Vulnerable dependenciesExternal endpoints declared · expectedSuspicious network references · expectedEgress to a private/loopback host · expected
scanned 1mo ago·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓
GhidraMCP
ghidraMCP is a Model Context Protocol server that lets LLMs autonomously reverse-engineer binaries by exposing core Ghidra functionality as MCP tools.
Paired with a Ghidra plugin, it can decompile and analyze binaries, list methods, classes, imports and exports, and automatically rename methods and data based on the agent's analysis. This brings AI-assisted reverse engineering and malware analysis into any MCP client.
It is aimed at security researchers, malware analysts, and reverse engineers who want to accelerate binary analysis with an AI assistant.
! Security: Review · 8888/100 · grade Bscanned 1mo ago
✓ no compromise signals7 risk-surface · 3/20 OWASP controls flagged
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
What this capability can do · high confidence (static)
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
OWASP Top 10 for LLM Applications
⚠LLM03Supply Chainhigh
Vulnerable/compromised dependencies, models or archives in the artifact.