frida-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| FRIDA_MCP_PROJECT | No | Path to the .fmcp project directory where state is stored. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_processesA | List processes visible to the local Frida device. |
| spawnA | Spawn a program suspended (gated) so hooks can be installed first. |
| attachB | Attach to a running process by name or numeric pid (as string). |
| resumeC | Resume a gated/spawned process so it starts running. |
| detachC | Detach Frida from a session (process keeps running). |
| killC | Kill the target process of a session. |
| list_modulesC | List loaded modules in the target. |
| eval_jsC | Evaluate JS in the resident agent's persistent context. |
| add_hookC | Hook a function (module!export or hex address); calls stream to disk. |
| trace_apiB | frida-trace style: hook all exports matching module!glob (e.g. kernel32!CreateFile*). |
| read_memoryC | Read |
| write_memoryC | Write hex-encoded bytes at |
| scan_memoryC | AOB/pattern scan over ranges with the given protection. |
| disassembleB | Disassemble |
| list_sessionsA | List all sessions (alive and dead) recorded in the project. |
| resume_sessionC | Re-attach a prior session and reinstall its hooks if the target is alive. |
| read_eventsC | Read captured events (hooks/repl/errors) from the trace log. |
| add_noteC | Attach a freeform note to a session. |
| list_notesC | List notes for a session. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 19 tools
Each tool targets a distinct Frida operation: lifecycle (attach, detach, spawn, resume, kill), memory (read, write, scan, disassemble), hooking (add_hook, trace_api, eval_js), listing (modules, processes, sessions, notes), and utilities (resume_session, read_events). Even similar tools like add_hook and trace_api are differentiated by specificity: add_hook for exact addresses or exports, trace_api for glob patterns. No two tools share an overlapping purpose.
Tools use snake_case consistently, but verb patterns vary: some are bare verbs (attach, detach, kill, resume, spawn), while others are verb_noun compounds (add_hook, read_memory, list_modules). This mix of single-word and compound names creates mild inconsistency, though each name is readable and descriptive. A more uniform verb_noun pattern would improve predictability.
19 tools cover a broad Frida feature set (process control, memory, hooks, scripting, event logging, and notes) without feeling overwhelming. While slightly above the typical 3–15 range, each tool addresses a core capability, and no tool seems redundant. The count is justified by the domain's complexity.
The tool surface covers essential operations but has notable gaps: no way to list installed hooks, remove hooks, or enumerate memory regions for scanning (though scan_memory accepts ranges). Unhooking and hook introspection are missing, and while eval_js provides scripting, a dedicated 'list scripts' tool is absent. These omissions may force agents to use workarounds.