idamesh
An MCP server that exposes IDA Pro's disassembler and Hex-Rays decompiler as tools and resources, enabling parallel binary analysis with multiple agents through a supervisor.
README
idamesh
A Model Context Protocol (MCP) server for IDA Pro. It exposes IDA's disassembler and the Hex-Rays decompiler to MCP clients (Claude and others) as tools and resources, with a supervisor that fronts multiple databases behind one endpoint so several agents can work in parallel.
What it does
- Read — decompile (Hex-Rays), disassemble, cross-references, call graphs, type and struct inspection, memory reads, and string / byte / text search.
- Query — structured filters over functions, instructions, xrefs, types, imports.
- Analyze — survey / triage, crypto and dangerous-API detection, vulnerability heuristics, stack-string reconstruction, and dataflow / taint tracing.
- Mutate — rename, comment, retype, define code and data, edit stack frames, patch bytes / assembly, bookmarks, and annotation export / import.
- Parallelize — open each database over a private copy so multiple agents can work the same binary at once, and merge their edits back into one database.
Read-only IDB state is also projected as ida://… MCP resources.
Requirements
- Python 3.9+
- A licensed IDA Pro install providing the
idapro/idalibPython API. Point theIDADIRenvironment variable at your IDA installation directory.
Install
pip install idamesh
Or from a clone, for development:
pip install -e .[dev] # editable install + pytest, to run the test suite
This provides the idamesh command with three subcommands: worker, supervisor,
and install.
Usage
Headless worker — one database on stdio (the client launches it):
idamesh worker /path/to/target.exe
Supervisor — one HTTP endpoint fronting many databases:
idamesh supervisor # http://127.0.0.1:8745/mcp
Open and close databases behind it with the idb_open / idb_list / idb_close
tools; route any tool to a session with an optional database key (omit it when a
single database is open). Opening the same binary twice yields two independent
sessions; idb_merge reconciles their edits.
GUI plugin — serve MCP over your live, open IDA database:
idamesh install # deploy the plugin into IDA's user directory, then restart IDA
Run idamesh supervisor (or set IDAMESH_AUTOLAUNCH_SUPERVISOR=1 to have the
plugin start one), then open a binary in IDA — the supervisor adopts the live
session and routes to it.
Both the worker (--transport http) and the supervisor speak MCP Streamable
HTTP at a single /mcp endpoint, loopback-bound with Origin validation.
Connect from Claude Code
claude mcp add --scope user --transport http idamesh http://127.0.0.1:8745/mcp
Or launch a single stdio worker directly:
claude mcp add --scope user -e IDADIR=/path/to/IDA-Pro \
idamesh -- idamesh worker /path/to/target.exe
Tests
pip install -e .[dev]
python -m pytest -q
The live idalib end-to-end tests skip cleanly when IDA is unavailable (no
IDADIR), so the suite is green without an IDA install.
License
MIT.
<!-- mcp-name: io.github.JordanRO2/idamesh -->
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。