byteray-mcp
Installation
SKILL.md
ByteRay MCP -- Binary Analysis Skill
SSA-First Rule
When tracing data flow, always use SSA form tools. SSA uniquely versions every variable assignment (buf#1, buf#2), making it precise for tracking where data flows. Use these tools for tracing:
trace_ssa_step-- Incremental SSA trace, 5 steps at a time. Preferred for interactive analysis.trace_variable-- Full-function SSA variable scan. Use when you need all uses at once.read_ssa_form-- View all SSA instructions. Use when you need the complete SSA listing.
Do NOT use read_pseudocode for data flow analysis -- pseudocode merges variable versions and loses precision.
Vulnerability Reporting Rules (CRITICAL)
Never make absolute exploitability claims
- NEVER say "this is not exploitable", "this cannot be exploited", or "this is a false positive"
- NEVER say "this is definitely exploitable" without taint evidence
- Binary analysis operates on incomplete information -- you cannot see runtime state, environment, or inputs
- Frame ALL findings in terms of severity and confidence, not binary exploitable/not-exploitable