Security

Hex-Rays IDA MCP: the official IDA server for agents

From IDA maker Hex-Rays: agents open binaries and run IDAPython to decompile and analyze them, sharing databases with the IDA GUI. Requires IDA 9.4 or later.

Project and installation docs

View project

https://github.com/HexRaysSA/ida-mcp

Much of reversing a sample is repetitive: read the decompiler output, name functions and variables, fix types, leave comments. Hex-Rays IDA MCP lets a coding agent drive IDA through that work. Its design is deliberately small: rather than splitting IDA’s API into hundreds of tools, it offers six, centered on execute_python, so the agent writes IDAPython and runs it inside IDA. IDA’s maker Hex-Rays maintains it; the repository was created in August 2026 and had about 560 stars as of 2026-10-06.

What it does

  • Open and manage databases: open_database loads a binary and waits for auto-analysis; list_databases, save_database and close_database handle sessions.
  • Run IDAPython: execute_python runs scripts inside IDA, covering decompilation, renaming, retyping and cross-references, with a timeout and cancellation.
  • API reference: reference lets the agent look up the IDA API so its scripts break less often.
  • Shared databases: built on IDA Nexus, so several clients can work on one database. With the GUI plugin the agent sees what you have open in IDA; it also runs fully headless.
  • Session traces: every tool call goes to a JSONL trace, and uvx ida-mcp dashboard --open shows what the agent did.

Who it’s for

  • Malware analysts with an IDA Pro license who want Claude Code or Codex to take a first pass at naming and commenting.
  • Vulnerability researchers who need an agent to work through many binaries.

Setup

Needs Git, uv, and IDA 9.4 or later with idalib and Python 3.11+. Hex-Rays’ hcli installs the GUI plugin and offers to configure your agents:

uvx ida-hcli mcp install

Or add the Claude Code plugin by hand:

claude plugin marketplace add HexRaysSA/claude-marketplace
claude plugin install ida-mcp@HexRaysSA

Our take

The best-known IDA server has been the community project ida-pro-mcp, at about 12k stars as of 2026-10-06, and its author now recommends the official server in his README. The official version is vendor-maintained, tracks new IDA releases, and its IDA Nexus layer lets several clients share one database. The limits are clear too: it needs IDA 9.4 or later with idalib, so anyone on an older IDA should stay with the community server, which supports IDA 8.3 and up and likewise excludes IDA Free. execute_python runs arbitrary Python with the same rights as your IDA process, so analyze malware inside an isolated VM. Hex-Rays also suggests disabling other IDA MCP servers to avoid confusing the agent. Licensed MIT.