JADX-MCP-SERVER (Part of Zin's Reverse Engineering MCP Suite)

by zinja-coder

690 808 downloads Not rated yet Apache-2.0
GitHub

About

JADX-MCP-SERVER is a standalone Python server that uses the Model Context Protocol (MCP) to connect LLMs like Claude with a modified version of jadx-gui (via the JADX-AI-MCP plugin), enabling live reverse engineering and analysis of decompiled Android APKs. It is part of Zin’s…

Details

License
Apache-2.0

Explore

- Provides over 20 MCP tools for code and resource analysis
- Enables live vulnerability detection and code review
- Supports debugger integration (stack frames, threads, variables)
- Allows cross-reference searches (xrefs) for methods, fields, and classes
- Can rename variables and retrieve manifest, resources, and smali

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name JADX-MCP-SERVER (Part of Zin's Reverse Engineering MCP Suite)
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

READ HERE

Demo: Perform Code Review to Find Vulnerabilities locally

https://github.com/user-attachments/assets/4cd26715-b5e6-4b4b-95e4-054de6789f42

Scenario 1 — Everything on the same machine (most common):
```bash

get_manifest_component

Retrieve specific manifest component instead of whole manifest file

The following MCP tools are available:

- fetch_current_class() — Get the class name and full source of selected class
- get_selected_text() — Get currently selected text
- get_all_classes() — List all classes in the project
- get_class_source() — Get full source of a given class
- get_method_by_name() — Fetch a method’s source
- search_method_by_name() — Search method across classes
- search_classes_by_keyword() — Search for classes whose source code contains a specific keyword (supports pagination)
- get_methods_of_class() — List methods in a class
- get_fields_of_class() — List fields in a class
- get_smali_of_class() — Fetch smali of class
- get_main_activity_class() — Fetch main activity from jadx mentioned in AndroidManifest.xml file.
- get_main_application_classes_code() — Fetch all the main application classes' code based on the package name defined in the AndroidManifest.xml.
- get_main_application_classes_names() — Fetch all the main application classes' names based on the package name defined in the AndroidManifest.xml.
- get_android_manifest() — Retrieve and return the AndroidManifest.xml content.
- get_manifest_component - Retrieve specific manifest component instead of whole manifest file
- get_strings() : Fetches the strings.xml file
- get_all_resource_file_names() : Retrieve all resource files names that exists in application
- get_resource_file() : Retrieve resource file content
- rename_variable() : Renames the variable within a method
- debug_get_stack_frames() : Get the stack frames from jadx debugger
- debug_get_threads() : Get the insights of threads from jadx debugger
- debug_get_variables() : Get the variables from jadx debugger
- xrefs_to_class() : Find all references to a class (returns method-level and class-level references, supports pagination)
- xrefs_to_method() : Find all references to a method (includes override-related methods, supports pagination)
- xrefs_to_field() : Find all references to a field (returns methods that access the field, supports pagination)
---

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "jadx-mcp-server (part of zin's reverse engineering mcp suite)": {
            "jadx-mcp-server": {
                "command": "uv",
                "args": [
                    "run",
                    "jadx_mcp_server.py",
                    "--http"
                ]
            }
        }
    }
}

McpServers

{
    "jadx-mcp-server": {
        "command": "uv",
        "args": [
            "run",
            "jadx_mcp_server.py",
            "--http"
        ]
    }
}

⚡ Fully automated MCP server built to communicate with JADX-AI-MCP Plugin to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.

GitHub contributors JADX-AI-MCP
