Skip to main content
Glama
Heretek-RE

re-gdb

by Heretek-RE
README.md
# re-gdb

MCP server wrapping [GDB](https://www.gnu.org/software/gdb/) + [GEF](https://github.com/hugsy/gef) for dynamic analysis. Spawns a persistent GDB subprocess per session and drives it via the GDB/MI protocol.

## Tools

| Tool | What it does |
|---|---|
| `check_gdb` | Confirm gdb + GEF |
| `start_session` | Open a session, optionally load a binary |
| `end_session` | Tear down a session |
| `run_to_breakpoint` | Set a BP and run |
| `step_count` | Single-step N times, return registers |
| `read_memory` | `x/N fmt ADDR` |
| `gef_heap` | GEF `heap chunks` |
| `gef_canary` | GEF `canary` |
| `gef_registers` | GEF `registers` |
| `gef_vmmap` | GEF `vmmap` |
| `gef_nearpc` | GEF `nearpc` |
| `gef_pattern_create` / `gef_pattern_offset` | Cyclic-pattern helpers |
| `attach_pid` | Attach to a running process |

## Install

```bash
# System dependency
apt install gdb        # Debian/Ubuntu
brew install gdb        # macOS
scoop install gdb       # Windows

# GEF (auto-installed by install.sh to ~/.gdb/gef.py)
curl -fsSL https://github.com/hugsy/gef/raw/main/gef.py -o ~/.gdb/gef.py

# Python
pip install -e ./servers/re-gdb
```

## Safety

Never run unsigned binaries on a host you care about. Use a sandbox, a VM, or a Docker container. Dynamic analysis on untrusted samples is dangerous.

TDQS

B3/5.0

Scored across 14 tools

Disambiguation5/5

Each tool targets a distinct GDB operation or GEF feature, with clear separation between session management, memory reading, stepping, breakpoints, and specific GEF utilities. No two tools have overlapping purposes.

Naming Consistency5/5

Tool names follow a predictable pattern: core GDB operations use verb_noun (attach_pid, read_memory) while GEF-specific tools use the gef_ prefix followed by a noun (gef_heap, gef_registers). Within each subgroup, naming is consistent and intuitive.

Tool Count5/5

14 tools is well-scoped for a GDB interface, covering essential debugger actions (attach, breakpoint, step, memory read) and key GEF features (heap, registers, vmmap, canary, pattern). Not too few nor overwhelming.

Completeness3/5

Covers core debugging operations but misses common tasks like memory write, expression evaluation, breakpoint deletion, continuing execution, and arbitrary command execution. These gaps may limit agent autonomy for complex reverse engineering workflows.

Maintenance

ActivityStale
ResponsivenessSyncing