Ghidra¶
Ghidra is the decompiler-backed static provider, served by Ghidra MCP. The
compose stack builds the ghidra-mcp service from external/ghidra-mcp, which
make setup (or make external) reconstructs.
Connect it¶
The Choose a static analyser setup guide walks the same settings and tests
the connection. The shipped transport is stdio with no command, so switching
Ghidra on without setting transport to http is refused at job submit with a
sentence that says so.
Ghidra does not degrade
A static run with no decompiler would be a confident report grounded in
nothing, so an agent that needs Ghidra fails the run when it starts.
POST /api/v1/jobs therefore asks first: every agent of the chosen team
that opens Ghidra is checked, and a Ghidra that is not ready is a 422
naming the agent and the address. See A team that needs Ghidra waits for
it.
The samples path¶
The worker copies each sample under the samples directory, and the
ghidra-mcp container mounts that directory at /data/samples.
GHIDRA_CONTAINER_SAMPLES_PATH is the path inside the Ghidra container —
/data/samples with the shipped compose file — and never the host directory.
Set to a host path, Ghidra answers every load with File not found. The worker
states the value it uses in one line at start:
Running it lighter¶
The ghidra-mcp service reads three variables from docker/.env:
| Variable | Default | Lighter |
|---|---|---|
GHIDRA_JAVA_OPTS |
-Xmx4g -XX:+UseG1GC |
-Xmx2g -XX:+UseG1GC |
GHIDRA_MEM_LIMIT |
6g |
4g |
GHIDRA_RESTART |
unless-stopped |
no, to start it only for the runs that need it |
Keep the memory limit about 2g above the heap: Ghidra's database is memory-mapped and its direct buffers live outside the heap. See Running Ghidra lighter.
What an agent on Ghidra gets¶
Before an agent on Ghidra over http starts its loop, its sample is loaded once,
and a sink-reachability pre-pass gives the agent its priority functions on the
first turn. The sample is mirrored for Ghidra even when Ghidra is not the
deployment's global provider, so a reverser given static_provider: "ghidra"
works under any global setting. The deep_static team's reversing stage and
the importable all-tools team's reverser are the teams that use it most. See
Which agents open a static provider.