MCP (Model Context Protocol) server extension for dnSpy, enabling AI agents to decompile and analyze .NET assemblies directly through dnSpy.
概要
MCP (Model Context Protocol) server extension for dnSpy, enabling AI agents to decompile and analyze .NET assemblies directly through dnSpy.
README
dnSpy MCP Server
MCP (Model Context Protocol) server extension for dnSpy, enabling AI agents to decompile and analyze .NET assemblies directly through dnSpy.
How It Works
dnSpy loads extension → MCP Server menu → Start → HttpListener on :5150
↕
AI agent (Claude, etc.)
HTTP POST (JSON-RPC 2.0)
The server runs as a dnSpy extension using System.Net.HttpListener — no ASP.NET Core or external dependencies required. AI agents connect via standard MCP protocol over HTTP.
Tools (36)
Decompiler
| Tool | Description |
|---|---|
decompile_method |
Decompile a method to C#. Accepts full name (Namespace.Class::Method), metadata token (0x06000001), or partial name |
decompile_type |
Decompile an entire type (all members) to C# |
decompile_assembly |
Decompile all types in the assembly (limited to 10 for brevity) |
Search
| Tool | Description |
|---|---|
search_types |
Search types by name pattern. Use regex: prefix for regex matching |
search_methods |
Search methods by name, optionally scoped to a specific type |
search_strings |
Search string literals in method bodies |
grep |
Multi-scope search across types, methods, and strings |
Analysis
| Tool | Description |
|---|---|
get_method_il |
Raw IL instructions with exception handlers |
get_method_signatures |
Method metadata: parameters, return type, flags, generic params |
get_type_hierarchy |
Inheritance chain, interfaces, member counts |
get_method_body |
IL bytes with MaxStack/InitLocals info |
get_il_opcodes_formatted |
Formatted IL opcodes with offsets and line indices |
update_method_body |
Patch a method body using C# statements (dry-run supported) |
UI & Navigation
| Tool | Description |
|---|---|
get_selected_node |
Get the currently selected node in dnSpy tree view |
refresh_u_i |
Refresh tree view UI after metadata changes |
Rename
| Tool | Description |
|---|---|
rename_namespace |
Rename a namespace across matching types (dry-run supported) |
rename_class |
Rename one class in an assembly+namespace (dry-run supported) |
rename_method |
Rename methods by exact or partial match (dry-run supported) |
Namespace
| Tool | Description |
|---|---|
get_global_namespaces |
List all types in the global namespace |
Type Inspection
| Tool | Description |
|---|---|
get_type_members |
List all members of a type with optional filter |
get_fields |
Detailed field info: type, access, static/const, values |
get_properties |
Property details: getter/setter, type, access |
Custom Attributes
| Tool | Description |
|---|---|
get_attributes |
Attributes on assembly/type/method/field with filter |
get_method_attributes |
Shortcut: attributes on a specific method |
Constants & Enums
| Tool | Description |
|---|---|
get_enum_values |
Enum members with name + value (hex + decimal) |
search_constants |
Search const/literal fields across assemblies |
Cross-References
| Tool | Description |
|---|---|
get_xrefs_to |
Find all references to a method or field |
get_callees |
Methods and fields called by a method |
Assembly
| Tool | Description |
|---|---|
assembly_overview |
Module info, version, entry point, type count, references |
assembly_list_namespaces |
All namespaces in the loaded assembly |
assembly_list_types |
Type listing with optional regex filter |
assembly_get_references |
Assembly references (DLLs, NuGet packages) |
Resources & Metadata
| Tool | Description |
|---|---|
get_resources |
List embedded resources |
get_resource_data |
Raw bytes of a specific resource |
get_metadata |
PE headers, MVID, runtime version, sections |
Quick Start
Prerequisites
- dnSpy (.NET 8.0 build)
- .NET 8.0 SDK
deps/folder with these DLLs copied from dnSpy:dnSpy.Contracts.DnSpy.dlldnSpy.Contracts.Logic.dllICSharpCode.Decompiler.dlldnlib.dll
Configure DnSpyBin path
The project resolves dnSpy contract DLLs via the `` MSBuild property in dnSpy.MCP.csproj:
..\..\deps
Default path resolves to /deps/. To change it, edit this property or pass it at the command line:
dotnet build -p:DnSpyBin="D:\path\to\dnSpy\bin"
Build & Deploy
# 1) Build only (Release mặc định)
pwsh scripts/build.ps1
# 2) Clean + build
pwsh scripts/build.ps1 -Clean
# 3) Build + deploy to staging (build/Extensions/)
pwsh scripts/build.ps1 -Deploy
# 4) Build + deploy directly to dnSpy runtime
pwsh scripts/build.ps1 -Deploy -DeployDir "D:\tools\dnSpy\Extensions"
# 5) Override sang Debug khi cần debug
pwsh scripts/build.ps1 -Configuration Debug -Deploy -DeployDir "D:\tools\dnSpy\Extensions"
This builds the extension DLL and deploys it. dnSpy must be closed before running.
