MalBuddy
README.md
# Dummy Agent Malware
Reverse-engineering assistant built with Google ADK and a vendored Ghidra MCP stack
(Docker headless on `:8089` → SSE bridge on `:8081` → ADK agent).
## Prerequisites
- **Docker** (for the headless Ghidra MCP server)
- **Python 3.10+**
- **LLM endpoint** — an OpenAI-compatible `/v1/chat/completions` server (e.g. LiteLLM proxy) at `http://localhost:4000/v1`
## Setup
```bash
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
```
Ensure `ghidra-mcp/docker/.env` has a non-empty `GHIDRA_MCP_AUTH_TOKEN`
(a shell `export` alone is not enough for Docker Compose).
`./scripts/start_ghidra_docker.sh` creates/fills `.env` from `.env.example`,
reuses a shell `GHIDRA_MCP_AUTH_TOKEN` if set, or generates one with
`openssl rand -hex 32`.
## Start Ghidra Docker
Headless Ghidra MCP HTTP API on `:8089`:
```bash
./scripts/start_ghidra_docker.sh
```
## Start MCP bridge
SSE bridge on `:8081` (leave this running in its own terminal):
```bash
./scripts/start_ghidra_bridge.sh
```
The bridge loads `GHIDRA_MCP_AUTH_TOKEN` from `ghidra-mcp/docker/.env` and
talks to `http://127.0.0.1:8089`.
## Verify stack
With Docker and the bridge running:
```bash
pytest tests/test_ghidra_stack.py -v
```
These are integration smoke tests (`@pytest.mark.integration`). They skip cleanly
if services are down; they fail if only half the stack is up.
## Start agent
From the **parent** directory of this folder:
```bash
adk web
```
Open the ADK web UI and select `Dummy_Agent_Malware`.
`agent.py` expects the bridge at `http://127.0.0.1:8081/sse` (`GHIDRA_MCP_URL`).
## Config knobs
| Setting | Where |
|--------|--------|
| LLM base URL / API key / model | `agent.py` (`LLM_BASE_URL`, `LLM_API_KEY`, `LLM_MODEL_NAME`) |
| Bridge SSE URL for ADK | `agent.py` (`GHIDRA_MCP_URL`) |
| Ghidra HTTP auth token | `ghidra-mcp/docker/.env` (`GHIDRA_MCP_AUTH_TOKEN`) |
## Troubleshooting
- **Docker not healthy / connection refused on :8089** — wait for the container
healthcheck (`docker compose -f ghidra-mcp/docker/docker-compose.yml ps`),
check logs with `docker logs ghidra-mcp`, and confirm the token in `.env`
matches what compose started with.
- **Missing / empty auth token** — put `GHIDRA_MCP_AUTH_TOKEN=...` in
`ghidra-mcp/docker/.env` (not only in your shell). Re-run
`./scripts/start_ghidra_docker.sh` (it can copy a shell token into `.env`
or generate one), then recreate the container.
- **Bridge connection refused on :8081** — start `./scripts/start_ghidra_bridge.sh`
and ensure Docker is already up; the bridge needs `:8089` plus the same token.
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessSyncing