JADX MCP Server

JADX-MCP-SERVER

MCP server for analyzing Android apps through JADX: the agent reads decompiled code, the manifest and hunts for vulnerabilities

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Reads decompiled code and debug info
  • Can expose tools over the network without authentication
All reasons and checks

zinja-coder/jadx-mcp-server

Install

Manual install

uv run jadx_mcp_server.py --http

Requires JADX-GUI with the JADX-AI-MCP plugin on localhost:8650. Needs Java 11+ and Python 3.10+.

This is third-party code. Review the repository files before installing.

What it does

JADX MCP Server connects an AI agent to the JADX-AI-MCP plugin inside JADX-GUI and exposes tools for dissecting Android apps. Through it the agent reads decompiled Java code, parses the AndroidManifest, renames classes and methods and reaches debug info. The server runs on Python (uv or pip) and talks to the plugin over a separate host and port, with stdio and HTTP transports. It is part of Zin's Reverse Engineering MCP Suite and is meant for local APK analysis.

Who it is for. For mobile app security specialists and developers who take APKs apart.

Good fit when

  • You need to dissect an APK and find vulnerabilities with an agent
  • You need to read an app's decompiled code and manifest
  • You need to rename classes and methods in JADX through an agent

Not a fit when

  • You do not have JADX-GUI with the JADX-AI-MCP plugin
  • You need to analyze a platform other than Android

Example request

Analyze this APK in JADX and find potential vulnerabilities in the manifest and exported components

Limitations

It works in tandem with JADX-GUI and the JADX-AI-MCP plugin; without them the server is useless. It needs Java 11+ and Python 3.10+. Binding to 0.0.0.0 exposes the tools over the network without auth or encryption, and the README advises doing so only on trusted networks or through an SSH tunnel.

How to disable. Stop the jadx_mcp_server process and remove the MCP entry from the agent config; the JADX-GUI plugin can be disabled separately.

MCP

Transport
stdio, http
Authentication
not required

Security check

  • Reads decompiled code and debug info
  • Can expose tools over the network without authentication

README in short

The README presents JADX MCP Server as part of a reverse-engineering suite that automates the agent's link to the JADX-AI-MCP plugin. It shows two connections, client to server and server to the JADX plugin, with separate hosts, ports and tuning flags. It walks scenarios for one machine, Docker or WSL and a remote machine. The README warns separately about the risks of binding to 0.0.0.0 without TLS or auth and suggests a firewall or SSH tunnel.

FAQ

What else is needed besides the server?

JADX-GUI with the JADX-AI-MCP plugin. The server reaches the plugin over its own host and port, localhost:8650 by default.

Can it run on another machine?

Yes, there are host, port, jadx-host and jadx-port flags and an HTTP mode, but open binding without auth is unsafe.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIJADX MCP Server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.