Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
IDA_MCP_BROKER_URLNoThe Broker address the current MCP process should connect to (equivalent to the --broker-url option).http://127.0.0.1:13337
IDA_MCP_CACHE_SCOPENominimal only builds strings / functions / imports (no cross references or globals, faster and more memory efficient). Narrowing the scope clears tables outside the range to avoid returning stale cross references.full
IDA_MCP_MAX_WORKERSNoEnvironment variable default for --max-workers: the maximum number of simultaneously opened database workers for idalib (0 means unlimited).4
IDA_MCP_IDLE_TTL_SECNoNumber of seconds after which an idle session is automatically closed to free memory (0 = disabled).0
IDA_MCP_DISABLE_CACHENoSet to 1 to completely disable the cache daemon thread (no database built, no extraction); the 7 cache tools will return -32001.0
IDA_MCP_CACHE_MAX_ROWSNoMaximum number of rows per table; if exceeded, that table's refresh for the current round is abandoned (keeping the old snapshot) and marked as partial.0
IDA_MCP_IDLE_SWEEP_SECNoScan period of the reclamation thread, minimum 1.30
IDA_MCP_CACHE_CHUNK_ROWSNoMaximum number of rows per chunk; peak memory is approximately the size of a single chunk.20000
IDA_MCP_CACHE_MAX_RSS_MBNoProcess RSS limit; if exceeded, the current refresh round is stopped (keeping the old snapshot) and degraded to 'degraded'.0
IDA_MCP_CACHE_FINGERPRINTNofull includes string text in the fingerprint (more accurate but slower to compute).shape
IDA_MCP_CACHE_INCREMENTALNoSet to 0 to disable table-level fingerprint incrementality and force a full rebuild.1
IDA_MCP_CACHE_TARGET_CHUNK_MSNoTarget duration per chunk, used to adaptively adjust chunk size (smaller means less UI blocking).150

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
prompts
{
  "listChanged": true
}
resources
{
  "subscribe": false,
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
instance_listA

列出所有已连接的 IDA/Hopper 实例。无需加载 IDB。返回 instance_id,name,binary_path,idb_path,base_addr。

instance_infoA

获取指定实例详情。instance_id 来自 instance_list。返回 binary_path,idb_path,base_addr,processor 等。

decompileB

反编译函数为伪代码(C 风格)。输入地址或符号名。返回 addr,code。失败返回 error。

disasmA

反汇编函数为汇编指令。输入地址或符号名。返回 addr,asm(行列表),cursor。支持 offset/分页。

func_profileC

Profile functions with summary metrics and optional sampled details.

analyze_batchC

Run comprehensive analysis over one or more target functions.

xrefs_toC

获取交叉引用(引用的目标地址)。

xref_queryC

Query xrefs with direction/type filters and pagination.

xrefs_to_fieldC

Get cross-references to structure fields

calleesB

Return unique callees per function, capped by limit.

find_bytesC

Search byte patterns (supports ??) with offset/limit pagination.

basic_blocksC

Return function CFG blocks with offset/max_blocks pagination.

findC

Search strings/immediates/refs for targets with offset/limit pagination.

insn_queryC

Query instructions with mnemonic/operand filters and scoped scans.

export_funcsB

导出函数数据。format: json(含 asm/code/xrefs)、c_header、prototypes。输入地址或符号名。

callgraphC

Build bounded callgraph from roots with depth/node/edge limits.

analyze_functionB

Compact single-function analysis: pseudocode, strings, constants, callers, callees, xrefs, blocks.

analyze_componentC

Analyze related functions as a group: per-function summaries, internal call graph, shared data.

trace_data_flowA

Follow cross-references from or to an address, automatically traversing multiple hops. Use 'forward' to see where data flows TO (xrefs-from), or 'backward' to see where data flows FROM (xrefs-to). At each node in the traversal, returns the function name, instruction, and whether it's code or data. Use this when you find an interesting string, constant, or global and want to understand every code path that touches it without manually chaining xrefs_to calls. Do not use for call graph traversal — use callgraph for that. max_depth controls how many hops to follow (default 5, max 20).

server_healthA

Health/ready probe for MCP server and current IDB state.

server_warmupA

Warm up IDA subsystems to reduce first-call latency and transient failures.

lookup_funcsA

按地址或名称查找函数。输入: 地址(0x401000/sub_401000)或符号名(main,start)。输出: addr,name,size。支持批量。

int_convertA

数值进制转换。输入任意格式数(0x/十进制),输出 decimal/hex/ascii/binary。禁止 LLM 手算进制,必须调用此工具。

list_funcsA

列出函数。支持 glob 过滤、分页。'0:50'=offset:count(列表索引,非地址)。

func_queryB

Query functions with richer filtering than list_funcs.

list_globalsA

列出全局变量。支持 glob 过滤、分页。'0:20'=offset:count(列表索引,非地址)。

entity_queryC

Query IDB entities with typed filters, projection, and pagination.

importsA

列出导入表。返回 addr, imported_name, module。用于查动态链接/API 调用。

imports_queryB

Query imports with richer filtering than imports(offset,count).

idb_saveC

Save active IDB to disk, optionally to a provided path.

find_regexA

在二进制字符串中按正则搜索。返回 addr,string。不区分大小写。用于找硬编码字符串。

search_textB

Search the rendered listing using IDA's native text search (fast C++ scan).

Discovers candidate EAs with ida_search.find_text(), then renders each hit once via ida_lines.generate_disassembly() to extract matching lines and classify them as disasm or comment. Returns one hit per EA.

list_instancesA

List all discovered IDA Pro instances with their binary name, port, and reachability status.

