MalBuddy
MCP server that integrates a headless Ghidra instance for binary reverse-engineering, enabling automated analysis and decompilation through a standardized interface.
README
Dummy Agent Malware
Reverse-engineering assistant built with Google ADK and a vendored Ghidra MCP stack
(Docker headless on :8089 → SSE bridge on :8081 → ADK agent).
Prerequisites
- Docker (for the headless Ghidra MCP server)
- Python 3.10+
- LLM endpoint — an OpenAI-compatible
/v1/chat/completionsserver (e.g. LiteLLM proxy) athttp://localhost:4000/v1
Setup
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
Ensure ghidra-mcp/docker/.env has a non-empty GHIDRA_MCP_AUTH_TOKEN
(a shell export alone is not enough for Docker Compose).
./scripts/start_ghidra_docker.sh creates/fills .env from .env.example,
reuses a shell GHIDRA_MCP_AUTH_TOKEN if set, or generates one with
openssl rand -hex 32.
Start Ghidra Docker
Headless Ghidra MCP HTTP API on :8089:
./scripts/start_ghidra_docker.sh
Start MCP bridge
SSE bridge on :8081 (leave this running in its own terminal):
./scripts/start_ghidra_bridge.sh
The bridge loads GHIDRA_MCP_AUTH_TOKEN from ghidra-mcp/docker/.env and
talks to http://127.0.0.1:8089.
Verify stack
With Docker and the bridge running:
pytest tests/test_ghidra_stack.py -v
These are integration smoke tests (@pytest.mark.integration). They skip cleanly
if services are down; they fail if only half the stack is up.
Start agent
From the parent directory of this folder:
adk web
Open the ADK web UI and select Dummy_Agent_Malware.
agent.py expects the bridge at http://127.0.0.1:8081/sse (GHIDRA_MCP_URL).
Config knobs
| Setting | Where |
|---|---|
| LLM base URL / API key / model | agent.py (LLM_BASE_URL, LLM_API_KEY, LLM_MODEL_NAME) |
| Bridge SSE URL for ADK | agent.py (GHIDRA_MCP_URL) |
| Ghidra HTTP auth token | ghidra-mcp/docker/.env (GHIDRA_MCP_AUTH_TOKEN) |
Troubleshooting
- Docker not healthy / connection refused on :8089 — wait for the container
healthcheck (
docker compose -f ghidra-mcp/docker/docker-compose.yml ps), check logs withdocker logs ghidra-mcp, and confirm the token in.envmatches what compose started with. - Missing / empty auth token — put
GHIDRA_MCP_AUTH_TOKEN=...inghidra-mcp/docker/.env(not only in your shell). Re-run./scripts/start_ghidra_docker.sh(it can copy a shell token into.envor generate one), then recreate the container. - Bridge connection refused on :8081 — start
./scripts/start_ghidra_bridge.shand ensure Docker is already up; the bridge needs:8089plus the same token.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.