JADX-MCP-SERVER (Part of Zin's Reverse Engineering MCP Suite)
About
JADX-MCP-SERVER is a standalone Python server that uses the Model Context Protocol (MCP) to connect LLMs like Claude with a modified version of jadx-gui (via the JADX-AI-MCP plugin), enabling live reverse engineering and analysis of decompiled Android APKs. It is part of Zin’s…
Details
- License
- Apache-2.0
Explore
- Provides over 20 MCP tools for code and resource analysis
- Enables live vulnerability detection and code review
- Supports debugger integration (stack frames, threads, variables)
- Allows cross-reference searches (xrefs) for methods, fields, and classes
- Can rename variables and retrieve manifest, resources, and smali
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
JADX-MCP-SERVER (Part of Zin's Reverse Engineering MCP Suite)Command (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Demo: Perform Code Review to Find Vulnerabilities locally
https://github.com/user-attachments/assets/4cd26715-b5e6-4b4b-95e4-054de6789f42
Scenario 1 — Everything on the same machine (most common):
```bash
get_manifest_component
Retrieve specific manifest component instead of whole manifest file
The following MCP tools are available:
- fetch_current_class() — Get the class name and full source of selected class
- get_selected_text() — Get currently selected text
- get_all_classes() — List all classes in the project
- get_class_source() — Get full source of a given class
- get_method_by_name() — Fetch a method’s source
- search_method_by_name() — Search method across classes
- search_classes_by_keyword() — Search for classes whose source code contains a specific keyword (supports pagination)
- get_methods_of_class() — List methods in a class
- get_fields_of_class() — List fields in a class
- get_smali_of_class() — Fetch smali of class
- get_main_activity_class() — Fetch main activity from jadx mentioned in AndroidManifest.xml file.
- get_main_application_classes_code() — Fetch all the main application classes' code based on the package name defined in the AndroidManifest.xml.
- get_main_application_classes_names() — Fetch all the main application classes' names based on the package name defined in the AndroidManifest.xml.
- get_android_manifest() — Retrieve and return the AndroidManifest.xml content.
- get_manifest_component - Retrieve specific manifest component instead of whole manifest file
- get_strings() : Fetches the strings.xml file
- get_all_resource_file_names() : Retrieve all resource files names that exists in application
- get_resource_file() : Retrieve resource file content
- rename_variable() : Renames the variable within a method
- debug_get_stack_frames() : Get the stack frames from jadx debugger
- debug_get_threads() : Get the insights of threads from jadx debugger
- debug_get_variables() : Get the variables from jadx debugger
- xrefs_to_class() : Find all references to a class (returns method-level and class-level references, supports pagination)
- xrefs_to_method() : Find all references to a method (includes override-related methods, supports pagination)
- xrefs_to_field() : Find all references to a field (returns methods that access the field, supports pagination)
---
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"jadx-mcp-server (part of zin's reverse engineering mcp suite)": {
"jadx-mcp-server": {
"command": "uv",
"args": [
"run",
"jadx_mcp_server.py",
"--http"
]
}
}
}
}
McpServers
{
"jadx-mcp-server": {
"command": "uv",
"args": [
"run",
"jadx_mcp_server.py",
"--http"
]
}
}
⚡ Fully automated MCP server built to communicate with JADX-AI-MCP Plugin to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.
