apktool-mcp-server

An MCP server on top of apktool: the agent decodes APKs, reads the manifest and smali, searches the code and patches it for Android reverse engineering

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Reads and modifies decoded Android app code and resources
  • A reverse engineering tool; use only on your own or authorized apps
  • Aimed at finding vulnerabilities and secrets, which requires authorization
All reasons and checks

zinja-coder/apktool-mcp-server

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add mcp/apktool-mcp-server

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Assembled automatically, review before installing.

This entry is high risk, so there is no one-click install. Review the code and add the config by hand.

Run in a terminal

claude mcp add --transport stdio --env 'APKTOOL_MCP_SERVER_PATH=<APKTOOL_MCP_SERVER_PATH value>' apktool-mcp-server -- uvx --directory '<APKTOOL_MCP_SERVER_PATH value>' run apktool_mcp_server.py

Or add to the file .mcp.json, in the project

{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.cursor/mcp.json, for all projects

{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

code --add-mcp '{"name":"apktool-mcp-server","type":"stdio","command":"uvx","args":["--directory","<APKTOOL_MCP_SERVER_PATH value>","run","apktool_mcp_server.py"],"env":{"APKTOOL_MCP_SERVER_PATH":"<APKTOOL_MCP_SERVER_PATH value>"}}'

Or add to the file .vscode/mcp.json, in the project

{
  "servers": {
    "apktool-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the servers key.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

codex mcp add apktool-mcp-server --env 'APKTOOL_MCP_SERVER_PATH=<APKTOOL_MCP_SERVER_PATH value>' -- uvx --directory '<APKTOOL_MCP_SERVER_PATH value>' run apktool_mcp_server.py

Or add to the file ~/.codex/config.toml, for all projects

[mcp_servers.apktool-mcp-server]
command = "uvx"
args = ["--directory", "<APKTOOL_MCP_SERVER_PATH value>", "run", "apktool_mcp_server.py"]
env = { APKTOOL_MCP_SERVER_PATH = "<APKTOOL_MCP_SERVER_PATH value>" }

If the file already exists, append the block to the end.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.gemini/settings.json, for all projects

{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/devin/mcp_config.json, for all projects

{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Formerly Windsurf.

Add to the file cline_mcp_settings.json, for all projects

{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .roo/mcp.json, in the project

{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

A fork of Roo Code, same .roo folders.

Add to the file opencode.json, in the project

{
  "mcp": {
    "apktool-mcp-server": {
      "type": "local",
      "command": [
        "uvx",
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "environment": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcp key.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/zed/settings.json, for all projects

{
  "context_servers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the context_servers key.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .codeassistant/mcp.json, in the project

{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "--directory",
        "<APKTOOL_MCP_SERVER_PATH value>",
        "run",
        "apktool_mcp_server.py"
      ],
      "env": {
        "APKTOOL_MCP_SERVER_PATH": "<APKTOOL_MCP_SERVER_PATH value>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

APKTOOL_MCP_SERVER_PATHrequired
Absolute path to apktool-mcp-server directory

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

You will need: uv

Checked against the repository on Sep 26, 2026, commit 12bb331.

Text for your agent

Install apktool and verify apktool -version. Install uv, download the apktool-mcp-server release and add it to the client config: command uv with args --directory path run apktool_mcp_server.py.

Other ways from the author
{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "/<path>/<to>/uv",
      "args": ["--directory", "</PATH/TO/>apktool-mcp-server/", "run", "apktool_mcp_server.py"]
    }
  }
}

Replace the paths with your own. Install apktool and uv first.

This is third-party code. Review the repository files before installing.

What it does

The server wraps apktool and gives an AI agent a set of tools for a decoded APK project. They include decoding an APK, building it back, reading AndroidManifest.xml and apktool.yml, listing and reading smali files and resources, pattern search, and editing smali and resource files. This supports reviewing permissions, hunting hardcoded endpoints and secrets, finding exported components and making targeted code changes. The server is written in Python with fastmcp and runs through uv.

Who it is for. For mobile app security specialists and reverse engineers who analyze their own or authorized APKs.

Good fit when

  • You review the permissions and components of an Android app from its manifest
  • You hunt for hardcoded endpoints or secrets in smali and resources
  • You need a targeted smali patch and a rebuild of the APK

Not a fit when

  • You have no right to analyze the app or the owner's consent
  • The target is someone else's app without authorization
  • You need runtime dynamic analysis rather than static work

Example request

Decode my APK and show the dangerous permissions from AndroidManifest.xml

Limitations

It needs apktool on PATH and the uv manager. The server works on the static view of an APK: smali, resources, manifest. Some tools modify project files, and a rebuild depends on the edits being correct. The authors note the project is early stage, so bugs and crashes are possible.

How to disable. Remove the apktool-mcp-server entry from the MCP client config and delete the project folder. The installed apktool can be removed separately if desired.

MCP

Transport
stdio
Authentication
not required

Security check

  • Reads and modifies decoded Android app code and resources
  • A reverse engineering tool; use only on your own or authorized apps
  • Aimed at finding vulnerabilities and secrets, which requires authorization

README in short

The README describes the server toolset and sample prompts for code understanding, vulnerability detection, reverse engineering and static analysis. Install goes through a release archive, uv and fastmcp, with config for Claude Desktop and Cherry Studio using the uv command. The project is part of the Zin Reverse Engineering MCP Suite and builds on apktool by iBotPeaches, licensed Apache 2.0. A legal warning limits use to authorized targets.

FAQ

Do I need a separate apktool?

Yes. The server wraps apktool, so install it and add it to the environment; verify with apktool -version.

Can it modify code?

Yes. There are tools to edit smali and resources and rebuild the APK, but the result depends on the edits being correct.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIapktool-mcp-server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.