---
title: "ghidra-agent-plugin"
description: "Inspect and improve an existing Ghidra Program through a small local MCP interface."
canonical: https://agentpluginsdirectory.com/plugins/ghidra-agent-plugin
last-updated: 2026-10-02
---

# ghidra-agent-plugin
Inspect and improve an existing Ghidra Program through a small local MCP interface.
- Slug: ghidra-agent-plugin
- Publisher: lumirth
- Repository: https://github.com/lumirth/ghidra-agent-plugin
- Manifest: plugin.json
- Version: 1.0.5
- License: MIT
- Category (editorial): security
- Skills: 1 (ghidra-re)
- MCP servers: 1 (ghidra)
- Stars: 0
- Repository created: 2026-08-16
- Repository last pushed: 2026-08-16
- Publisher type: User
- Listing: https://agentpluginsdirectory.com/plugins/ghidra-agent-plugin
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What ghidra-agent-plugin does, in the publisher's words

A small, GUI-independent MCP interface for an existing Ghidra Program. It works as a native Codex plugin and as a portable Agent Plugin for clients including Cursor.

The private stdio process keeps the PyGhidra JVM warm. Each tool call opens the selected Program for that operation and releases it before returning. There is no network listener, Ghidra extension, daemon, index, cache, mutation journal, unsaved edit session, or custom lock protocol.

- Ghidra installed locally; 12.1.2 is the currently validated version.
- A 64-bit JDK 21, as required by Ghidra 12.1.
- uv available on PATH or through UV_PATH.
- Python 3.9 or newer to run the small launcher. The Python 3.10+ analysis runtime is managed by uv.

The launcher discovers common Ghidra installations. Set GHIDRA_INSTALL_DIR when discovery is not sufficient. Call select_program with an explicit absolute.gpr path; the server never chooses a project from ambient configuration.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/lumirth/ghidra-agent-plugin/HEAD/README.md

## Skills

- ghidra-re: Inspect or improve an existing Ghidra Program through structured decompilation, listing, p-code, search, raw references, native analysis, and atomic saved edits. Use for binary and firmware reverse engineering when the answer or durable improvement belongs in Ghidra's Program database.

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

## MCP servers

- ghidra: transport: stdio; command: python3 -c import pathlib,runpy; roots=('${CURSOR_PLUGIN_ROOT}','${PLUGIN_ROOT}'); script=next(pathlib.Path(root)/'scripts/ghidra_agent.py' for root in roots if (pathlib.Path(root)/'scripts/ghidra_age

Read from the plugin's own mcp.json. Environment variable names only, never values.
