Apktool

by secfathy

Not rated
GitHub

About

A server for Android APK analysis and reverse engineering using Apktool.

Details

Author
secfathy
Categories
Developer Tools, Security, Other

Setup

Install Apktool in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/secfathy/APktool-MCP

Follow the installation instructions in the repository README, then restart your MCP client.

A powerfulModel Context Protocol (MCP) serverthat exposesApktoolfunctionality for Android APK analysis and reverse engineering. Integrates seamlessly withGemini CLIto provide AI-powered APK security analysis, privacy auditing, and reverse engineering guidance through natural language commands.

- Decompile APKsto extract resources, manifest, and smali code
- Analyze permissionsand app components for security assessment
- Extract string resourcesand detect hardcoded secrets
- Search smali codefor specific patterns and security vulnerabilities
- Recompile modified APKsafter making changes

- Natural language commandsfor complex APK analysis tasks
- Automated security auditswith AI-generated insights
- Privacy compliance checkingand GDPR/CCPA analysis
- Step-by-step reverse engineeringguidance
- Intelligent vulnerability detectionand risk assessment

- Security Analysis: Comprehensive vulnerability assessment
- Privacy Audit: Data collection and compliance analysis
- Reverse Engineering Guide: Step-by-step analysis workflows

# Ubuntu/Debian sudo apt update && sudo apt install default-jdk # macOS (Homebrew) brew install openjdk # Verify installation java -version
# Option 1: Package manager (recommended) # Ubuntu/Debian sudo apt install apktool # macOS brew install apktool # Option 2: Manual installation # Download from https://ibotpeaches.github.io/Apktool/install/ # Verify installation apktool --version
python3 --version # Should be 3.10 or higher
git clone https://github.com/SecFathy/APktool-MCP.git cd APktool-MCP
python3 -m venv venv source venv/bin/activate # Linux/macOS # or venv\Scripts\activate # Windows
python3 apktool_server.py # Should start the MCP server successfully
# Follow instructions at https://github.com/google-gemini/gemini-cli

Edit your Gemini CLI configuration file:

- Linux/macOS:~/.config/gemini-cli/config.json
- Windows:%APPDATA%\gemini-cli\config.json

{ "mcpServers": { "apktool": { "command": "python3", "args": ["/absolute/path/to/apktool_server.py"], "env": { "APKTOOL_WORK_DIR": "/path/to/workspace" } } } }

Claude Desktop Integration (Alternative)

- macOS:~/Library/Application Support/Claude/claude_desktop_config.json
- Windows:%APPDATA%\Claude\claude_desktop_config.json
- Linux:~/.config/Claude/claude_desktop_config.json

{ "mcpServers": { "apktool": { "command": "python3", "args": ["/absolute/path/to/apktool_server.py"], "env": { "APKTOOL_WORK_DIR": "/path/to/workspace" } } } }
# Start Gemini CLI gemini # Security Analysis > "Analyze the APK at ./suspicious_app.apk for security vulnerabilities" # Permission Analysis > "What permissions does ./myapp.apk request and are any of them dangerous?" # Code Analysis > "Find any hardcoded API keys or secrets in ./social_app.apk" # Privacy Audit > "Generate a privacy compliance report for ./messenger_app.apk" # Reverse Engineering > "Help me understand how the authentication works in ./banking_app.apk"
# Decompile an APK > Use decode_apk to decompile ./sample.apk # Analyze permissions > Use list_permissions on the decompiled directory ./sample # Search for patterns > Use find_smali_references to search for "crypto" in ./sample # Extract strings > Use extract_strings from ./sample for locale "en" # Rebuild APK > Use build_apk to recompile ./sample into ./sample_modified.apk
# Run automated security analysis > Run the security analysis prompt on ./target_app.apk # Perform privacy audit > Execute privacy audit workflow for ./social_media_app.apk # Get reverse engineering guidance > Use the reverse engineering guide for analyzing login functionality in ./app.apk
apktool-mcp-server/ ├── apktool_server.py # Main MCP server implementation ├── requirements.txt # Python dependencies ├── config.json # Example Gemini CLI configuration ├── README.md # This file ├── GEMINI.md # AI assistant context file ├── LICENSE # MIT license ├── examples/ # Usage examples and samples │ ├── sample_analysis.py # Example analysis scripts │ └── workflows/ # Common workflow examples ├── tests/ # Unit tests │ ├── test_server.py # Server functionality tests │ └── test_tools.py # Individual tool tests └── docs/ # Additional documentation ├── SECURITY.md # Security guidelines ├── CONTRIBUTING.md # Contribution guidelines └── TROUBLESHOOTING.md # Common issues and solutions

- Legal Compliance: Only analyze APKs you own or have explicit permission to analyze
- Malware Risk: Unknown APKs may contain malicious code - use in isolated environments
- Data Privacy: Decompiled APKs may contain sensitive user information
- Workspace Isolation: Configure dedicated workspace with restricted permissions
- Process Limits: Server includes timeouts to prevent resource exhaustion

# Use dedicated workspace export APKTOOL_WORK_DIR="/secure/isolated/workspace" # Set appropriate permissions chmod 750 /secure/isolated/workspace # Monitor resource usage htop # Watch memory and CPU during analysis # Clean up after analysis rm -rf /secure/isolated/workspace/*
# Install test dependencies pip install pytest pytest-asyncio # Run all tests pytest tests/ # Run with coverage pytest --cov=apktool_server tests/
# Test server startup python3 apktool_server.py # Test with sample APK # Download a sample APK and test basic functionality
# Test Gemini CLI integration gemini > /tools # Should list apktool tools > Use decode_apk to analyze sample.apk

We welcome contributions! Please seeCONTRIBUTING.mdfor details.

# Clone and setup development environment git clone https://github.com/SecFathy/APktool-MCP.git cd APktool-MCP python3 -m venv venv source venv/bin/activate pip install -r requirements.txt pip install -r requirements-dev.txt # Run tests pytest # Format code black apktool_server.py

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning with Cycode.

Extentos is a multi-vendor development platform for adding smart-glasses capabilities to existing iOS and Android apps. The simplest analogy is Stripe for smart glasses

An MCP server tailored for React Native–first development using Gluestack UI

Model Context Protocol Servers Repository for OpenZeppelin Products

MCP Server for PGYER platform, supports uploading, querying apps, etc.

Enable AI agents to secure code with Semgrep.

Model Context Protocol server for Skycloak managed Keycloak. Manage clusters, realms, applications, SSO and users from any MCP client.

Dependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.

A CLI tool for developers to manage Android devices via ADB.

Drives an Android emulator or a real device over adb: screenshots, UI hierarchy with true device-pixel coordinates, tap and type, app lifecycle, logcat, and Gradle builds and tests.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.