JADX-AI-MCP
A JADX plugin and MCP server: the agent explores decompiled Android app code, finds vulnerabilities and helps with reverse engineering
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Reverse engineering and security analysis are only allowed for permitted apps
- Gives the agent access to the analyzed APK's decompiled code
Install
Manual install
Install the JADX-AI-MCP plugin into JADX per the README, run the companion jadx-mcp-server and connect it to your MCP client. Building needs Java 11+ and Python 3.10+.
This is third-party code. Review the repository files before installing.
What it does
JADX-AI-MCP bridges the Android decompiler JADX with an LLM through MCP. The plugin is added to JADX, and a companion MCP server lets the agent work with the decompiled code of an APK opened in JADX: read classes and methods, look for vulnerabilities, explain logic and drive the app analysis. The project is part of the Zin MCP Suite and targets mobile application security analysis and reverse engineering. The client can be Claude or another MCP-compatible tool.
Who it is for. For mobile security professionals and reverse engineers who analyze Android apps they are authorized to inspect.
Good fit when
- You want the agent to explore an APK's decompiled code
- You want to find vulnerabilities in an Android app under authorized analysis
- You want explanations of class and method logic from JADX
Not a fit when
- You are not authorized to analyze the app or its code
- You need analysis of a non-Android platform
Example request
Open this APK in JADX and find where the app stores secrets, explain the logicLimitations
You need JADX installed with the plugin added and the MCP server running; building and running need Java 11 or newer and Python 3.10 or newer. The tool analyzes decompiled code rather than running the app. Reverse engineering and security analysis are only allowed for apps you are permitted to inspect.
How to disable. Remove the MCP server entry from the client config, stop the server and remove the JADX-AI-MCP plugin from JADX.
MCP
- Transport
- stdio
- Authentication
- not required
Security check
- Reverse engineering and security analysis are only allowed for permitted apps
- Gives the agent access to the analyzed APK's decompiled code
README in short
The README describes JADX-AI-MCP as a plugin for the Android decompiler JADX and an MCP server that together let an LLM such as Claude analyze APKs: find vulnerabilities, explore and reverse engineer code. The project is part of the Zin MCP Suite and works together with a companion jadx-mcp-server. Building and running need Java 11 or newer and Python 3.10 or newer. Its purpose is mobile application security analysis and reverse engineering. Apache-2.0 licensed.
FAQ
What is needed besides the plugin?
JADX installed and the MCP server running, which links the project open in JADX to your MCP client.
Does it run the app?
No. The tool works with decompiled code in JADX rather than executing the app itself.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents