</>MCP Agents Market
Skill

android-reverse-engineering-skill

by SimoneAvogadro7.2kShellUpdated 2026-06-10

Claude Code skill to support Android app's reverse engineering

Claude Code

An agent skill for Claude Code that decompiles Android applications and extracts HTTP API endpoints from compiled binaries. It analyzes APK, XAPK, JAR, and AAR files to uncover Retrofit, OkHttp, Ktor, and Apollo GraphQL endpoints, authentication patterns, and hardcoded URLs without access to source code. The skill includes first-class Kotlin support with R8 deobfuscation that recovers original class names from metadata, and features a Phase 0 fingerprinting mode to quickly triage apps before full decompilation.

Key Features

Decompiles APK, XAPK, JAR, and AAR files using jadx, Fernflower, or Vineflower engines with side-by-side comparison mode
Extracts API endpoints from Retrofit, OkHttp, Volley, Ktor, Apollo GraphQL, and Koin dependency injection frameworks
Recovers original Kotlin class names (Repository, ViewModel, UseCase patterns) from R8-obfuscated binaries via metadata analysis
Phase 0 fingerprinting triages apps in seconds to detect framework type, HTTP stack, obfuscation level, and native libraries before decompilation
Traces execution flows from Activities and Fragments through ViewModels down to HTTP calls
R8-resistant path and URL extraction using quoted string literals that survive aggressive obfuscation
Cross-platform support with both Bash and PowerShell scripts for Linux, macOS, and Windows
Detects authentication patterns including tokens, HMAC request-signing schemes, and hardcoded credentials

Use Cases

  • 01Security research and authorized penetration testing of Android applications
  • 02Documenting undocumented REST and GraphQL APIs from compiled mobile apps
  • 03Analyzing malware samples to identify command-and-control endpoints and communication patterns
  • 04Reverse engineering third-party apps for interoperability and integration purposes
  • 05Educational projects and capture-the-flag competitions involving Android app analysis
  • 06Incident response investigations to trace network activity and data exfiltration vectors

Related Skills

View more

android-reverse-engineering-skill — FAQ

What is the android-reverse-engineering-skill?+

It's a Claude Code skill that adds Android reverse engineering capabilities to the AI agent, enabling it to decompile APK files and extract API endpoints, authentication patterns, and call flows from obfuscated Android applications.

How do I install this agent skill in Claude Code?+

Run '/plugin marketplace add SimoneAvogadro/android-reverse-engineering-skill' followed by '/plugin install android-reverse-engineering@android-reverse-engineering-skill' inside Claude Code. The skill will persist across all future sessions.

What are the prerequisites for using this skill?+

You need Java JDK 17 or higher and the jadx CLI tool installed. Optional but recommended dependencies include Vineflower or Fernflower for better decompilation output and dex2jar for certain workflows. The skill includes scripts to check and auto-install missing dependencies.

Does this skill work with modern Kotlin and obfuscated apps?+

Yes, it specifically supports modern Kotlin/KMP stacks including Ktor and Apollo GraphQL. It recovers original Kotlin class names from R8-obfuscated binaries by extracting metadata that the obfuscator cannot strip, typically recovering 100% of Repository, ViewModel, and UseCase class names.

Is this skill free to use?+

Yes, it's open source and released under the Apache 2.0 license. All decompilation and analysis happens locally on your machine.

Which operating systems are supported?+

Linux and macOS are fully supported via Bash scripts. Windows support through PowerShell scripts is experimental and being actively stabilized by the maintainer.

How do I install android-reverse-engineering-skill?+

Open the source repository on GitHub and follow its README. android-reverse-engineering-skill is a skill — MCP Agents Market links you directly to the official repo.

Is android-reverse-engineering-skill free?+

android-reverse-engineering-skill is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches