Conduit
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ConduitShow xrefs to the function at 0x402000"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Conduit
Conduit is an MCP debugger. One server connects Cursor, Claude, Cline, and any other MCP client to radare2, x64dbg, cdb, and Frida for disassembly, control-flow graphs, cross-references, strings, and live debugging.
The bars are engine support, not a success-rate benchmark. 100% means every engine that job applies to implements it: static jobs on radare2, and live memory on x64dbg, cdb, and Frida. 67% means x64dbg and cdb only. Frida does not step, pause, or take full breakpoints and thread control; its registers and call stack are the last hardware-breakpoint hit, not a live read. Assembly reading has an explain tool, and its accuracy was not measured. The gray “before” percents are an estimate of what a shell can do with no debugger tool, not a measured baseline.
Static analysis and live debugging share one tool surface. session_open picks the engine. Nothing is stubbed: a tool the engine does not implement returns capability_unsupported.
Protocol | MCP |
Transports | stdio, Streamable HTTP ( |
Static engine | radare2 — disassembly, CFG, xrefs, strings, hexdump |
Debug engines | x64dbg, cdb (WinDbg), Frida |
Clients | Cursor, Claude Desktop, Cline, OpenCode |
Install
Node.js 20 or newer and npm must already be on PATH. Then:
npm install -g github:Alyhnte/conduitThat puts the conduit command on PATH. The npm package name is conduit-debugger because conduit is already taken on the npm registry. Python is not required.
A pip build of the same project is also published as pip install conduit-debugger. The hub entry uses the npm command above.
Related MCP server: re-mcp
Prerequisites
Clean-machine install, in order:
Node.js ≥ 20 —
node --versionradare2 — a prebuilt release, no compilation. Any 6.x works (goldens were captured with 6.2.2; the comparator tolerates formatting drift between r2 versions). Must be on PATH as
radare2orr2:r2 -v. Override the path withDBG_BRIDGE_R2.Graphviz —
doton PATH (dot -V). Required to render a control-flow graph fromget_cfg. x64dbg does not draw that graph itself.Python 3.10+ — required for an
x64dbgsession. The loader embeds Python and the bridge needsiced_x86(python -m pip install iced_x86). 64-bit Python must be on PATH, or setPYTHON_HOME_X64. 32-bit Python is only for x86 targets (PYTHON_HOME_X86or%USERPROFILE%\Tools\python-x86). Regenerating the example fixture also uses Python 3. Details:plugin/x64dbg/README.md.
prerequisites reports these programs plus x64dbg, cdb, Frida, and ScyllaHide.
A missing program includes indir (a URL) and nereye (where to put it). Conduit
does not download it. The same hint is appended to engine_unavailable
when a session tries to start a missing engine.
explain reads an assembly window: what the region does, where it jumps, and
which calls are notifications (MessageBox, printf, and the like). Pass
instructions already read, or a session_id. Reading a live debug session
still needs confirm:true.
Run
node dist/server.js # stdio (default)
node dist/server.js --transport http --port 3847 # Streamable HTTPHTTP prints conduit streamable-http 2026-07-28 http://127.0.0.1:3847/mcp
and serves POST /mcp plus GET /health. --host, --port, and
--transport flags exist; DBG_BRIDGE_HOST, DBG_BRIDGE_PORT, and
DBG_BRIDGE_TRANSPORT do the same.
Optional token: set DBG_BRIDGE_TOKEN and every HTTP route (including
/health) requires Authorization: Bearer <token> (anything else gets
401 {error:"unauthorized"}). When unset, localhost stays open. The token
is env-only (a flag would leak via the process list) and is compared in
constant time. stdio needs no token: spawning the process locally is the
authentication there.
Connect a client
Ready-made configs live in configs/ (stdio and HTTP variants for Cursor,
Claude Desktop, Cline, and OpenCode). Replace <DBG_BRIDGE_DIR> with the
absolute path of this folder and follow configs/README.md, then restart
the client.
Quick check inside the client: call health. Expect status: ok and
name: conduit.
Client compatibility: the server speaks 2026-07-28 and also accepts
2025-era clients (for example opencode 1.x negotiating 2025-11-25)
through the SDK's legacy fallback. Verified end-to-end with real
opencode and cursor-agent runs (health → session_open →
open_target → disassemble).
