Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/vibrev/ida-headless-mcp/idapythonnpx skills add VibRev/ida-headless-mcp --skill idapythongit clone --depth 1 https://github.com/VibRev/ida-headless-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vibrev/ida-headless-mcp/idapython)<a href="https://agentmods.dev/skills/vibrev/ida-headless-mcp/idapython"><img src="https://agentmods.dev/badge/skills/vibrev/ida-headless-mcp/idapython.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00077 | $0.01547 |
| Opus 5 | $0.00039 | $0.00773 |
| Sonnet 5 | $0.00015 | $0.00309 |
| Haiku 4.5 | $0.00008 | $0.00155 |
Grade A, and why
idapython scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to idapython — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 155 lines — stays where its author put it; the contents beside it link to each section on GitHub.
IDAPython
Use modern ida_* modules. Avoid legacy idc module.
Module Router
| Task | Module | Key Items |
|---|---|---|
| Bytes/memory | ida_bytes |
get_bytes, patch_bytes, get_flags, create_* |
| Functions | ida_funcs |
func_t, get_func, add_func, get_func_name |
| Names | ida_name |
set_name, get_name, demangle_name |
| Types | ida_typeinf |
tinfo_t, apply_tinfo, parse_decl |
| Decompiler | ida_hexrays |
decompile, cfunc_t, lvar_t, ctree visitor |
| Segments | ida_segment |
segment_t, getseg, add_segm |
| Xrefs | ida_xref |
xrefblk_t, add_cref, add_dref |
| Instructions | ida_ua |
insn_t, op_t, decode_insn |
| Stack frames | ida_frame |
get_frame, define_stkvar |
| Iteration | idautils |
Functions(), Heads(), XrefsTo(), Strings() |
| UI/dialogs | ida_kernwin |
msg, ask_*, jumpto, Choose |
| Database info | ida_ida |
inf_get_*, inf_is_64bit() |
| Analysis | ida_auto |
auto_wait, plan_and_wait |
| Flow graphs | ida_gdl |
FlowChart, BasicBlock |
| Register tracking | ida_regfinder |
find_reg_value, reg_value_info_t |
Core Patterns
Iterate functions
for ea in idautils.Functions():
name = ida_funcs.get_func_name(ea)
func = ida_funcs.get_func(ea)
Iterate instructions in function
for head in idautils.FuncItems(func_ea):
insn = ida_ua.insn_t()
if ida_ua.decode_insn(insn, head):
print(f"{head:#x}: {insn.itype}")
Cross-references
for xref in idautils.XrefsTo(ea):
print(f"{xref.frm:#x} -> {xref.to:#x} type={xref.type}")
Read/write bytes
data = ida_bytes.get_bytes(ea, size)
ida_bytes.patch_bytes(ea, b"\x90\x90")
Names
name = ida_name.get_name(ea)
ida_name.set_name(ea, "new_name", ida_name.SN_NOCHECK)
Decompile function
cfunc = ida_hexrays.decompile(ea)
if cfunc:
print(cfunc) # pseudocode
for lvar in cfunc.lvars:
print(f"{lvar.name}: {lvar.type()}")
What ships with it
60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- docs/ida_auto.md 1.7 KB
- docs/ida_auto.rst 10 KB
- docs/ida_bitrange.md 652 B
- docs/ida_bitrange.rst 2.0 KB
- docs/ida_bytes.md 4.0 KB
- docs/ida_bytes.rst 93 KB
- docs/ida_dbg.md 3.8 KB
- docs/ida_dbg.rst 75 KB
- docs/ida_dirtree.md 1.9 KB
- docs/ida_dirtree.rst 16 KB
- docs/ida_diskio.md 2.2 KB
- docs/ida_diskio.rst 7.0 KB
- docs/ida_entry.md 1.0 KB
- docs/ida_entry.rst 3.8 KB
- docs/ida_expr.md 3.5 KB
- docs/ida_expr.rst 19 KB
- docs/ida_fixup.md 2.8 KB
- docs/ida_fixup.rst 9.5 KB
- docs/ida_fpro.md 1.6 KB
- docs/ida_fpro.rst 3.5 KB
- docs/ida_frame.md 4.8 KB
- docs/ida_frame.rst 21 KB
- docs/ida_funcs.md 7.5 KB
- docs/ida_funcs.rst 33 KB
- docs/ida_gdl.md 1.5 KB
- docs/ida_gdl.rst 12 KB
- docs/ida_graph.md 2.0 KB
- docs/ida_graph.rst 41 KB
- docs/ida_hexrays.md 5.5 KB
- docs/ida_hexrays.rst 371 KB
- docs/ida_ida.md 2.6 KB
- docs/ida_ida.rst 68 KB
- docs/ida_idaapi.md 1.3 KB
- docs/ida_idaapi.rst 14 KB
- docs/ida_idc.md 381 B
- docs/ida_idc.rst 439 B
- docs/ida_idd.md 1.5 KB
- docs/ida_idd.rst 65 KB
- docs/ida_idp.md 1.4 KB
- docs/ida_idp.rst 133 KB
- docs/ida_ieee.md 1.0 KB
- docs/ida_ieee.rst 5.1 KB
- docs/ida_kernwin.md 2.0 KB
- docs/ida_kernwin.rst 228 KB
- docs/ida_libfuncs.md 966 B
- docs/ida_libfuncs.rst 3.0 KB
- docs/ida_lines.md 1.1 KB
- docs/ida_lines.rst 16 KB
- docs/ida_loader.md 3.5 KB
- docs/ida_loader.rst 21 KB
- docs/ida_merge.md 1.3 KB
- docs/ida_merge.rst 25 KB
- docs/ida_mergemod.md 740 B
- docs/ida_mergemod.rst 3.8 KB
- docs/ida_moves.md 2.7 KB
- docs/ida_moves.rst 7.4 KB
- docs/ida_nalt.md 9.3 KB
- docs/ida_nalt.rst 52 KB
- docs/ida_name.md 7.0 KB
- docs/ida_name.rst 28 KB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 155 lines · 77 tokens per session scan A 421e209611d0
idapython is a skill published in the GitHub repository VibRev/ida-headless-mcp (15 stars, last pushed 7d ago), licensed Apache-2.0. It adds 77 tokens to every session and 1,547 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to idapython, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
analyzing-golang-malware-with-ghidra
Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo and pclntab structures, recovering stripped/obfuscated function names (e.g. via GoResolver), and extracting embedded module/dependency strings and types from Go binaries. Use when analyzing a Go-language malware sample, deobfuscating a…
Reverse Engineering & Binary Analysis
Binary analysis, assembly interpretation, disassembly, decompilation, firmware RE, and protocol reverse engineering.
IDA-Skill
IDA Pro 逆向分析。通过 IDAPython 脚本获取反汇编、反编译、字符串、导入表、交叉引用等信息。.
analyzing-golang-malware-with-ghidra
Use when reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries. Use when reverseing engineer go-compiled malware using ghidra with specialized scripts for.
performing-fuzzing-with-aflplusplus
Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with afl-cmin and afl-tmin, runs parallel fuzzing campaigns with…
analyzing-golang-malware-with-ghidra
Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.