apktool-mcp-server

MCP.Pizza Chef: zinja-coder

Apktool unpacks an Android installer file back into its manifest, images, text and low-level code. This project puts that unpacked folder in front of your assistant, which can then list and read the files, search for hardcoded passwords or web addresses, flag risky permissions, edit a file and rebuild the app. It is aimed at security research and reverse engineering, is documented for Claude Desktop, and the author openly describes it as early-stage work with rough edges.

Coding

Use This MCP server To

See which permissions an Android app asks for Search an unpacked app for hardcoded passwords Find screens left open to other apps Read the code behind one particular screen Rebuild the app after making a change Get a plain-language summary of what an app does

README

apktool-mcp-server (Part of Zin's Reverse Engineering MCP Suite)

⚡ Fully automated MCP server built on top of apktool to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.

GitHub contributors apktool-mcp-server GitHub all releases GitHub release (latest by SemVer) Latest release Python 3.10+ License

banner

Image generated using AI tools.


apktool-mcp-server FAQ

Which app does this work in?
Claude Desktop is documented, and the author also shows it driving a local model through their own companion client.
What do I need installed first?
Apktool itself, plus Python and the uv tool used to run the server.
Can I use this to check whether an app is spying on me?
Partly — you can inspect permissions, web addresses and code, but reading the result still takes judgement.
Is it stable?
The author labels it early-stage and warns about bugs and crashes, so expect rough edges.
Is taking an app apart allowed?
That depends on the app's licence and your local law; it is built for security research on apps you have permission to test.
Does it need a key or a paid account?
No. Everything runs locally on your own machine.