер
Рекомендуемая конфигурация запускает код напрямую из этого репозитория:
В кодовой базе зарегистрировано 75 инструментов анализа IDA, а supervisor добавляет управление мульти-бинарными сессиями. Видимый клиенту список намеренно меняется: debugger-инструменты являются расширением, опасные операции отключены без явного разрешения, а профиль может оставить только выбранные имена.
Проект основан на MIT-кодовой базе mrexodia/ida-pro-mcp. Постоянный кэш и headless-оркестрация также используют идеи из QiuChenly/ida-pro-mcp-enhancement и winmin/ida-headless-mcp. Атрибуция сохранена в README и истории исходников; упаковка Fusion, cache-инструменты, batch workflow и lifecycle сессий поддерживаются в этом репозитории.
Лицензия
Проект распространяется по MIT License. IDA Pro и Hex-Rays — товарные знаки Hex-Rays SA и не входят в состав проекта.