# Add to your Claude Code skills
git clone https://github.com/blacktop/ida-mcp-rsGuides for using mcp servers skills like ida-mcp-rs.
Last scanned: 5/19/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-19T07:45:33.800Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how ida-mcp-rs compares with popular alternatives.
ida-mcp-rs is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by blacktop. Headless IDA Pro MCP Server. It has 858 GitHub stars.
Yes. ida-mcp-rs passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/blacktop/ida-mcp-rs" and add it to your Claude Code skills directory (see the Installation section above).
ida-mcp-rs is primarily written in Rust. It is open-source under blacktop on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh ida-mcp-rs against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
--profile=lean measured 25% cheaper than the full set on real tasks with
the same correctness, and the full set is there when you need it.save_idb checkpoints,
analysis flushed to disk as soon as it finishes, graceful shutdown on every
signal a client sends, and database state discarded rather than trusted
after an IDA crash.run_script returns a trailing
expression as JSON and keeps state between calls, so one script can find,
filter, and return only what matters.macOS / Linux (via Homebrew)
brew install blacktop/tap/ida-mcp # Latest (IDA 9.4)
macOS (Apple Silicon), older IDA releases (via versioned Homebrew casks)
brew install blacktop/tap/ida-mcp@9.3 # IDA 9.3/9.3sp1
brew install blacktop/tap/ida-mcp@9.2 # IDA 9.2
Windows (via Scoop)
scoop bucket add blacktop https://github.com/blacktop/scoop-bucket
scoop install blacktop/ida-mcp
Windows note: see Windows below for DLL discovery options.
macOS / Linux (via Nix)
nix shell github:blacktop/nur#ida-mcp \
--extra-experimental-features 'nix-command flakes'
Direct download: grab the archive for your platform from GitHub Releases.
Build from source: see docs/BUILDING.md.
ida-mcp versions follow IDA Pro versions:
v9.5.0-beta.xfor the IDA 9.5 beta,v9.4.xfor IDA 9.4,v9.3.xfor IDA 9.3, andv9.2.xfor IDA 9.2. ida-mcp checks compatibility when it initializes IDA. An incompatible version causes IDA-backed tools to fail with an error identifying the detected version and, when available, the loaded library path. Scoop and NUR publish only the latest version. For an older IDA, use the matching GitHub Release or, on Apple Silicon, a versioned Homebrew cask.
A prerelease build for the IDA 9.5 beta is available for macOS on Apple Silicon:
brew install blacktop/tap/ida-mcp@beta # IDA 9.5 beta
The beta cask conflicts with the stable ida-mcp cask, so remove one before installing the other:
brew uninstall --cask ida-mcp # switch to the beta
brew uninstall --cask ida-mcp@beta # switch back to stable
You can also download ida-mcp_<version>_Darwin_arm64.tar.gz from the prerelease on GitHub. There are no beta packages for Linux or Windows; build main from source as described in docs/BUILDING.md.
Standard IDA installs in /Applications work without extra setup:
claude mcp add ida -- ida-mcp
If you see Library not loaded: @rpath/libida.dylib, point DYLD_LIBRARY_PATH at your IDA install:
claude mcp add ida -e DYLD_LIBRARY_PATH='/path/to/IDA.app/Contents/MacOS' -- ida-mcp
Paths found automatically:
/Applications/IDA Professional 9.4.app/Contents/MacOS/Applications/IDA Pro 9.4.app/Contents/MacOS/Applications/IDA Home 9.4.app/Contents/MacOS/Applications/IDA Essential 9.4.app/Contents/MacOSThe beta searches the same locations with 9.5 in place of 9.4.
The IDA installer defaults to ~/ida-pro-9.4, and the launcher script looks there:
claude mcp add ida -- ida-mcp
For any other install location, set IDADIR:
claude mcp add ida -e IDADIR='/path/to/ida' -- ida-mcp
Lookup order: $IDADIR, then ~/ida-pro-9.4, then /opt/ida-pro-9.4 and the other RUNPATH fallbacks.
