Skip to main content
Glama

bindiff-mcp

MCP server that gives reverse-engineering agents binary diffing: export binaries to BinExport v2 and compare two builds with BinDiff.

IDA is driven through ida-nexus, so a binary already open in the IDA GUI is exported from that database (renames and annotations included); otherwise a headless idalib worker is spawned and released again when the export finishes. Export and diff parsing reuse python-binexport and python-bindiff.

Prerequisites

  • IDA Pro 9.x with idalib enabled (idapyswitch), IDADIR pointing at the install

  • The BinExport IDA plugin (binexport12_ida.so) in $IDAUSR/plugins

  • The BinDiff differ (bindiff) in PATH, in $BINDIFF_PATH, default at /opt/zynamics/BinDiff/bin

  • libmagic (used by python-binexport through python-magic)

Related MCP server: GhidraMCP

Install

uv pip install .

Run

bindiff-mcp stdio                              # stdio transport (default)
bindiff-mcp http --host 127.0.0.1 --port 8745  # Streamable HTTP at /mcp

Register with Claude Code:

claude mcp add bindiff -- bindiff-mcp stdio
claude mcp add bindiff --transport http http://127.0.0.1:8745/mcp

Tools

binexport(binary, output_results_dir=".")

Exports binary to <output_results_dir>/<binary name>.BinExport. An export that is at least as new as the binary is reused instead of re-analyzing it. Returns JSON:

{
  "binary": "/work/httpd",
  "binexport": "/work/out/httpd.BinExport",
  "reused": false,
  "name": "httpd",
  "architecture": "x86-64",
  "sha256": "...",
  "functions": 2317
}

bindiff_compare(primary_binary, secondary_binary, output_results_dir=".")

Exports both binaries in parallel (into primary/ and secondary/ subdirectories, so identical file names cannot collide), runs the differ, and writes four JSON files into output_results_dir:

File

Content

matched_similar.json

matched functions with similarity 1.0 (identical)

matched_different.json

matched functions that changed, most divergent first

primary_only.json

functions only in the primary binary

secondary_only.json

functions only in the secondary binary

Match entries carry both addresses and names, the similarity and confidence scores and the BinDiff algorithm that produced the match; unmatched entries carry address, name and function type. The tool returns JSON with the overall similarity and confidence, the .BinDiff database path, per-list counts and the path of every file written.

Environment

Variable

Default

Meaning

BINDIFF_MCP_OPEN_TIMEOUT

600

Seconds to wait for IDA to open a database

BINDIFF_MCP_EXPORT_TIMEOUT

1800

Seconds for one export, excluding autoanalysis

BINDIFF_PATH

—

Directory containing the bindiff differ

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    Not graded
    maintenance
    Enables intelligent file and folder comparison with advanced text normalization, duplicate detection, and line-level diff analysis. Provides secure workspace-constrained file operations with CRC32-based exact matching and smart text comparison capabilities.
    -
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables LLMs to autonomously reverse engineer binaries using Ghidra's capabilities including decompilation, function analysis, automatic renaming, and BSim integration for function similarity matching.
    1
    AGPL 3.0
  • F
    license
    A
    quality
    D
    maintenance
    Enables binary comparison capabilities by leveraging IDA Pro and BinDiff to analyze similarities and differences between files. Users can perform automated function analysis to identify changed functions and compare original binaries against patched versions.
    1
    2
    -