Skip to content

Ghidra

Ghidra is the decompiler-backed static provider, served by Ghidra MCP. The compose stack builds the ghidra-mcp service from external/ghidra-mcp, which make setup (or make external) reconstructs.

Connect it

core.static.provider          = ghidra
core.static.ghidra.enabled    = true
core.static.ghidra.transport  = http
core.static.ghidra.url        = http://ghidra-mcp:8089
core.static.ghidra.auth_token = <GHIDRA_MCP_AUTH_TOKEN from docker/.env>
core.static.provider          = ghidra
core.static.ghidra.enabled    = true
core.static.ghidra.transport  = http
core.static.ghidra.url        = http://localhost:8089
core.static.ghidra.auth_token = <GHIDRA_MCP_AUTH_TOKEN from docker/.env>

The Choose a static analyser setup guide walks the same settings and tests the connection. The shipped transport is stdio with no command, so switching Ghidra on without setting transport to http is refused at job submit with a sentence that says so.

Ghidra does not degrade

A static run with no decompiler would be a confident report grounded in nothing, so an agent that needs Ghidra fails the run when it starts. POST /api/v1/jobs therefore asks first: every agent of the chosen team that opens Ghidra is checked, and a Ghidra that is not ready is a 422 naming the agent and the address. See A team that needs Ghidra waits for it.

The samples path

The worker copies each sample under the samples directory, and the ghidra-mcp container mounts that directory at /data/samples. GHIDRA_CONTAINER_SAMPLES_PATH is the path inside the Ghidra container — /data/samples with the shipped compose file — and never the host directory. Set to a host path, Ghidra answers every load with File not found. The worker states the value it uses in one line at start:

Ghidra samples path: /data/samples (from GHIDRA_CONTAINER_SAMPLES_PATH). ...

See The Ghidra samples path.

Running it lighter

The ghidra-mcp service reads three variables from docker/.env:

Variable Default Lighter
GHIDRA_JAVA_OPTS -Xmx4g -XX:+UseG1GC -Xmx2g -XX:+UseG1GC
GHIDRA_MEM_LIMIT 6g 4g
GHIDRA_RESTART unless-stopped no, to start it only for the runs that need it

Keep the memory limit about 2g above the heap: Ghidra's database is memory-mapped and its direct buffers live outside the heap. See Running Ghidra lighter.

What an agent on Ghidra gets

Before an agent on Ghidra over http starts its loop, its sample is loaded once, and a sink-reachability pre-pass gives the agent its priority functions on the first turn. The sample is mirrored for Ghidra even when Ghidra is not the deployment's global provider, so a reverser given static_provider: "ghidra" works under any global setting. The deep_static team's reversing stage and the importable all-tools team's reverser are the teams that use it most. See Which agents open a static provider.