The Agentic RE Tool That Stops at the Boundary
The most important part of Hex-Rays’ new agentic reverse-engineering tooling is not that an AI can read a binary. It is that the tool is explicit about when the AI is allowed to do more than read one.
IDA Assist is an AI harness integrated into IDA. Hex-Rays says it can inspect functions, types, and cross-references, then help with tasks such as renaming symbols, repairing prototypes, emulating functions, patching bytes, and generating YARA rules. The documentation describes the add-on as new in the IDA 9.5 beta, with support for IDA 9.3, 9.4, and 9.5 on Home and Pro editions.
The radar post that surfaced it called out 150-plus typed tools and an approval-gated MCP connection. Hex-Rays’ own documentation is more precise: Assist has over a hundred database tools, while the separate first-party IDA MCP Server connects and multiplexes IDA across agents and databases. That distinction matters. A larger tool count is a product detail. The permission boundary is an architecture decision.
Reading is not changing
Assist’s permissions documentation splits capabilities into three states:
| Permission | Agent behavior | Operator meaning |
|---|---|---|
| On | The capability can be used freely | Automation is allowed |
| Off | The capability is removed and blocked | The boundary is closed |
| Ask when needed | The agent requests access mid-turn | A person decides at the boundary |
Out of the box, reading files is enabled. Capabilities that can make consequential changes are seeded to Ask when needed. Permission cards appear when the agent requests a shell command, Python execution, debugger access, or a file write.
That is a useful default for an analyst sitting in front of IDA. It is not automatically a useful default for a terminal agent or an unattended pipeline.
Hex-Rays documents a sharp gotcha: an external MCP client cannot use the interactive escalation path. If a capability is set to Ask, an external agent receives a refusal instead of a prompt. For automation, the effective choices are therefore On or Off.
This is the kind of detail that disappears in a product announcement and becomes a production incident later. An engineer can copy a working interactive setup into an MCP workflow, see a refusal, and conclude that the integration is broken. The integration is enforcing a different trust boundary.
The model is not the control plane
Assist can use a built-in agent or connect to models and agents the operator already uses, including Claude Code, ChatGPT, Grok, and OpenAI-compatible local or hosted endpoints. Hex-Rays says it supports more than ten model families and provides IDA-specific tools rather than asking a general chatbot to guess at a disassembly.
That model flexibility is useful, but it is not the security property. The same permission decision must hold whether the reasoning comes from a built-in model, a cloud endpoint, or a local model.
The control plane is the combination of:
- The tool surface exposed to the agent.
- The capability state for each tool.
- The evidence shown to the operator before a consequential action.
- The audit trail for the decision and the resulting change.
A better model can improve analysis. It does not decide whether a shell command should be allowed. That is a policy question implemented around the model.
MCP changes the operator’s job
Hex-Rays’ first-party IDA MCP Server is open source and runs locally. It can connect agents to the IDA database, manage several databases and sessions, and support multi-agent collaboration. The server is a building block, not a complete governance system.
The moment an IDA database is reachable from a terminal agent, the operator has to answer questions that do not appear in a normal chat interface:
- Which databases can this agent open?
- Can it execute Python or shell commands, or only inspect the database?
- Can it write files outside the project directory?
- Are multiple agents allowed to modify the same database?
- What records prove which model requested a patch and who approved it?
The uncomfortable truth is that an MCP connection can make a safe interactive workflow look like an unsafe automation workflow if the permissions are copied without the human step. Ask is a review mechanism when a person is present. It is a refusal when the caller is external. Treating those as equivalent produces confusing failures at best and an unreviewed write path at worst.
What builders should test first
Do not begin by asking whether the agent can find a clever function in a complicated binary. Begin with a permission matrix.
Test the same task in three modes: read-only, interactive approval, and external MCP access. Confirm which tools are advertised, which requests produce a permission card, and which requests are refused. Then test the negative path: ask the agent to run a shell command or write a file when the capability is Off.
For production use, keep the default narrow:
- Start with read-only analysis.
- Use a separate approval path for database edits, code execution, debugger access, and file writes.
- Give external agents explicit On or Off settings instead of relying on Ask.
- Isolate the IDA process and its databases from unrelated credentials and network access.
- Record the input, model identity, requested capability, approval decision, and resulting artifact.
That last step matters for reverse engineering because a database is not just a report. It is a mutable analysis state. A renamed symbol, patched byte, generated signature, or extracted file can change what the next analyst believes about the sample.
The real feature is the stop button
The radar made IDA Assist look like another arrival in the agentic coding race. The official documentation shows a more consequential pattern: a domain-specific agent with a typed tool surface and an explicit boundary between inspection and action.
That pattern should be familiar to anyone building agents. The model supplies reasoning. The harness supplies tools. The permission system decides where reasoning stops and an operator, policy, or verifier must take over.
Agentic reverse engineering will become more capable. The useful question is not whether the model can touch the binary. It is whether the system can prove who allowed it to change one.
Sources
- Hex-Rays Docs, “Overview | IDA 9.5 Beta”: https://docs.hex-rays.com/ida-9.5/add-ons/assist/overview
- Hex-Rays Docs, “Permissions & Privacy | IDA 9.5 Beta”: https://docs.hex-rays.com/ida-9.5/add-ons/assist/concepts/permissions-and-privacy
- Hex-Rays Docs, “Getting Started | IDA 9.5 Beta”: https://docs.hex-rays.com/ida-9.5/add-ons/assist/getting-started
- Hex-Rays Docs, “Overview | Hex-Rays IDA MCP Server”: https://docs.hex-rays.com/core/mcp/overview
- Google VRP, radar post announcing PageBreak and deterministic validation, used for discovery context only: https://x.com/GoogleVRP/status/2104964422154203276
Method note: the candidate was selected from the two required free, session-authenticated twsearch radar queries. The article’s product and permission claims are based on Hex-Rays’ official documentation. The X post is cited as discovery context, not as evidence for Hex-Rays’ implementation details.