MARE MCP Toolbox — Development skill for Claude Code
Agentic malware analysis environment with MCP-connected disassemblers, RE tooling, and structured workflows for Claude Code and Codex CLI.
How to install MARE MCP Toolbox
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open cervonwong/MARE-MCP-Toolbox and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What MARE MCP Toolbox does
Agentic malware analysis environment with MCP-connected disassemblers, RE tooling, and structured workflows for Claude Code and Codex CLI.
Alternatives in Development
- OpenAI Codex CLI — (Rust implementation) 67.8k ★
- Tempest — Agentic Engineering that actually scales 161 ★
- Damon Ade — ADE — an agentic development environment for macOS 95 ★
README
MARE-MCP-Toolbox
Agentic malware analysis on a Kali Linux Docker container with 50+ reverse engineering tools and three disassembler backends (IDA Pro, Binary Ninja, Ghidra), exposed both to in-container agents AND to external MCP clients.
The gateway ships **54 curated MCP tools** by default (61 with dynamic mode enabled, +1 with the env-gated unsafe r2 tool) on top of the active disassembler's native MCP surface, over Streamable HTTP with bearer auth.
Two ways to use this
| Mode | Who's running | When to use | Entrypoint |
|---|---|---|---|
| Local | Claude Code or Codex inside the container | Hands-on triage from a single workstation; the agent has full filesystem + tool access | ./run_docker.sh |
| Remote | Claude Code on the host, mastra.ai agents, or any MCP client outside the container | Multi-client / fleet workflows; CI; integration into your own agent framework | ./run_docker.sh --remote |
Both modes can run from the same image. Local agents talk to the disassembler MCP backends directly over stdio/SSE; remote clients talk to the gateway over Streamable HTTP with bearer auth. Dynamic-analysis tools (strace, ltrace, qemu-user, gdb sessions) are an MCP-only surface enabled via `./run_docker.sh --remote --dynamic`.
Prerequisites
- Docker + Docker Compose v2
- Optional:
binaryninja.zipand/oridapro.zipin the repo root for paid disassembler backends (auto-detected at build) - For remote mode: a host port reachable by your MCP client (default
8080) - For the mastra.ai starter: Node.js 20+
- For dynamic mode: host
kernel.yama.ptrace_scope <= 1; for foreign-arch samples, host-side binfmt registration viadocker run --rm --privileged multiarch/qemu-user-static --reset -p yes
Quick start — local mode
The default `./run_docker.sh` invocation builds the image (if needed) and drops you into an interactive Kali shell. Claude Code and Codex are pre-wired to the disassembler backend via `.
Related Skills
Mathias Agent Toolbox
Public Claude Code and Codex plugin marketplace for reusable agent workflows, engineering skills, and Rust too
Malware Sandbox MCP
Detonate files & URLs in cloud malware sandboxes (Hybrid Analysis, tria.ge, ANY.RUN) and enrich IOCs across Ma
Usage Insights
Cross-client (Claude Code + Codex CLI) usage insights with hybrid evidence + agentic analysis.
Codex Toolbox
Build one useful MCP server while learning how Codex tools, skills, hooks, subagents and permissions fit toget
Codex Agent SDK Go
Go SDK for the OpenAI Codex CLI app-server transport with JSON-RPC 2.0, typed events, approvals, MCP config, a
Claude Code Toolbox
Claude Code Toolbox — automated installers and environment configuration framework for Claude Code with one-li
Related Agents
Agentic Malware Analysis
Agentic malware analysis environment with MCP-connected disassemblers, RE tooling, and structured workflows fo
Codex Bridge
把指定工作外包給 gpt-5.5(codex)並忠實回傳其輸出。當需要 gpt-5.5 的批量實作或獨立第二審查視角時使用。這是 plugin 內第三種 codex 路徑:一次性 codex exec CLI 呼叫、輸出
Codex Cross Reviewer
Cross-review orchestrator using Codex CLI as 2nd reviewer. Runs structured finding exchange with consensus loo