quark-engine
The Quark Engine Claude Code plugin brings Android malware analysis capabilities directly into the Claude Code development environment. It provides two specialized skills: /quark:analysis for scanning APK files against a rule database, and /quark:rule-gen for creating custom detection rules from decompiled code. Security researchers and mobile developers can analyze Android applications for malicious behaviors, banking trojans, RATs, and other threats without leaving their AI-assisted coding workflow. The plugin leverages Quark-Engine's extensive malware family signatures covering DroidKungFu, SpyNote, ToxicPanda, Hydra, and dozens of other Android threat families.
Key Features
Use Cases
- 01Scanning Android APK files for known malware signatures during security audits
- 02Generating custom Quark rules to detect new or variant Android threats from decompiled code
- 03Analyzing banking trojan behaviors like overlay attacks, OTP interception, and keylogging
- 04Identifying RAT capabilities such as screen recording, remote control, and surveillance features
- 05Researching malware families for threat intelligence and incident response
- 06Validating Android app security during mobile development workflows
Related Plugins
View moreandrej-karpathy-skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
claude-mem
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Understand-Anything
Graphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
rtk
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
quark-engine — FAQ
What is the Quark Engine Claude Code plugin?+
It's a Claude Code plugin that adds Android malware analysis capabilities through two skills: /quark:analysis for scanning APKs and /quark:rule-gen for creating detection rules. It integrates the Quark-Engine security tool into your AI-assisted development environment.
How do I install the Quark Engine plugin in Claude Code?+
First install Quark-Engine via pip3 install -U quark-engine, then run /plugin marketplace add ev-flow/quark-engine followed by /plugin install quark@quark-engine inside Claude Code. Download the latest rules with the freshquark command.
Which AI clients work with this plugin?+
This plugin is specifically designed for Claude Code. The skills (/quark:analysis and /quark:rule-gen) are invoked through Claude Code's plugin interface.
Do I need API keys or special permissions to use Quark Engine?+
No API keys are required. You need Python 3.10+ installed and the ability to run pip commands to install the quark-engine package. The rule database is downloaded freely via the freshquark command.
Is the Quark Engine plugin free to use?+
Yes, Quark-Engine is open source and licensed under GPLv3. Both the core engine and the Claude Code plugin are free to use.
What malware families can Quark Engine detect?+
It detects 20+ Android malware families including banking trojans (SharkBot, Hydra, Cerberus, BRATA, GodFather), RATs (SpyNote, AhRat, AndroRat), ransomware (SLocker), NFC relay attacks (PhantomCard, NGate), and many others. The rule database is regularly updated.
How do I install quark-engine?+
Open the source repository on GitHub and follow its README. quark-engine is a plugin — MCP Agents Market links you directly to the official repo.
Is quark-engine free?+
quark-engine is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.