</>MCP Agents Market
MCP Server

jar-analyzer

by jar-analyzer2.2kJavaUpdated 2026-08-26

Jar Analyzer - 一个 JAR 包 GUI 分析工具,内置 AI 助手协助分析,支持 JAR DIFF 分析,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索等

Claude CodeCodexQwen CodeZCode

Jar Analyzer is a comprehensive Java archive analysis tool with built-in MCP server support and AI assistant capabilities for security auditing and code review. The tool enables developers to analyze JAR files through method call chain tracking, control-flow graph visualization, taint analysis, and string searching across massive codebases. It features both a standalone GUI application and an MCP server that exposes analysis capabilities to AI assistants like Claude Code, enabling natural-language queries over JAR structure, dependencies, and potential vulnerabilities. The tool maintains a local database for fast, deterministic analysis that complements AI-driven code exploration.

Key Features

MCP server with SSE and Streamable HTTP support for AI assistant integration
JAR diff analysis for comparing versions and tracking source code changes across releases
Depth-first search algorithm for automatic vulnerability chain discovery and method call path tracing
JVM-simulated taint analysis for validating exploit chain feasibility
Control-flow graph (CFG) visualization with basic block division and exception flow analysis
Spring Controller and Java Servlet entry point detection for web application analysis
Custom SpEL-based expression search for hunting specific gadget patterns
Built-in AI assistant with workflow support and research capabilities

Use Cases

  • 01Security researchers auditing Java applications for vulnerabilities and exploit chains
  • 02Developers analyzing third-party dependency changes between library versions
  • 03Penetration testers identifying servlet endpoints and Spring controller mappings in web applications
  • 04Code reviewers searching for sensitive information leaks (IPs, credentials, API keys) across JAR archives
  • 05SCA workflows integrating automated JAR analysis into CI/CD pipelines via MCP
  • 06Reverse engineers exploring method call relationships in obfuscated or undocumented Java code

Related MCP Servers

View more

jar-analyzer — FAQ

What is Jar Analyzer and what does the MCP server do?+

Jar Analyzer is a Java archive analysis tool with an integrated MCP server that exposes JAR analysis capabilities to AI assistants. The MCP server allows tools like Claude Code to query method calls, search strings, analyze dependencies, and identify vulnerabilities through natural language.

How do I install and connect the Jar Analyzer MCP server?+

First analyze a JAR file using the GUI to build the database, then navigate to the MCP panel and click 'Start MCP'. Add the SSE or HTTP endpoint configuration to your AI client's MCP settings JSON file.

Which AI clients support Jar Analyzer MCP?+

The MCP server works with Claude Code, Codex, Qwen Code, ZCode, and other clients supporting SSE or Streamable HTTP MCP protocols.

What are the prerequisites for running Jar Analyzer?+

You need JDK 8 (64-bit) to run the tool. No API keys are required; all analysis runs locally offline to protect code confidentiality.

Is Jar Analyzer free to use?+

Yes, Jar Analyzer is completely open source and free. The project has been continuously updated for five years with 67 releases across v1 and v2 versions.

How does Jar Analyzer compare to AI-only code analysis?+

Jar Analyzer provides deterministic, reproducible analysis with sub-second query responses on databases containing millions of methods, whereas AI may hallucinate class names or exceed context windows. The tool complements AI by providing precise grounding data and offers built-in AI integration via MCP for hybrid workflows.

How do I install jar-analyzer?+

Open the source repository on GitHub and follow its README. jar-analyzer is a mcp server — MCP Agents Market links you directly to the official repo.

Is jar-analyzer free?+

jar-analyzer is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches