kuna_mcp

kuna_mcp

MCP server for targeted binary analysis with Kuna, enabling listing and decompiling specific functions via natural language.

Category
访问服务器

README

kuna_mcp

kuna_mcp is a Python MCP server for targeted binary analysis with Kuna. It exposes Kuna through MCP's Streamable HTTP transport, so MCP clients communicate with it using JSON-RPC at http://127.0.0.1:8000/mcp by default.

The project and Python package are named kuna_mcp; the installed shell command uses the conventional executable spelling kuna-mcp.

Whole-binary decompilation is deliberately not exposed. Large binaries can take a long time and produce far more context than an AI can use safely.

MCP tools

  • list_functions — list functions as structured JSON, with pagination when Kuna returns a JSON list.
  • decompile_function — decompile one function by name or hexadecimal VMA.
  • decompile_functions — decompile a bounded list concurrently and return one response. Individual failures are preserved alongside successful results.

The server does not expose decompile-all or decompile-project.

Release status

The current release is 0.1.0: the first usable version of kuna_mcp. The server, installer, real Kuna integration, and HTTP transport are functional, but the public MCP tool schemas may still evolve before the 1.0.0 compatibility milestone.

Install

Requirements are Python 3.10+, a Rust toolchain, make, and git.

./install.sh

The installer initializes the Kuna submodule, runs make binaries and make specs, creates .venv, and installs this package. Kuna's executable is expected at kuna/decompiler/target/release/kuna and its specifications at kuna/specs.

For Python-only development (using an existing Kuna installation):

python3 -m venv .venv
.venv/bin/pip install -e '.[dev]'

Run over HTTP

.venv/bin/kuna-mcp

Options and their environment equivalents:

--host  KUNA_MCP_HOST  default: 127.0.0.1
--port  KUNA_MCP_PORT  default: 8000
--path  KUNA_MCP_PATH  default: /mcp

Example:

.venv/bin/kuna-mcp --host 0.0.0.0 --port 8080

The default loopback binding is intentional. If you bind to a public or shared interface, put the server behind authentication and TLS; every authenticated client can request reads of binaries allowed by KUNA_ALLOWED_BINARY_ROOTS.

Connect an MCP client to http://127.0.0.1:8000/mcp. The server uses stateless Streamable HTTP with JSON responses; the MCP SDK performs initialization, JSON-RPC validation, tool discovery, input-schema validation, and response framing.

Use with an MCP client

Start kuna-mcp, then register the following Streamable HTTP endpoint in your MCP client:

http://127.0.0.1:8000/mcp

For clients that accept JSON server configuration, the entry normally has this shape (the surrounding configuration filename varies by client):

{
  "mcpServers": {
    "kuna": {
      "type": "http",
      "url": "http://127.0.0.1:8000/mcp"
    }
  }
}

Once connected, ask the client to list functions before requesting targeted decompilation. For example:

List the first 50 functions in /bin/ls with Kuna.
Decompile function sub_187d0 from /bin/ls.
Decompile addresses 0x187d0 and 0x18940 from /bin/ls in one request.

The same flow can be exercised with the MCP Python client:

import asyncio
from mcp import Client


async def main():
    async with Client("http://127.0.0.1:8000/mcp") as client:
        functions = await client.call_tool(
            "list_functions",
            {"binary_path": "/bin/ls", "offset": 0, "limit": 10},
        )
        print(functions.structured_content)


asyncio.run(main())

MCP Inspector

With Node.js available, start the server and connect the MCP Inspector to the URL above:

npx -y @modelcontextprotocol/inspector

Configuration and limits

All values are read when the server starts.

Variable Default Purpose
KUNA_BINARY ./kuna/decompiler/target/release/kuna Kuna executable
KUNA_SLEIGH_PATH ./kuna/specs Compiled SLEIGH specifications
KUNA_ALLOWED_BINARY_ROOTS project root, /bin, /usr/bin Allowed input roots, separated by : on Unix
KUNA_TIMEOUT_SECONDS 120 Timeout for each Kuna process
KUNA_MAX_BATCH_SIZE 20 Maximum functions in one batch
KUNA_MAX_CONCURRENCY 4 Maximum simultaneous Kuna processes
KUNA_MAX_OUTPUT_BYTES 8388608 Maximum stdout bytes per Kuna call

Set the allow-list to every directory containing binaries the MCP may inspect:

KUNA_ALLOWED_BINARY_ROOTS=/samples:/opt/firmware .venv/bin/kuna-mcp

Resolved paths must remain below one of those roots, so symlinks cannot escape the allow-list. Kuna is always launched without a shell.

Example tool arguments

List functions:

{
  "binary_path": "/bin/ls",
  "mode": "auto",
  "offset": 0,
  "limit": 500
}

Decompile by name:

{
  "binary_path": "/bin/ls",
  "function": "sub_187d0"
}

Decompile several addresses in one request:

{
  "binary_path": "/bin/ls",
  "functions": ["0x187d0", "0x18940"],
  "by_address": true,
  "mode": "reliable"
}

Test

Install the development dependencies and run the fast test suite:

.venv/bin/pip install -e '.[dev]'
.venv/bin/pytest -q

These tests use a controlled fake Kuna executable and an in-memory MCP client, so they validate command construction, pagination, validation, partial batch failures, structured MCP results, and exposed tool names without requiring a Kuna rebuild.

To test the relevant Kuna CLI surface itself:

source "$HOME/.cargo/env"
cargo test --manifest-path kuna/decompiler/Cargo.toml \
  -p kuna-cli --test decompile_all_cli

End-to-end HTTP test

Terminal 1:

.venv/bin/kuna-mcp

Terminal 2:

.venv/bin/python scripts/http_smoke_test.py \
  --url http://127.0.0.1:8000/mcp \
  --binary /bin/ls

The smoke test connects through HTTP, initializes MCP/JSON-RPC, discovers the tools, lists functions with the real Kuna executable, and decompiles the first non-header function by address. A successful run exits with status zero.

Only analyze binaries you are legally authorized to inspect.

https://github.com/user-attachments/assets/47458d03-e454-43ab-acc8-2a4e57a201de

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选