AgentStack
MCP verified MIT Self-run

Re Frida

mcp-heretek-re-re-frida · by Heretek-RE

MCP server wrapping the Frida dynamic-instrumentation toolkit for Android, iOS, macOS, Linux, and Windows targets. Spawn

No reviews yet
0 installs
1 views
0.0% view→install

Install

$ agentstack add mcp-heretek-re-re-frida

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Re Frida? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

re-frida

MCP server wrapping the Frida dynamic-instrumentation toolkit. Frida injects a JavaScript engine (V8) into a target process and lets the analyst hook arbitrary functions, walk the type graph, and call into the target at runtime.

The MCP layer adds:

  • a stable session identifier — multiple scripts and hooks can be

installed under one session, sharing state.

  • a strict allowlist of binary-operation shapes — Frida exposes

the full V8 JS API to scripts but the MCP wrappers only call the canonical, well-understood primitives (attach, spawn, enumerate, hook, RPC).

  • soft-skip behaviour — when the `frida` Python module or

the native `libfrida are missing, every tool returns WARN` with an install hint and the plugin keeps working.

Tools

| Tool | What it does | |---|---| | check_frida | Health check — return frida version, native lib presence, USB device list | | start_session | Spawn a new process under Frida (target: Android / iOS / native PID / remote endpoint) | | attach_pid | Attach to a running process by host PID | | script_load | Compile + load a Frida script (JavaScript) into a session | | script_call | Call a method on a loaded script's exports (RPC) | | enumerate_modules | List modules loaded into the session's process | | enumerate_exports | List exports of a single module | | hook_method | Install an Interceptor hook on a named method | | rpc_export | Register a Python-side callable as an RPC export the JS side can call | | end_session | Tear down a session, unload scripts, detach |

Install

Frida is a heavy install (the Python module pulls in `frida + frida-tools; the underlying libfrida` is a native shared library shipped via PyPI wheels). To install standalone:

pip install -e ./servers/re-frida

On the target device (the phone or VM Frida is talking to), the matching `frida-server` binary must be running. See .

Run

re-frida                            # stdio transport (default for MCP)
python -m re_frida                  # equivalent

Deferred to a future run

The original Explore findings called for a Frida server; this plugin-internal scaffolding lands it so the deep-dive agents can pick it up. The Windows targets in the Live Fire stress test still use re-winedbg as the primary dynamic tool; the Android target future run is where re-frida becomes the workhorse.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.