apktool-mcp-server (Part of Zin's Reverse Engineering MCP Suite)
About
A MCP Server for APK Tool (Part of Android Reverse Engineering MCP Suites)
Details
- License
- Apache-2.0
Explore
- Kindly open an issue with respective template.
- Tested on Claude Desktop Client, support for other AI will be tested soon!
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
apktool-mcp-server (Part of Zin's Reverse Engineering MCP Suite)Command (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
https://apktool.org/docs/install
$ apktool -version
curl -LsSf https://astral.sh/uv/install.sh | sh
uv venv
source .venv/bin/activate # or .venv\Scripts\activate on Windows
uv pip install httpx fastmcp
<div align="center">
<a href="https://github.com/zinja-coder/zin-mcp-client">
</a>
</div>
⚡ Lightweight, Fast, Simple, CLI-Based MCP Client for STDIO MCP Servers, to fill the gap and provide bridge between your local LLMs running Ollama and MCP Servers.
Check Now: https://github.com/zinja-coder/zin-mcp-client
Demo: Coming soon...
Make sure Claude Desktop is running with MCP enabled.
For instance, I have used following for Kali Linux: https://github.com/aaddrick/claude-desktop-debian
Configure and add MCP server to LLM file:
bashnano ~/.config/Claude/claude_desktop_config.json
- Windows: %APPDATA%\Claude\claude_desktop_config.json
- macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
And following content in it:
json{
"mcpServers": {
"apktool-mcp-server": {
"command": "/<path>/<to>/uv",
"args": [
"--directory",
"</PATH/TO/>apktool-mcp-server/",
"run",
"apktool_mcp_server.py"
]
}
}
}
Replace:
- path/to/uv with the actual path to your uv executable
- path/to/apktool-mcp-server with the absolute path to where you cloned this
repository
Then, navigate code and interact via real-time code review prompts using the built-in integration.
If you want to configure the MCP tool in Cherry Studio, you can refer to the following configuration.
- Type: stdio
- command: uv
- argument:
bash--directory
path/to/apktool-mcp-server
run
apktool_mcp_server.py
``
- path/to/apktool-mcp-server` with the absolute path to where you cloned thisrepository
⚡ Fully automated MCP server built on top of apktool to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.
</div>
<!-- It is a still in early stage of development, so expects bugs, crashes and logical erros.-->
<div align="center">
</div>
<!--
-->
Image generated using AI tools.
---
apktool-mcp-server is a MCP server for the Apk Tool that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.
Think: "Decompile → Context-Aware Code Review → AI Recommendations" — all in real time.
Watch the demo!
https://github.com/user-attachments/assets/d50251b8-6b1c-4341-b18e-ae54eb24a847
- Solving the CTFs
https://github.com/user-attachments/assets/c783a604-a636-4e70-9fa8-37e3d219b20b
The following MCP tools are available:
- build_apk() — Build an APK from a decoded APKTool Project.
- get_manifest() — Get the AndroidManifest.xml content from a decoded APK project.
- get_apktool_yml() — Get apktool.yml information from a decoded APK project.
- list_smali_directories() — List all smali directories in a project.
- list_smali_files() — List smali files in a specific smali directory, optinally filtered by package prefix.
- get_smali_file() — Get content of a specific smali file by class name.
- modify_smali_file() — Modify the content of a specific smali file.
- list_resources() — List resources in a project, optionally filtered by resource type.
- get_resource_file() — Get Content of a specific resource file.
- modify_resource_file() — Modify the content of a specific resource file.
- search_in_file() — Search for a pattern in files with specified extensions.
- clean_project() — Clean a project directory to prepare for rebuilding.
- decode_apk() — Decode an APK file using APKTool, extracting resources and smali code.
---
https://github.com/zinja-coder/apktool-mcp-server/releases
uv venv
source .venv/bin/activate # or .venv\Scripts\activate on Windows
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"apktool-mcp-server (part of zin's reverse engineering mcp suite)": {
"apktool-mcp-server": {
"command": "uv",
"args": [
"venv"
]
}
}
}
}
McpServers
{
"apktool-mcp-server": {
"command": "uv",
"args": [
"venv"
]
}
}
⚡ Fully automated MCP server built on top of apktool to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.