Options:
pwsh scripts/build.ps1 -Clean # Clean before build
pwsh scripts/build.ps1 -Deploy # Deploy after build
pwsh scripts/build.ps1 -DeployDir "" # Custom deploy target (used with -Deploy)
pwsh scripts/build.ps1 -Configuration Debug # Build Debug instead of Release
pwsh scripts/build.ps1 -Configuration Release # Build Release (default)
Build output paths
- Build output (Release default):
src/dnSpy.MCP/bin/Release/net8.0-windows/dnSpy.MCP.x.dll - Build output (Debug override):
src/dnSpy.MCP/bin/Debug/net8.0-windows/dnSpy.MCP.x.dll - Staging deploy:
build/Extensions/dnSpy.MCP.x.dll - Runtime deploy:
/Extensions/dnSpy.MCP.x.dll
Only these files should be copied to dnSpy’s Extensions folder:
dnSpy.MCP.x.dlldnSpy.MCP.x.deps.jsondnSpy.MCP.x.pdb(optional for debugging)
Do not copy the whole build/Extensions folder recursively into dnSpy (avoid nested Extensions/Extensions/ and stale dependency files).
Usage
- Start
dnSpy.exe - Open a .NET assembly (.exe/.dll)
- Menu → MCP Server → Start
- Open View → Output (Alt+2) → select MCP Server to see logs
- Connect from an AI agent via
http://127.0.0.1:5150/
Menu Options
| Menu Item | Action |
|---|---|
| Start | Start the MCP HTTP server |
| Status | Show running/stopped state and port |
| Show Log | Display recent log entries |
| Clear Log | Clear log file and output window |
Project Structure
dnspy_mcp/
├── src/
│ └── dnSpy.MCP/ # Standalone extension project (recommended)
│ ├── Mcp/
│ │ ├── McpServerHost.cs # HTTP transport + JSON-RPC 2.0 dispatch
│ │ ├── ToolRegistry.cs # Reflection-based tool discovery
│ │ ├── McpLogger.cs # Logging: file + Output Window
│ │ └── McpServerOptions.cs # Port/host configuration
│ ├── Tools/ # 13 tool classes, 36 tools total
│ ├── Helpers/
│ │ ├── MethodResolver.cs # Resolve methods/types by name/token
│ │ └── TextDecompilerOutput.cs
│ ├── TheExtension.cs # MEF entry point
│ ├── DnSpyContext.cs # Static service bridge
│ └── MenuCommands.cs # dnSpy menu items
├── deps/ # dnSpy contract DLLs (for standalone build)
├── build/Extensions/ # Deployed extension DLLs
├── skills/ # AI agent workflow guides (install to .claude/skills/)
│ └── deobfuscate-dotnet/ # .NET deobfuscation skill
│ └── SKILL.md
└── scripts/
└── build.ps1 # Build & deploy script
Adding New Tools
Tools are discovered at runtime via reflection. To add a new tool:
- Create a
public staticclass insrc/dnSpy.MCP/Tools/under thednSpy.MCP.Toolsnamespace - Add
public staticmethods with a[Description("...")]attribute - Parameters use
[Description("...")]for documentation
using System.ComponentModel;
namespace dnSpy.MCP.Tools {
public static class MyTools {
[Description("Describe what this tool does")]
public static string MyTool(
[Description("Parameter description")] string param1) {
// Access dnSpy services via DnSpyContext
var module = DnSpyContext.DocumentService?
.GetAssemblies().FirstOrDefault()?.ModuleDef;
return $"Result: {param1}";
}
}
}
Method names are automatically converted to snake_case for the MCP protocol (e.g., MyTool → my_tool).
