Gdb Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Gdb Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol server that wraps gdb so an LLM can drive live debugging sessions. The server exposes tools for starting a session on a binary, attaching to an existing PID, running ad-hoc commands, batching commands, checking status, and shutting sessions down.
Requiresgdbon the host and themcppython package (v1+).
Install from PyPI (preferred):
pip install gdb-mcpYou can also install from source, inside a virtualenv (recommended) or directly:
# optional but recommended
python -m venv .venv
. .venv/bin/activate
pip install -e .
# or: pip install .You can start the server directly:
gdb-mcp
# or
python -m gdb_mcp.serverThe server uses stdio for transport (the default for most MCP clients). Point your MCP client configuration at the command above.
Run gdb-mcp --install to add the server to any detected MCP-aware clients without editing config files by hand. The installer currently knows how to update:
~/.codex/config.toml)Use --install-command /custom/path/to/gdb-mcp or --install-args ... if you need to override what gets written.
start_binary(binary_path, args=None, cwd=None, load_init=True, start_timeout=30.0, prompt=None, force_prompt=True) – launch gdbagainst a target binary (with optional args) and return a session id and the initial banner. Set load_init=False to skip user gdbinit (default is to load it so helpers like GEF/pwndbg remain enabled). Increase start_timeout if loading extensions takes longer to reach the first prompt. Use prompt to force a specific prompt string (defaults cover (gdb), (pwndbg), and gef>). force_prompt sets the prompt to the chosen value after startup to avoid timeouts from customized prompts (e.g., pwndbg); set force_prompt=False if you need to keep your custom prompt unchanged.
attach_to_pid(pid, cwd=None, load_init=True, start_timeout=30.0, prompt=None, force_prompt=True) – start gdb and attach to arunning process (same load_init/timeout/prompt behavior as above).
gdb_command(session_id, command, timeout_seconds=15.0) – execute a singlegdb command in the given session and return the output.
batch_commands(session_id, commands, timeout_seconds=15.0) – run a list ofcommands sequentially.
list_sessions() – get a snapshot of all active sessions.session_status(session_id) – check if the gdb process is still alive.stop_session(session_id) – shut down the gdb process and remove it.Each tool returns simple JSON so it is easy to route back into your LLM prompt.
enables pending breakpoints to keep interactions non-blocking.
timeout_seconds applies per command. If you expect a program to run for along time, pass a larger timeout or None.
(gdb) prompt. Ifyou spawn a program that never returns to the prompt (e.g., it blocks on input), the call will time out.
(gdb), (pwndbg),gef>), even with ANSI colors. You can still pass a custom prompt if you use something nonstandard. By default the server forces the prompt to a stable value (force_prompt=True) so gdbinit customizations (like pwndbg) don’t prevent the initial prompt from being detected.
Auto-playing preview:
Demo
Source video: docs/media/demo.mp4
our workflow. I leaned on AI to write the entire project—including this README.
was used as a starting point.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.