android-reverse-engineering-claude-skill
Reduces manual effort in Android security audits and compliance reviews by automating decompilation, bytecode analysis, and vulnerability detection—critical …
A Claude Code skill that automates Android application reverse engineering. It decompiles APK, XAPK, AAB, DEX, JAR, and AAR files (using jadx or Vineflower), extracts HTTP endpoints (Retrofit, OkHttp, Volley, GraphQL, WebSocket), traces call flows, audits security patterns, and runs adaptive dynamic analysis with Frida to bypass runtime protections such as SSL pinning, root detection, and anti-tamper. It generates structured Markdown reports. For security teams and mobile engineers doing app audits.
- Ask Claude to analyze decompiled Android APK code and identify security vulnerabilities in authentication logic.
- Automate extraction and documentation of API endpoints discovered during Android app reverse engineering analysis.
- Generate detailed reports on third-party library dependencies found in reverse-engineered Android applications.
Reduces manual effort in Android security audits and compliance reviews by automating decompilation, bytecode analysis, and vulnerability detection—critical for teams managing risk in third-party or legacy mobile apps.
Security teams and mobile engineers conducting vulnerability assessments or app audits on Android applications.
https://github.com/incogbyte/android-reverse-engineering-cla...
By incogbyte
How to Get It
/plugin marketplace add incogbyte/android-reverse-engineering-claude-skill then /plugin install android-reverse-engineering@android-reverse-engineering-claude-skill
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
After installing, paste this into Claude:
Analyze decompiled Android APK code and identify security vulnerabilities in authentication logic
Trust Signals Auto-scanned
Community Pulse New
No community discussions found yet. This doesn't mean the tool isn't good — it may be new or serve a niche use case.
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
Scored from trust signals (evidence-eval-v1): 32 GitHub stars; contributors unknown; last commit 1d ago; license Unlicense.
Things to check
- Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
Scored from trust signals (evidence-eval-v1): 32 GitHub stars; contributors unknown; last commit 1d ago; license Unlicense.