GitHub contributors JADX-MCP-SERVER
GitHub all releases
GitHub release (latest by SemVer)
Latest release
Java 11+
Python 3.10+
License

⭐ Contributors

Thanks to these wonderful people for their contributions ⭐
<table>
<tr align="center">
<td>
<a href="https://github.com/ljt270864457">

<br /><sub><b>ljt270864457</b></sub>
</a>
</td>
<td>
<a href="https://github.com/badmonkey7">

<br /><sub><b>badmonkey7</b></sub>
</a>
</td>
<td>
<a href="https://github.com/p0px">

<br /><sub><b>p0px</b></sub>
</a>
</td>
<td>
<a href="https://github.com/bx33661">

<br /><sub><b>bx33661</b></sub>
</a>
</td>
<td>
<a href="https://github.com/Haicaji">

<br /><sub><b>Haicaji</b></sub>
</a>
</td>
<td>
<a href="https://github.com/mostafaNazari702">

<br /><sub><b>Mostafa Nazari</b></sub>
</a>
</td>
<td>
<a href="https://github.com/ChineseAStar">

<br /><sub><b>ChineseAStar</b></sub>
</a>
</td>
<td>
<a href="https://github.com/cyal1r">

<br /><sub><b>cyal1</b></sub>
</a>
</td>
<td>
<a href="https://github.com/tiann">

<br /><sub><b>tainn</b></sub>
</a>
</td>
<td>
<a href="https://github.com/ZERO-A-ONE">

<br /><sub><b>ZERO-A-ONE</b></sub>
</a>
</td>
<td>
<a href="https://github.com/neoz">

<br /><sub><b>neoz</b></sub>
</a>
</td>
<td>
<a href="https://github.com/SamadiPour">

<br /><sub><b>SamadiPour</b></sub>
</a>
</td>
<td>
<a href="https://github.com/wuseluosi">

<br /><sub><b>wuseluosi</b></sub>
</a>
</td>
<td>
<a href="https://github.com/CainYzb">

<br /><sub><b>CainYzb</b></sub>
</a>
</td>
<td>
<a href="https://github.com/tbodt">

<br /><sub><b>tbodt</b></sub>
</a>
</td>
<td>
<a href="https://github.com/LilNick0101">

<br /><sub><b>LikNick0101</b></sub>
</a>
</td>
<td>
<a href="https://github.com/lwsinclair">

<br /><sub><b>lwsinclair</b></sub>
</a>
</td>
</tr>
</table>

</div>
<!-- Still in early stage of development — expect bugs, crashes, and logical errors.-->

<!-- MCP (Model Context Protocol) server that connects to a custom plugin of JADX called JADX-AI-MCP and provides reverse engineering capabilities directly to local LLMs like Claude Desktop.-->

<div align="center">
banner
</div>

ReadTheDocs:
- We are now live at Read The Docs:

---

Download now: https://github.com/zinja-coder/jadx-ai-mcp/releases

---

🤖 What is JADX-MCP-SERVER?

JADX MCP Server is a standalone Python server that interacts with a modified version of jadx-gui (see: jadx-ai-mcp) via MCP (Model Context Protocol). It lets LLMs communicate with the decompiled Android app context live.

🤖 What is JADX-AI-MCP?

JADX-AI-MCP is a plugin for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

Think: "Decompile → Context-Aware Code Review → AI Recommendations" — all in real time.

High Level Sequence Diagram
sequenceDiagram
LLM CLIENT->>JADX MCP SERVER: INVOKE MCP TOOL
JADX MCP SERVER->>JADX AI MCP PLUGIN: INVOKE HTTP REQUEST
JADX AI MCP PLUGIN->>REQUEST HANDLERS: INVOKE HTTP REQUEST HANDLER
REQUEST HANDLERS->>JADX GUI: PERFORM ACTION/GATHER DATA
JADX GUI->>REQUEST HANDLERS: ACTION PERFORMED/DATA GATHERED
REQUEST HANDLERS->>JADX AI MCP PLUGIN: CRAFT HTTP RESPONSE
JADX AI MCP PLUGIN->>JADX MCP SERVER:HTTP RESPONSE
JADX MCP SERVER->>LLM CLIENT: MCP TOOL RESULT

Watch the demos!

- Perform quick analysis

https://github.com/user-attachments/assets/b65c3041-fde3-4803-8d99-45ca77dbe30a

- Quickly find vulnerabilities

https://github.com/user-attachments/assets/c184afae-3713-4bc0-a1d0-546c1f4eb57f

- Multiple AI Agents Support

https://github.com/user-attachments/assets/6342ea0f-fa8f-44e6-9b3a-4ceb8919a5b0

- Analyze The APK Resources

https://github.com/user-attachments/assets/f42d8072-0e3e-4f03-93ea-121af4e66eb1

- Your AI Assistant during debugging of APK using JADX

https://github.com/user-attachments/assets/2b0bd9b1-95c1-4f32-9b0c-38b864dd6aec

It is combination of two tools:
1. JADX-AI-MCP
2. JADX MCP SERVER

---

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.

Videos about JADX-MCP-SERVER (Part of Zin's Reverse Engineering MCP Suite)

Relevant YouTube tutorials, setups, and demos