Configuration
Default configuration in McpServerOptions.cs:
- Host:
127.0.0.1 - Port:
5150
Logging
Logs are written to three destinations:
- File:
build/Extensions/mcp-server.log - In-memory: Viewable via MCP Server → Show Log
- Output Window: View → Output → MCP Server (in dnSpy)
Architecture Notes
Why HttpListener instead of MCP SDK?
The official MCP SDK (ModelContextProtocol 1.2.0) pulls Microsoft.Extensions.* 10.x dependencies, but dnSpy runs on .NET 8.0 with Microsoft.Extensions.* 8.x. This is a hard version conflict that cannot be resolved with binding redirects. The solution is a custom HTTP transport using System.Net.HttpListener.
Standalone Build
The project references pre-built DLLs from deps/, enabling fast iteration without cloning the full dnSpy source. For integrated builds as part of dnSpy.sln, clone dnSpyEx and copy src/dnSpy.MCP/ into Extensions/.
Connecting AI Agents
This MCP server exposes dnSpy’s decompilation and analysis tools via the standard MCP protocol over HTTP at http://127.0.0.1:5150/. Most modern AI agents support HTTP MCP servers natively — no bridge package needed.
Claude Code (recommended)
Use the claude mcp add command to add the server. Choose a scope:
# Local scope (default) — only this project, stored in ~/.claude.json
claude mcp add --transport http dnspy http://127.0.0.1:5150
# Project scope — shared with team via .mcp.json (check into git)
claude mcp add --transport http dnspy --scope project http://127.0.0.1:5150
# User scope — all your projects
claude mcp add --transport http dnspy --scope user http://127.0.0.1:5150
Project scope generates a .mcp.json at the project root:
{
"mcpServers": {
"dnspy": {
"type": "http",
"url": "http://127.0.0.1:5150"
}
}
}
Local/User scope writes to ~/.claude.json under the project path:
{
"projects": {
"/path/to/your/project": {
"mcpServers": {
"dnspy": {
"type": "http",
"url": "http://127.0.0.1:5150"
}
}
}
}
}
Other useful commands:
claude mcp list # list all configured servers
claude mcp get dnspy # show config for a server
claude mcp remove dnspy # remove a server
Other AI Editors
| Editor | Config file | Format |
|---|---|---|
| Cursor | ~/.cursor/mcp.json |
{ "mcpServers": { "dnspy": { "url": "http://127.0.0.1:5150/" } } } |
| VS Code (Cline/Roo) | .vscode/mcp.json |
Same as above |
Verification
- Start dnSpy and open an assembly
- Menu → MCP Server → Start
- In your AI agent, verify the connection:
You should see 36 MCP tools available:
- decompile_method
- decompile_type
- search_types
- grep
- get_xrefs_to
- assembly_overview
- ...and more
If the agent does not auto-discover the tools, tell it: “Use the dnSpy MCP server at http://127.0.0.1:5150/ to access decompilation and analysis tools.”
Skills
The skills/ directory contains reusable workflow guides for AI agents working with this MCP server. These skills teach the AI how to think about common analysis tasks — it dynamically picks tools based on what it discovers, rather than following rigid steps.
Available Skills
| Skill | Description |
|---|---|
deobfuscate-dotnet |
Deobfuscate .NET binaries: string decryption, symbol renaming, control flow analysis, proxy call resolution, anti-tamper removal |
Skill Structure
Each skill is a folder containing a SKILL.md file:
skills/
└── deobfuscate-dotnet/
└── SKILL.md # Skill definition (YAML frontmatter + instructions)
Installing Skills for Claude Code
Claude Code auto-discovers skills from .claude/skills/. To install:
# Install a specific skill
cp -r skills/deobfuscate-dotnet .claude/skills/
# Or install all skills
cp -r skills/* .claude/skills/
After installing, the skill activates automatically when you describe a matching task — for example:
# These will trigger the deobfuscation skill:
"Giúp tôi decrypt các string trong binary này"
"Rename lại các class/method bị obfuscate"
"Binary này bị protect bằng gì? Phân tích giúp tôi"
No restart needed — Claude Code picks up new skills on the next message.
For Other AI Editors
If your AI editor supports custom instructions or system prompts, paste the content of SKILL.md directly into your configuration. The skill content is self-contained and editor-agnostic.
License
This project is licensed under GPLv3, consistent with dnSpy’s license.
インストール
This server does not publish a one-line install command.
Open the repository installation guide設定
{
"mcpServers": {
"dnspy": {
"type": "http",
"url": "http://127.0.0.1:5150"
}
}
}