JADX AI MCP: Android app analysis inside JADX
A JADX plugin plus MCP server: agents read decompiled source, Smali, the manifest and resources, follow cross-references, bulk-rename and read debugger state.
Project and installation docs
View projecthttps://github.com/zinja-coder/jadx-ai-mcp
When you audit an Android app, JADX turns the APK into readable Java, and then you face hundreds of obfuscated classes to read and rename one at a time, hunting for hardcoded secrets and unsafe API calls by hand. JADX AI MCP is a JADX plugin paired with a separate Python MCP server that lets an agent work on the project you have open in the JADX GUI: read code, follow references, rename, comment, with the results showing up in JADX itself. It had about 2.9k stars as of 2026-10-06.
What it does
- Read code:
fetch_current_classreads the selected class;get_class_source,get_method_by_nameandget_smali_of_classreturn Java source and Smali. - Manifest and resources:
get_android_manifestandget_main_activity_classfind entry points;get_stringsandget_resource_fileread resources. - Cross-references:
xrefs_to_class,xrefs_to_methodandxrefs_to_fieldshow who calls what, with pagination. - Deobfuscation:
rename_class,rename_method,rename_field,rename_packageandrename_variablerename in bulk, andadd_commentsaves comments with the project. - Debugger:
debug_get_stack_frames,debug_get_threadsanddebug_get_variablesread live state from the JADX debugger.
Who it’s for
- Mobile pentesters who need to map an APK’s structure quickly.
- Researchers examining suspicious Android apps who want a bulk deobfuscation pass first.
Setup
Needs JADX, uv and Python. Install the JADX plugin:
jadx plugins --install "github:zinja-coder:jadx-ai-mcp"
Then install the MCP server and set jadx_mcp_server as the command in your client config:
uv tool install git+https://github.com/zinja-coder/jadx-mcp-server
Alternatively, download the plugin jar and server archive from Releases and start it with uv --directory <path> run jadx_mcp_server.py.
Our take
Most reverse engineering servers target native binaries; this one focuses on Android and fills the mobile-audit gap. The plugin-plus-server design means the agent works on the project in your GUI, and renames and comments land in the JADX project, so you and the model look at the same result. A few cautions: the JADX GUI has to be running, since the plugin talks to the MCP server over local HTTP; renames modify the project, so back up important work; and the README’s sample prompts include things like rewriting code, whose output still needs checking. The same author maintains companion tools such as APKTool MCP. Licensed Apache-2.0.