End-to-end check
Fixture: examples/target/mini_branch.elf — a hand-packed 64-bit ELF
(1536 bytes, no compiler needed) whose entry 0x400200 runs a branching
function (lea + cmp/je if/else). .rodata holds HELLO-FIXTURE
and mini-branch. Sources: mini_branch.c, mini_branch.asm,
gen_mini_branch.py.
session_open {"engine": "radare2"}→session_idopen_target {"session_id", "path": "<abs path>/mini_branch.elf", "mode": "static"}disassemble {"session_id"}→ 10 ops atentry0get_cfg {"session_id", "format": "both"}→ 4-block CFG, JSON + DOTstrings {"session_id"}→HELLO-FIXTURE@0x400300,mini-branch@0x40030edump {"session_id", "address": "0x400200", "length": 34, "format": "json"}xrefs {"session_id", "address": "0x400300"}→ DATA xref from0x400200events_pull {"session_id"}→ containstarget.openedclose_target {"session_id"}/session_close {"session_id"}
Raw-protocol note (only if you drive the server without an MCP client):
every request on protocol 2026-07-28 carries the envelope
_meta: {"io.modelcontextprotocol/protocolVersion": "2026-07-28", "io.modelcontextprotocol/clientCapabilities": {}},
starting with server/discover. Over HTTP, POST /mcp also requires the
Mcp-Method header (and Mcp-Name for tools/call). The golden runner
(tests/run_golden.mjs) shows the exact wire format. The stdio transport
pins its dialect on the first request, so a bare request or a legacy
initialize locks that process into legacy mode and later
server/discover calls fail with Method not found.
Debug engines
The same debug_* tool names work on every engine. Config files under
configs/ do not name an engine. session_open does.
x64dbg | cdb | frida | |
Launch | hidden debugger, break on entry | hidden | spawn stays suspended until |
Attach / close | detach leaves the target running |
|
|
Software breakpoint | yes | yes |
|
Hardware execute | yes | yes (after the initial breakpoint) | yes, slots 0–3; a fifth is |
Hardware read/write, memory breakpoints | yes | hardware read/write yes; memory no |
|
Continue | until the next stop or exit | until the next stop or exit | until the next hit or exit; the hit slot is disarmed |
Pause / step | yes | yes |
|
Registers / call stack | live | live | last hardware-breakpoint hit only |
Live memory read / search / dump |
| same | same |
Disassemble / run to address |
| same | same; run-to arms one hardware slot and disarms it on the hit |
Assemble | XEDParse, no GUI |
|
|
Thread list / context |
| same; id is the cdb index | same; id is the OS thread id |
Thread select / freeze | yes | yes |
|
Scylla / ScyllaHide |
|
|
|
Snapshot / rewind | checkpoint of registers, threads, and one memory window | same | memory window restores; register commit is |
Where |
|
| npm dependency |
Debug fixtures live at plugin/x64dbg/test/mini_pe_x64.exe and mini_pe_x86.exe.
Test
npm test # node tests/run_golden.mjs
npm run test:debug # x64dbg launch + attach (Windows)
npm run test:cdb # cdb launch + attach (Windows)
npm run test:frida # Frida hardware-breakpoint loop (Windows)
npm run test:dynamic # confirm gate, live memory/code/thread/checkpoint
npm run test:explain # assembly reading + download hints
npm run test:concurrency # multi-client isolation over HTTP
npm run test:auth # optional DBG_BRIDGE_TOKEN gate over HTTPExpected: 38 passed, 0 failed. The suite checks prerequisites, fixture
determinism, golden output, Graphviz rendering, and full MCP sessions over
stdio and HTTP.
To re-capture goldens after an intentional behavior change:
node tests/run_golden.mjs --updateTroubleshooting
Symptom | Cause / fix |
|
|
| run |
golden mismatch after an r2 upgrade | formatting drift: run |
HTTP client cannot connect | the server must be running ( |
| only |
| the session is not radare2 |
| Frida has no single-step or thread-suspend API |
| repeat the dynamic tool call with |
| Frida already holds four hardware execute breakpoints |
| set |
| the dialect was pinned by the first request; restart and send the |
|
|
Host rejected over HTTP | set |
Layout
conduit/
├── src/ engines and MCP tools
├── dist/ build output (git-ignored)
├── examples/target/ mini_branch.elf fixture
├── plugin/x64dbg/ x64dbg bridge and debug fixtures
├── tests/ golden runner and engine acceptance
├── configs/ Cursor, Claude Desktop, Cline, OpenCode
└── README.mdLicense
MIT. See LICENSE. The x64dbg plugin sources are vendored from
ouonet/x64dbg-mcp; see
plugin/x64dbg/THIRD_PARTY_NOTICES.md.
This server cannot be deployed
Maintenance
Related MCP Connectors
Repository knowledge graph MCP server for codebase understanding and debugging.
MCP server to assist with JxBrowser development.
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
Host your MCP tool over streamable HTTP in one command.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceConnects AI agents to IDA Pro and x64dbg for unified static and dynamic reverse engineering, enabling coordinated analysis, debugging, and patch planning through a local MCP daemon.15MIT
- AlicenseAqualityCmaintenanceA multi-backend MCP server that exposes binary analysis capabilities from IDA Pro and Ghidra, allowing LLMs to directly drive reverse-engineering tools via natural language.11163Apache 2.0
- AlicenseNot gradedqualityCmaintenanceMCP server exposing the rizin CLI for static binary analysis of executables.MIT
- FlicenseCqualityDmaintenanceA radare2 MCP server for binary analysis and reverse engineering, enabling AI agents to interact with radare2 through natural language or structured commands for tasks like static analysis, debugging, and patching.4315-