styx-mcp
Styx MCP
冥河。二进制是彼岸,逆向是渡河。
MCP stdio server exposing 7 reverse-engineering tools for LLM agents (hermes-agent, Claude Desktop, etc.).
Tools
Tool | Description | Dependency |
| Hex dump + magic detection + Shannon entropy | (stdlib) |
| Capstone linear disassembly + function boundary detection |
|
| Multi-encoding (ASCII/UTF-16LE/UTF-8) string extraction + classification | (stdlib) |
| Cross-reference analysis: call-graph overview + per-address callers/callees/string refs |
|
| Ghidra headless decompiler — C pseudocode | Ghidra binary |
| Symbolic execution: CFG extraction / explore / avoid |
|
| OLLVM control-flow flattening recovery via PyGhidra |
|
Install
# Minimal — hexdump, disasm, strings, xref
pip install styx-mcp
# With angr
pip install styx-mcp[angr]
# With PyGhidra (deobfuscate)
pip install styx-mcp[pyghidra]
# Everything
pip install styx-mcp[all]Ghidra tool requires Ghidra headless: pacman -S ghidra (Arch) or download from ghidra-sre.org.
Usage
hermes-agent
# config.yaml
mcp_servers:
styx:
command: ["python", "-m", "styx.mcp_server"]Claude Desktop
{
"mcpServers": {
"styx": {
"command": "python",
"args": ["-m", "styx.mcp_server"]
}
}
}Standalone
python -m styx.mcp_serverPython API
from styx.tools.hexdump import hexdump
from styx.pipeline import run_pipeline
result = hexdump("/bin/ls")
print(result["output"])
# Batch pipeline
result = run_pipeline("/bin/ls", ["hexdump", "disasm", "strings", "xref"])Protocol
JSON-RPC 2.0 over stdin/stdout (MCP stdio transport). Each tool returns:
{
"success": true,
"error": null,
"output": "...",
"discovered_nodes": [],
"discovered_edges": [],
"hypothesis_updates": []
}License
MIT