Security

JADX AI MCP: Android app analysis inside JADX

A JADX plugin plus MCP server: agents read decompiled source, Smali, the manifest and resources, follow cross-references, bulk-rename and read debugger state.

Project and installation docs

View project

https://github.com/zinja-coder/jadx-ai-mcp

When you audit an Android app, JADX turns the APK into readable Java, and then you face hundreds of obfuscated classes to read and rename one at a time, hunting for hardcoded secrets and unsafe API calls by hand. JADX AI MCP is a JADX plugin paired with a separate Python MCP server that lets an agent work on the project you have open in the JADX GUI: read code, follow references, rename, comment, with the results showing up in JADX itself. It had about 2.9k stars as of 2026-10-06.

What it does

  • Read code: fetch_current_class reads the selected class; get_class_source, get_method_by_name and get_smali_of_class return Java source and Smali.
  • Manifest and resources: get_android_manifest and get_main_activity_class find entry points; get_strings and get_resource_file read resources.
  • Cross-references: xrefs_to_class, xrefs_to_method and xrefs_to_field show who calls what, with pagination.
  • Deobfuscation: rename_class, rename_method, rename_field, rename_package and rename_variable rename in bulk, and add_comment saves comments with the project.
  • Debugger: debug_get_stack_frames, debug_get_threads and debug_get_variables read live state from the JADX debugger.

Who it’s for

  • Mobile pentesters who need to map an APK’s structure quickly.
  • Researchers examining suspicious Android apps who want a bulk deobfuscation pass first.

Setup

Needs JADX, uv and Python. Install the JADX plugin:

jadx plugins --install "github:zinja-coder:jadx-ai-mcp"

Then install the MCP server and set jadx_mcp_server as the command in your client config:

uv tool install git+https://github.com/zinja-coder/jadx-mcp-server

Alternatively, download the plugin jar and server archive from Releases and start it with uv --directory <path> run jadx_mcp_server.py.

Our take

Most reverse engineering servers target native binaries; this one focuses on Android and fills the mobile-audit gap. The plugin-plus-server design means the agent works on the project in your GUI, and renames and comments land in the JADX project, so you and the model look at the same result. A few cautions: the JADX GUI has to be running, since the plugin talks to the MCP server over local HTTP; renames modify the project, so back up important work; and the README’s sample prompts include things like rewriting code, whose output still needs checking. The same author maintains companion tools such as APKTool MCP. Licensed Apache-2.0.