re-angr
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@re-angrbuild control flow graph for function 'main' in /bin/ls"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
re-angr
MCP server for angr (UC Santa Barbara, BSD) — symbolic execution + CFG + reaching-definitions. The "I have a heavy constraint problem and want a second opinion" tool.
Why
The other RE-AI MCP servers handle most RE tasks well. But there are two cases where angr's approach is materially different from re-triton's:
CFG construction. angr's CFG is built statically (no execution, no emulation) and is one of the most accurate in the open-source world.
re-rizin.analyze_functionis faster but uses different heuristics; cross-validating with angr catches edge cases.Reaching definitions. angr's dataflow analysis is what makes
re-mba-deobfuscatereliable. An MBA identity likex + y == (x & y) + (x | y)looks like real arithmetic, but the reaching-defs graph reveals that(x & y)and(x | y)were defined from the same source — the identity is a no-op substitution.
re-angr exposes both, and re-triton for the same constraint problem. The two together give the analyst a much stronger signal than either alone.
Related MCP server: angr-mcp
Architecture
The Python MCP server is a thin wrapper around an angr-cli Python helper installed by install.sh:
Claude Code (MCP stdio)
│
▼
re-angr server (Python, this directory)
│ subprocess.run(...)
▼
angr-cli (small Python script, wraps the angr API)
│
└─ angr>=9.2 (pip-installed, the actual binary analysis platform)The subprocess boundary is intentional: angr keeps long-lived AngrProject objects, which don't survive across JSON-RPC calls cleanly. The helper spawns a fresh Python process per call, which matches the per-tool-call model the MCP server uses.
Tools
Tool | What it does |
| Health check — return angr + cle versions |
| Build a control-flow graph of a binary (or one function) |
| Run angr symbolic execution starting at an address |
| Compute the def-use graph for a function |
Install
./install.sh installs angr>=9.2 from PyPI.
To install standalone:
pip install 're-angr[core]'Requirements
Python 3.11+
angr>=9.2 (BSD, on PyPI)
No system dependencies
Degraded mode
If angr-cli is not installed, every tool returns {"status": "WARN", "error": "angr-cli not installed; run install.sh", ...}. The Python MCP server itself always loads so Claude Code can surface the install hint.
Pairing with re-triton
re-triton is the fast first-call symbolic executor (Triton 1.0 with Quarkslab's bindings). re-angr is the cross-validation pass:
Use
re-triton.solve_constraintfor "what input reaches this branch?" (fast, in-process).Use
re-angr.symbolic_execfor "does another symbolic executor agree?" (slower, but independent).Use
re-angr.reaching_definitionsfor "where was this variable defined?" (Triton doesn't compute this — it's a static dataflow analysis).
For MBA-obfuscated arithmetic: re-triton.solve_constraint solves the symbolic equation; re-angr.reaching_definitions shows the variable is a no-op substitution. Both together is a strong "this is a known identity" signal.
For CFG construction: re-rizin.analyze_function is the fast first call; re-angr.build_cfg is the cross-validation pass. Discrepancies (e.g. angr sees an indirect call that rizin doesn't) are worth investigating.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseCqualityAmaintenanceMCP Server for automated reverse engineering with IDA Pro.Last updated4310,958MIT
- Alicense-qualityDmaintenanceExposes angr binary-analysis capabilities (symbolic execution, taint analysis, CFG recovery) as MCP tools for vulnerability exploration and exploit development.Last updated9MIT
- Alicense-qualityBmaintenanceA multi-backend MCP server that exposes binary analysis capabilities from IDA Pro and Ghidra, allowing LLMs to directly drive reverse-engineering tools via natural language.Last updated136Apache 2.0
- Alicense-qualityCmaintenanceMCP server exposing the rizin CLI for static binary analysis of executables.Last updatedMIT
Related MCP Connectors
MCP server for ScanMalware.com URL scanning, malware detection, and analysis.
MCP server for Klever blockchain smart contract development.
Read-only MCP server for the WebAssembly spec: instructions, types, sections, search, proposals.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Heretek-RE/re-angr'
If you have feedback or need assistance with the MCP directory API, please join our Discord server