You don't even need an MCP, I just let the agent write scripts for headless ghidra. The MCPs are fragile and there isn't a whole lot of knowledge about how to use them in the training datasets, whereas there are plenty of ghidra scripts (and proper docs for the APIs).
> there isn't a whole lot of knowledge about how to use them in the training datasets
if you include a SKILL.md for the MCP (or just dump it into the prompt) it's not a problem.I don't use Ghidra but IDA Pro MCP works extremely well for me for all manner of tasks. for example, some software likes to call home for license checking (and I wish to run it with networking denied to it). it no longer does.
I agree! Don't give it away!
Seriously, though, the popular Ghidra MCP is really badly architected; it's way better to rearchitect it or just script Ghidra directly. With that said, Opus 5.5 seems to have been trained on CoT from the popular Ghidra MCP. This makes it work better, but also makes it even more inefficient if you modify the MCP without changing its name and shape significantly (it will try to make tool calls using the "mainline" format, then have to retry them when they fail).
Even with Opus 5.5, IMO it's better to just ditch the MCP and let the LLMs eat with bintools and headless Ghidra; with both GLM and Opus this produces significantly more efficient results than the popular MCP. On the other hand the IDA Pro MCP is much better architected and seems to be pretty good.