Use this to see which IDA databases are currently open and available for analysis. The 'active' field indicates which instance is currently handling your tool calls.

select_instanceA

Switch to a different IDA Pro instance. All subsequent tool calls will be routed to the selected instance. Use list_instances to see available instances.

To switch back to this instance, call select_instance with this instance's port, or call select_instance with port=0 to reset.

get_bytesA

从内存读取原始字节。输入格式: 对象{addr,size}、数组、或字符串'addr:size'(例'0x401000:16'、'0x401000:16, 0x402000:8')。返回 addr,data(hex)。

get_intB

从指定地址按类型读整数。支持有符号(i)无符号(u)、8/16/32/64位、大小端(le/be)。返回 addr,ty,value。

get_stringB

从地址读取 IDA 识别的字符串(C/宽字符)。返回 addr,value。若该址无字符串则 error。

get_global_valueA

按地址或符号名读取全局变量值。自动识别 hex 地址 vs 名称。需 IDA 已定义该全局类型。

patchC

Patch bytes at memory addresses with hex data

put_intC

Write integer values to memory addresses

set_commentsC

Set comments at addresses (both disassembly and decompiler views)

append_commentsC

Append comments at addresses, deduping exact text by default.

patch_asmC

Patch assembly instructions at addresses

renameC

批量重命名: 函数、全局变量、局部变量、栈变量。支持 dry_run 等选项。

define_funcB

Define functions; IDA infers bounds unless end is provided.

define_codeC

Convert bytes to code instruction(s) at address(es).

undefineC

Undefine item(s) at address(es), converting back to raw bytes.

make_signatureB

Create unique byte signatures for addresses. Generates the shortest unique signature starting at each address by walking instructions and wildcarding operands. Useful for finding stable patterns that survive recompilation.

make_signature_for_functionA

Create unique byte signatures for function entry points. Resolves each name/address to a function, then generates the shortest unique signature starting at the function start.

make_signature_for_rangeA

Create a byte signature for a specific address range (e.g. a selected region). Unlike make_signature, this does NOT guarantee uniqueness — it simply encodes the bytes in the range with optional operand wildcarding.

find_xref_signaturesA

Find signatures for code locations that reference an address. For each input address, finds all code cross-references TO it, generates a unique signature at each xref site, and returns the shortest ones. Ideal for creating signatures for data addresses, vtable entries, or string references that can't be signatured directly.

stack_frameC

Return stack variables for function address(es).

declare_stackC

Create stack variables from typed stack declarations.

delete_stackC

Delete stack variables by name or offset.

survey_binaryA

Get a compact overview of the binary in one call. Returns file metadata, segment layout, entry points, statistics, top 15 strings and functions ranked by xref count (functions include classification: thunk/wrapper/leaf/dispatcher/ complex), imports by category, and call graph summary. Use this as your FIRST tool call when starting analysis. Do not call list_funcs, imports, or find_regex separately for triage — this returns all of that. Use detail_level='minimal' for binaries with >10k functions.

declare_typeC

Declare C type definitions in local type library.

enum_upsertB

Create or extend local enums in an idempotent way.

read_structC

Read struct fields from memory at address; auto-detect type when possible.

search_structsC

Search local structs/unions by name pattern.

type_queryC

Query local types with structured filters/projection-friendly output.

type_inspectB

Inspect named types (size/kind/declaration/members).

set_typeC

Apply types (function/global/local/stack)

type_apply_batchC

Apply multiple type edits and return aggregate status.

infer_typesC

Infer and apply likely types at target addresses.

refresh_cacheA

请求指定 IDA 实例立即刷新其本地 SQLite 静态缓存 (xxx.idb.mcp.sqlite)。实际刷新仍然需要 IDA 进入 idle 状态才会执行,此工具仅唤醒插件端守护线程并立即返回。

cache_statusA

查询指定 IDA 实例的本地 SQLite 静态缓存状态 (status / last_updated / 各表计数)。当 status != 'ready' 时,find_regex / entity_query / list_funcs / list_globals / imports 等工具将返回错误并提示稍后重试。

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
idb_metadata_resourceGet IDB file metadata (path, arch, base address, size, hashes)
idb_segments_resourceGet all memory segments with permissions
idb_entrypoints_resourceGet entry points (main, TLS callbacks, etc.)
cursor_resourceGet current cursor position and function
selection_resourceGet current selection range (if any)
types_resourceGet all local types
structs_resourceGet all structures/unions

TDQS

C2.7/5.0

Scored across 66 tools

Disambiguation2/5

Several tools appear to duplicate each other: instance_list vs list_instances both list IDA instances, imports vs imports_query, list_funcs vs func_query, and xrefs_to vs xref_query cover overlapping ground. Analysis tools (analyze_function, analyze_component, analyze_batch, func_profile, survey_binary) also overlap heavily, making selection between them uncertain.

Naming Consistency2/5

The conventions are mixed: some tools are verb_noun (list_funcs, get_bytes, find_regex), others noun_verb (xrefs_to), others bare nouns (decompile, disasm, patch, rename, callees). The most glaring flaw is instance_list vs list_instances, the same concept with inverted word order.

Tool Count2/5

At 66 tools this is far above a comfortable surface, and a meaningful subset are redundant query variants (imports_query, func_query, xref_query, entity_query) or near-duplicate instance/signature helpers. The domain is broad but the count is inflated by overlapping tools rather than distinct capabilities.

Completeness4/5

The surface is remarkably thorough for binary reverse engineering: decompilation, disassembly, xrefs, callgraphs, read/write/patch of memory and code, stack frames, type declaration, signatures, comments, renaming, and cache management are all present. Only minor lifecycle gaps (e.g. segment-level operations, richer diffing) seem missing.

Maintenance

ActivityMaintained
ResponsivenessNo issues