Skip to main content
Glama
jackmis0724

styx-mcp

by jackmis0724

Styx MCP

冥河。二进制是彼岸,逆向是渡河。

MCP stdio server exposing 7 reverse-engineering tools for LLM agents (hermes-agent, Claude Desktop, etc.).

Tools

Tool

Description

Dependency

hexdump

Hex dump + magic detection + Shannon entropy

(stdlib)

disasm

Capstone linear disassembly + function boundary detection

capstone

strings

Multi-encoding (ASCII/UTF-16LE/UTF-8) string extraction + classification

(stdlib)

xref

Cross-reference analysis: call-graph overview + per-address callers/callees/string refs

capstone

ghidra

Ghidra headless decompiler — C pseudocode

Ghidra binary

angr

Symbolic execution: CFG extraction / explore / avoid

angr (optional)

deobfuscate

OLLVM control-flow flattening recovery via PyGhidra

pyghidra (optional)

Install

# Minimal — hexdump, disasm, strings, xref
pip install styx-mcp

# With angr
pip install styx-mcp[angr]

# With PyGhidra (deobfuscate)
pip install styx-mcp[pyghidra]

# Everything
pip install styx-mcp[all]

Ghidra tool requires Ghidra headless: pacman -S ghidra (Arch) or download from ghidra-sre.org.

Usage

hermes-agent

# config.yaml
mcp_servers:
  styx:
    command: ["python", "-m", "styx.mcp_server"]

Claude Desktop

{
  "mcpServers": {
    "styx": {
      "command": "python",
      "args": ["-m", "styx.mcp_server"]
    }
  }
}

Standalone

python -m styx.mcp_server

Python API

from styx.tools.hexdump import hexdump
from styx.pipeline import run_pipeline

result = hexdump("/bin/ls")
print(result["output"])

# Batch pipeline
result = run_pipeline("/bin/ls", ["hexdump", "disasm", "strings", "xref"])

Protocol

JSON-RPC 2.0 over stdin/stdout (MCP stdio transport). Each tool returns:

{
  "success": true,
  "error": null,
  "output": "...",
  "discovered_nodes": [],
  "discovered_edges": [],
  "hypothesis_updates": []
}

License

MIT