</>MCP Agents Market
Plugin

quark-engine

by ev-flow1.7kPythonUpdated 2026-09-04

Claude Code

The Quark Engine Claude Code plugin brings Android malware analysis capabilities directly into the Claude Code development environment. It provides two specialized skills: /quark:analysis for scanning APK files against a rule database, and /quark:rule-gen for creating custom detection rules from decompiled code. Security researchers and mobile developers can analyze Android applications for malicious behaviors, banking trojans, RATs, and other threats without leaving their AI-assisted coding workflow. The plugin leverages Quark-Engine's extensive malware family signatures covering DroidKungFu, SpyNote, ToxicPanda, Hydra, and dozens of other Android threat families.

Key Features

Two Claude Code skills: /quark:analysis for APK malware scanning and /quark:rule-gen for custom rule generation
Detection signatures for 20+ Android malware families including banking trojans, RATs, ransomware, and NFC relay attacks
Analysis of overlay attacks, accessibility abuse, SMS interception, and credential theft behaviors
Integration with Quark-Engine's regularly updated rule database via the freshquark command
Support for generating summary reports showing malicious behaviors and risk scores
Malware family reports covering DroidKungFu, GoldDream, SpyNote, SharkBot, Cerberus, BRATA, and many others
Rule creation from decompiled Android code to identify new threat patterns
GPL-licensed open source tool featured at Black Hat, DEFCON, and HITB security conferences

Use Cases

  • 01Scanning Android APK files for known malware signatures during security audits
  • 02Generating custom Quark rules to detect new or variant Android threats from decompiled code
  • 03Analyzing banking trojan behaviors like overlay attacks, OTP interception, and keylogging
  • 04Identifying RAT capabilities such as screen recording, remote control, and surveillance features
  • 05Researching malware families for threat intelligence and incident response
  • 06Validating Android app security during mobile development workflows

Related Plugins

View more

quark-engine — FAQ

What is the Quark Engine Claude Code plugin?+

It's a Claude Code plugin that adds Android malware analysis capabilities through two skills: /quark:analysis for scanning APKs and /quark:rule-gen for creating detection rules. It integrates the Quark-Engine security tool into your AI-assisted development environment.

How do I install the Quark Engine plugin in Claude Code?+

First install Quark-Engine via pip3 install -U quark-engine, then run /plugin marketplace add ev-flow/quark-engine followed by /plugin install quark@quark-engine inside Claude Code. Download the latest rules with the freshquark command.

Which AI clients work with this plugin?+

This plugin is specifically designed for Claude Code. The skills (/quark:analysis and /quark:rule-gen) are invoked through Claude Code's plugin interface.

Do I need API keys or special permissions to use Quark Engine?+

No API keys are required. You need Python 3.10+ installed and the ability to run pip commands to install the quark-engine package. The rule database is downloaded freely via the freshquark command.

Is the Quark Engine plugin free to use?+

Yes, Quark-Engine is open source and licensed under GPLv3. Both the core engine and the Claude Code plugin are free to use.

What malware families can Quark Engine detect?+

It detects 20+ Android malware families including banking trojans (SharkBot, Hydra, Cerberus, BRATA, GodFather), RATs (SpyNote, AhRat, AndroRat), ransomware (SLocker), NFC relay attacks (PhantomCard, NGate), and many others. The rule database is regularly updated.

How do I install quark-engine?+

Open the source repository on GitHub and follow its README. quark-engine is a plugin — MCP Agents Market links you directly to the official repo.

Is quark-engine free?+

quark-engine is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches