BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

android-reverse-engineering-claude-skill

Skill Development Usable
Works inClaude Code
Usable Scanned — metadata only

Reduces manual effort in Android security audits and compliance reviews by automating decompilation, bytecode analysis, and vulnerability detection—critical …

A Claude Code skill that automates Android application reverse engineering. It decompiles APK, XAPK, AAB, DEX, JAR, and AAR files (using jadx or Vineflower), extracts HTTP endpoints (Retrofit, OkHttp, Volley, GraphQL, WebSocket), traces call flows, audits security patterns, and runs adaptive dynamic analysis with Frida to bypass runtime protections such as SSL pinning, root detection, and anti-tamper. It generates structured Markdown reports. For security teams and mobile engineers doing app audits.

101 starsUnlicense (commercial OK)FreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Reduces manual effort in Android security audits and compliance reviews by automating decompilation, bytecode analysis, and vulnerability detection—critical for teams managing risk in third-party or legacy mobile apps.

Security teams and mobile engineers conducting vulnerability assessments or app audits on Android applications.

Claude Code Claude Cowork Claude Chat

https://github.com/incogbyte/android-reverse-engineering-cla...

By incogbyte

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
/plugin marketplace add incogbyte/android-reverse-engineering-claude-skill   then   /plugin install android-reverse-engineering@android-reverse-engineering-claude-skill

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Analyze decompiled Android APK code and identify security vulnerabilities in authentication logic
PrerequisitesMandatory: Java JDK 17+ and jadx. Optional (recommended): Vineflower, dex2jar, bundletool, apktool, adb. Dynamic analysis (Phase 7) additionally needs Python 3.8+, adb, frida-server on the device, and frida-tools. The skill ships install scripts (scripts/check-deps.sh, install-dep.sh, setup-frida.sh).CostFree

Trust Signals Auto-scanned

Stars101Contributors2Last updated2026-06-20LicenseUnlicense (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-17 · scanner v1

Community Pulse New

No community discussions found yet. This doesn't mean the tool isn't good — it may be new or serve a niche use case.

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

Scored from trust signals (evidence-eval-v1): 32 GitHub stars; contributors unknown; last commit 1d ago; license Unlicense.

Things to check

  • Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
2/5
Reliability
3/5
Security
3/5
Overall score2.75 / 5.00 UsableEvaluatedJun 2026
Scored from trust signals (evidence-eval-v1): 32 GitHub stars; contributors unknown; last commit 1d ago; license Unlicense.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →