MalBuddy
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MalBuddydecompile the main function of this malware sample"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Dummy Agent Malware
Reverse-engineering assistant built with Google ADK and a vendored Ghidra MCP stack
(Docker headless on :8089 → SSE bridge on :8081 → ADK agent).
Prerequisites
Docker (for the headless Ghidra MCP server)
Python 3.10+
LLM endpoint — an OpenAI-compatible
/v1/chat/completionsserver (e.g. LiteLLM proxy) athttp://localhost:4000/v1
Related MCP server: GhidraMCP
Setup
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txtEnsure ghidra-mcp/docker/.env has a non-empty GHIDRA_MCP_AUTH_TOKEN
(a shell export alone is not enough for Docker Compose).
./scripts/start_ghidra_docker.sh creates/fills .env from .env.example,
reuses a shell GHIDRA_MCP_AUTH_TOKEN if set, or generates one with
openssl rand -hex 32.
Start Ghidra Docker
Headless Ghidra MCP HTTP API on :8089:
./scripts/start_ghidra_docker.shStart MCP bridge
SSE bridge on :8081 (leave this running in its own terminal):
./scripts/start_ghidra_bridge.shThe bridge loads GHIDRA_MCP_AUTH_TOKEN from ghidra-mcp/docker/.env and
talks to http://127.0.0.1:8089.
Verify stack
With Docker and the bridge running:
pytest tests/test_ghidra_stack.py -vThese are integration smoke tests (@pytest.mark.integration). They skip cleanly
if services are down; they fail if only half the stack is up.
Start agent
From the parent directory of this folder:
adk webOpen the ADK web UI and select Dummy_Agent_Malware.
agent.py expects the bridge at http://127.0.0.1:8081/sse (GHIDRA_MCP_URL).
Config knobs
Setting | Where |
LLM base URL / API key / model |
|
Bridge SSE URL for ADK |
|
Ghidra HTTP auth token |
|
Troubleshooting
Docker not healthy / connection refused on :8089 — wait for the container healthcheck (
docker compose -f ghidra-mcp/docker/docker-compose.yml ps), check logs withdocker logs ghidra-mcp, and confirm the token in.envmatches what compose started with.Missing / empty auth token — put
GHIDRA_MCP_AUTH_TOKEN=...inghidra-mcp/docker/.env(not only in your shell). Re-run./scripts/start_ghidra_docker.sh(it can copy a shell token into.envor generate one), then recreate the container.Bridge connection refused on :8081 — start
./scripts/start_ghidra_bridge.shand ensure Docker is already up; the bridge needs:8089plus the same token.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceAn MCP server that allows LLMs to autonomously reverse engineer applications by exposing Ghidra functionality, enabling decompilation, analysis, and automatic renaming of methods and data.Last updated9,633Apache 2.0
- Alicense-qualityDmaintenanceAn MCP server that allows LLMs to autonomously reverse engineer applications by exposing Ghidra's functionality, including decompiling binaries, analyzing code, and renaming methods and data.Last updatedApache 2.0
- Alicense-qualityDmaintenanceMCP server that integrates Ghidra for binary analysis, enabling decompilation, disassembly, and advanced reverse engineering tasks through Claude Code.Last updated13MIT
- Alicense-qualityBmaintenanceA multi-backend MCP server that exposes binary analysis capabilities from IDA Pro and Ghidra, allowing LLMs to directly drive reverse-engineering tools via natural language.Last updated128Apache 2.0
Related MCP Connectors
An MCP server that gives your AI access to the source code and docs of all public github repos
A MCP server built for developers enabling Git based project management with project and personal…
An MCP server for deep research or task groups
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/amanbharti008/MalBuddy'
If you have feedback or need assistance with the MCP directory API, please join our Discord server