</div>
<!-- It is a still in early stage of development, so expects bugs, crashes and logical erros.-->
<div align="center">
</div>
<!--
-->
Image generated using AI tools.
---
🤖 What is apktool-mcp-server?
apktool-mcp-server is a MCP server for the Apk Tool that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.
Think: "Decompile → Context-Aware Code Review → AI Recommendations" — all in real time.
Watch the demo!
https://github.com/user-attachments/assets/d50251b8-6b1c-4341-b18e-ae54eb24a847
- Solving the CTFs
https://github.com/user-attachments/assets/c783a604-a636-4e70-9fa8-37e3d219b20b
Other projects in Zin MCP Suite
- JADX-AI-MCP - JADX-MCP-Server - ZIN-MCP-ClientCurrent MCP Tools
The following MCP tools are available:
- build_apk() — Build an APK from a decoded APKTool Project.
- get_manifest() — Get the AndroidManifest.xml content from a decoded APK project.
- get_apktool_yml() — Get apktool.yml information from a decoded APK project.
- list_smali_directories() — List all smali directories in a project.
- list_smali_files() — List smali files in a specific smali directory, optinally filtered by package prefix.
- get_smali_file() — Get content of a specific smali file by class name.
- modify_smali_file() — Modify the content of a specific smali file.
- list_resources() — List resources in a project, optionally filtered by resource type.
- get_resource_file() — Get Content of a specific resource file.
- modify_resource_file() — Modify the content of a specific resource file.
- search_in_file() — Search for a pattern in files with specified extensions.
- clean_project() — Clean a project directory to prepare for rebuilding.
- decode_apk() — Decode an APK file using APKTool, extracting resources and smali code.
---
🗒️ Sample Prompts
🔍 Basic Code Understanding
- “List all smali directories for the dvac project.”
- “Show me all the smali files under the package prefix com.vulnerable.component in the dvac project.”
- “Get the smali code for the class com.vulnerable.component.MainActivity.”
- “Compare MainActivity.smali with its previous version and show differences.”
- “Search for usage of startActivity in smali files of dvac project.”
🛡️ Vulnerability Detection
- “Analyze declared permissions in the dvac AndroidManifest.xml and flag dangerous ones.”
- “Search for hardcoded URLs or IPs in all .xml and .smali files in the project.”
- “Find all uses of PendingIntent.getActivity in smali files.”
- “Check for exported activities or receivers in dvac’s AndroidManifest.xml.”
- “List all smali files that access android.permission.SEND_SMS or READ_CONTACTS.”
🛠️ Reverse Engineering Helpers
- “Decode this APK: dvac.apk and create a project called dvac.”
- “Create a new APKTool project called test-harness.”
- “Clean the dvac project before rebuild.”
- “Extract DEX files from dvac project for external analysis.”
- “Modify MainActivity.smali to insert a log line at the beginning of onCreate().”
📦 Static Analysis
- “Get the complete AndroidManifest.xml from dvac project.”
- “Show the contents of apktool.yml for the dvac project.”
- “List all resource files of type layout.”
- “Search for the word password in all resource and smali files.”
- “Check which permissions are used and compare them against typical over-permissioning risks.”
🤖 AI Code Modification
- “Modify the onCreate() method in MainActivity.smali to add a toast message.”
- “Replace all http:// links with https:// in strings.xml.”
- “Add the android:exported=false attribute to all activities in the AndroidManifest.xml.”
- “Patch the method validateLogin in LoginManager.smali to always return true.”
- “Add logging statements to every method in MainActivity.smali.”
📄 Documentation & Metadata
- “List all decoded APKTool projects in the workspace.”
- “Show me the apktool.yml config to review the version, original APK metadata, and compression settings.”
- “Get all available Android devices connected via ADB. (To be migrated to ADB MCP Server.)”
- “Get metadata about the project dvac from its apktool.yml.”
- “Check which APKTool version is currently installed on the server.”
---
🛠️ Getting Started
1. Downlaod from Releases: https://github.com/zinja-coder/apktool-mcp-server/releases
```bash
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