Option A: put ida-mcp.exe in your IDA directory. This is the simplest route and needs no environment setup:
# Copy the binary next to ida.dll / idalib.dll
copy ida-mcp.exe "C:\Program Files\IDA Professional 9.4\"
claude mcp add ida -- "C:\Program Files\IDA Professional 9.4\ida-mcp.exe"
Option B: install with Scoop, which finds IDA and sets IDADIR:
scoop bucket add blacktop https://github.com/blacktop/scoop-bucket
scoop install blacktop/ida-mcp
claude mcp add ida -- ida-mcp
Option C: set IDADIR yourself:
$idaDir = "C:\Program Files\IDA Professional 9.4"
[Environment]::SetEnvironmentVariable("IDADIR", $idaDir, "User")
$userPath = [Environment]::GetEnvironmentVariable("Path", "User")
$pathEntries = @($userPath -split ";" | Where-Object { $_ })
if (-not ($pathEntries -contains $idaDir)) {
[Environment]::SetEnvironmentVariable(
"Path", (@($pathEntries + $idaDir) -join ";"), "User"
)
}
# Then restart your terminal
claude mcp add ida -- ida-mcp
Windows has to find ida.dll and idalib.dll before ida-mcp starts. Putting ida-mcp.exe in the IDA directory is the easiest way. Otherwise, set IDADIR and add the same directory to PATH so the DLLs load at runtime.
Common IDA paths:
C:\Program Files\IDA Professional 9.4C:\Program Files\IDA Pro 9.4C:\Program Files\IDA Home 9.4The binary links against IDA's libraries at runtime. Baked-in RPATHs cover the standard install paths. For anything else:
| Platform | Library | Fallback Configuration |
|---|---|---|
| macOS | libida.dylib |
DYLD_LIBRARY_PATH |
| Linux | libida.so |
IDADIR (launcher reads it) or LD_LIBRARY_PATH |
| Windows | ida.dll |
Place exe in IDA dir, or set IDADIR and add IDA dir to PATH |
claude mcp add ida -- ida-mcp
codex mcp add ida -- ida-mcp
gemini mcp add ida -- ida-mcp
Add to .cursor/mcp.json:
{
"mcpServers": {
"ida": { "command": "ida-mcp" }
}
}
Once your agent is configured, it can drive the tools directly:
# Open a binary. This returns quickly; analysis runs separately.
open_idb(path: "~/samples/malware")
# Keep the generated database out of a read-only input directory
open_idb(path: "/System/example", idb_out: "~/ida-work/example.i64")
# Pick one slice of a universal (fat) Mach-O
open_idb(path: "/bin/ls", arch: "arm64e", idb_out: "~/ida-work/ls.i64")
# These work immediately, no analysis needed
list_functions(limit: 20)
disasm_by_name(name: "main", count: 20)
strings(limit: 10)
# For xrefs/decompile on large binaries, run analysis in the background
analyze_funcs(background: true) # returns task_id
task_status(task_id: "analyze-<random>") # poll progress (ID from the analyze_funcs response)
# Decompile (requires Hex-Rays + completed analysis)
decompile(address: "0x100000f00")
# Discover more tools
tool_catalog(query: "find callers")
Tools that change the database (rename, set_comments, patch, patch_asm,
apply_types, declare_stack, delete_stack, and lumina_apply) take exactly
one address or one symbol name. Names must match exactly, case included. A near
miss changes nothing and returns up to eight similar names with their addresses.
A returned target record identifies the database, resolved symbol (or null),
and requested and effective addresses. Check the operation's result to determine
whether the change succeeded.
For Hex-Rays locals and arguments, use list_lvars with one function address
or exact target_name. rename_lvar and set_lvar_type take the same function
selector plus exactly one of lvar_locator or lvar_name. Prefer the opaque
locator returned by list_lvars: display names such as v1 can move to a
different local after a prototype change. A stale or ambiguous locator fails
without making a change. Locals without a locator are edited by exact, unique
name.
The tools return the variable as it was before the edit and the resolved
function target. Use save_idb to checkpoint edits to disk.
list_lvars(target_name: "interesting_function")
rename_lvar(target_name: "interesting_function", lvar_locator: "<locator from list_lvars>", new_name: "count")
set_lvar_type(target_name: "interesting_function", lvar_loc