⭐ Contributors
Thanks to these wonderful people for their contributions ⭐
<table>
<tr align="center">
<td>
<a href="https://github.com/ljt270864457">
<br /><sub><b>ljt270864457</b></sub>
</a>
</td>
<td>
<a href="https://github.com/badmonkey7">
<br /><sub><b>badmonkey7</b></sub>
</a>
</td>
<td>
<a href="https://github.com/p0px">
<br /><sub><b>p0px</b></sub>
</a>
</td>
<td>
<a href="https://github.com/bx33661">
<br /><sub><b>bx33661</b></sub>
</a>
</td>
<td>
<a href="https://github.com/Haicaji">
<br /><sub><b>Haicaji</b></sub>
</a>
</td>
<td>
<a href="https://github.com/mostafaNazari702">
<br /><sub><b>Mostafa Nazari</b></sub>
</a>
</td>
<td>
<a href="https://github.com/ChineseAStar">
<br /><sub><b>ChineseAStar</b></sub>
</a>
</td>
<td>
<a href="https://github.com/cyal1r">
<br /><sub><b>cyal1</b></sub>
</a>
</td>
<td>
<a href="https://github.com/tiann">
<br /><sub><b>tainn</b></sub>
</a>
</td>
<td>
<a href="https://github.com/ZERO-A-ONE">
<br /><sub><b>ZERO-A-ONE</b></sub>
</a>
</td>
<td>
<a href="https://github.com/neoz">
<br /><sub><b>neoz</b></sub>
</a>
</td>
<td>
<a href="https://github.com/SamadiPour">
<br /><sub><b>SamadiPour</b></sub>
</a>
</td>
<td>
<a href="https://github.com/wuseluosi">
<br /><sub><b>wuseluosi</b></sub>
</a>
</td>
<td>
<a href="https://github.com/CainYzb">
<br /><sub><b>CainYzb</b></sub>
</a>
</td>
<td>
<a href="https://github.com/tbodt">
<br /><sub><b>tbodt</b></sub>
</a>
</td>
<td>
<a href="https://github.com/LilNick0101">
<br /><sub><b>LikNick0101</b></sub>
</a>
</td>
<td>
<a href="https://github.com/lwsinclair">
<br /><sub><b>lwsinclair</b></sub>
</a>
</td>
</tr>
</table>
</div>
<!-- Still in early stage of development — expect bugs, crashes, and logical errors.-->
<!-- MCP (Model Context Protocol) server that connects to a custom plugin of JADX called JADX-AI-MCP and provides reverse engineering capabilities directly to local LLMs like Claude Desktop.-->
<div align="center">

</div>
ReadTheDocs:
- We are now live at Read The Docs:---
Download now: https://github.com/zinja-coder/jadx-ai-mcp/releases
---
🤖 What is JADX-MCP-SERVER?
JADX MCP Server is a standalone Python server that interacts with a modified version of jadx-gui (see: jadx-ai-mcp) via MCP (Model Context Protocol). It lets LLMs communicate with the decompiled Android app context live.
🤖 What is JADX-AI-MCP?
JADX-AI-MCP is a plugin for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.
Think: "Decompile → Context-Aware Code Review → AI Recommendations" — all in real time.
High Level Sequence Diagram
sequenceDiagram
LLM CLIENT->>JADX MCP SERVER: INVOKE MCP TOOL
JADX MCP SERVER->>JADX AI MCP PLUGIN: INVOKE HTTP REQUEST
JADX AI MCP PLUGIN->>REQUEST HANDLERS: INVOKE HTTP REQUEST HANDLER
REQUEST HANDLERS->>JADX GUI: PERFORM ACTION/GATHER DATA
JADX GUI->>REQUEST HANDLERS: ACTION PERFORMED/DATA GATHERED
REQUEST HANDLERS->>JADX AI MCP PLUGIN: CRAFT HTTP RESPONSE
JADX AI MCP PLUGIN->>JADX MCP SERVER:HTTP RESPONSE
JADX MCP SERVER->>LLM CLIENT: MCP TOOL RESULT
Watch the demos!
- Perform quick analysis
https://github.com/user-attachments/assets/b65c3041-fde3-4803-8d99-45ca77dbe30a
- Quickly find vulnerabilities
https://github.com/user-attachments/assets/c184afae-3713-4bc0-a1d0-546c1f4eb57f
- Multiple AI Agents Support
https://github.com/user-attachments/assets/6342ea0f-fa8f-44e6-9b3a-4ceb8919a5b0
- Analyze The APK Resources
https://github.com/user-attachments/assets/f42d8072-0e3e-4f03-93ea-121af4e66eb1
- Your AI Assistant during debugging of APK using JADX
https://github.com/user-attachments/assets/2b0bd9b1-95c1-4f32-9b0c-38b864dd6aec
It is combination of two tools:
1. JADX-AI-MCP
2. JADX MCP SERVER
---
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



