MalBuddy
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MalBuddydecompile the main function of this malware sample"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Dummy Agent Malware
Reverse-engineering assistant built with Google ADK and a vendored Ghidra MCP stack
(Docker headless on :8089 → SSE bridge on :8081 → ADK agent).
Prerequisites
Docker (for the headless Ghidra MCP server)
Python 3.10+
LLM endpoint — an OpenAI-compatible
/v1/chat/completionsserver (e.g. LiteLLM proxy) athttp://localhost:4000/v1
Related MCP server: GhidraMCP
Setup
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txtEnsure ghidra-mcp/docker/.env has a non-empty GHIDRA_MCP_AUTH_TOKEN
(a shell export alone is not enough for Docker Compose).
./scripts/start_ghidra_docker.sh creates/fills .env from .env.example,
reuses a shell GHIDRA_MCP_AUTH_TOKEN if set, or generates one with
openssl rand -hex 32.
Start Ghidra Docker
Headless Ghidra MCP HTTP API on :8089:
./scripts/start_ghidra_docker.shStart MCP bridge
SSE bridge on :8081 (leave this running in its own terminal):
./scripts/start_ghidra_bridge.shThe bridge loads GHIDRA_MCP_AUTH_TOKEN from ghidra-mcp/docker/.env and
talks to http://127.0.0.1:8089.
Verify stack
With Docker and the bridge running:
pytest tests/test_ghidra_stack.py -vThese are integration smoke tests (@pytest.mark.integration). They skip cleanly
if services are down; they fail if only half the stack is up.
Start agent
From the parent directory of this folder:
adk webOpen the ADK web UI and select Dummy_Agent_Malware.
agent.py expects the bridge at http://127.0.0.1:8081/sse (GHIDRA_MCP_URL).
Config knobs
Setting | Where |
LLM base URL / API key / model |
|
Bridge SSE URL for ADK |
|
Ghidra HTTP auth token |
|
Troubleshooting
Docker not healthy / connection refused on :8089 — wait for the container healthcheck (
docker compose -f ghidra-mcp/docker/docker-compose.yml ps), check logs withdocker logs ghidra-mcp, and confirm the token in.envmatches what compose started with.Missing / empty auth token — put
GHIDRA_MCP_AUTH_TOKEN=...inghidra-mcp/docker/.env(not only in your shell). Re-run./scripts/start_ghidra_docker.sh(it can copy a shell token into.envor generate one), then recreate the container.Bridge connection refused on :8081 — start
./scripts/start_ghidra_bridge.shand ensure Docker is already up; the bridge needs:8089plus the same token.
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP server for static security analysis of Android source code
MCP server for progressive tool usage at any scale (see https://klavis.ai)
Repository knowledge graph MCP server for codebase understanding and debugging.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceAn MCP server that allows LLMs to autonomously reverse engineer applications by exposing Ghidra functionality, enabling decompilation, analysis, and automatic renaming of methods and data.9,968Apache 2.0
- AlicenseNot gradedqualityDmaintenanceAn MCP server that allows LLMs to autonomously reverse engineer applications by exposing Ghidra's functionality, including decompiling binaries, analyzing code, and renaming methods and data.Apache 2.0
- AlicenseNot gradedqualityDmaintenanceMCP server that integrates Ghidra for binary analysis, enabling decompilation, disassembly, and advanced reverse engineering tasks through Claude Code.15MIT
- AlicenseNot gradedqualityBmaintenanceA multi-backend MCP server that exposes binary analysis capabilities from IDA Pro and Ghidra, allowing LLMs to directly drive reverse-engineering tools via natural language.152Apache 2.0