Atlas / MCP servers / lm060719 / reconbridge

reconbridgeCAUTION

mcp/lm060719/reconbridge

通用逆向分析 KernelSU 模块:手机侧只做原子能力,智能全在 PC 侧(Claude Code + MCP)。仅限授权安全研究与教育用途。

Verdict
CAUTION
Grade
C
Trust score
70 /100
Exposed tools
79 68r · 8w · 3d
Transport
streamable-http
License
MIT
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

中文 | English

QQ交流群:1076516767

在 Android(KernelSU root)设备上运行的通用逆向能力后端。手机侧只做原子能力(拉包 / 读文件 / 列 so / 注入 hook),所有智能(定位函数、生成 hook、分析结果)都在 PC 侧(Claude Code + MCP)完成。

📌 给 AI agent / 新会话的一页纸速查:`AGENTS_QUICKSTART.md` —— 全部 MCP 工具签名、M5 用法、典型工作流、高频坑,读一篇即可上手。
进度:M1 / M2 / M3 / M4 / M5 均已完成并真机验证(Xiaomi SM8750 / Android 16 / KernelSU + ZygiskNext + LSPosed)。 - M5:通用 Java trace + 实时篡改与 Action Pipeline(LSPosed 模块,trace_java / patch_java)—— 见 m5/README.md、m5/JAVA_HOOK_PROTOCOL.md。
## ⚠️ 免责声明 / Disclaimer 本项目仅供已获授权的安全研究、CTF、逆向学习与防御性研究使用。使用者须对自己所分析的设备与应用拥有合法授权(自有设备、明确授权的渗透测试、公开的教学样本等)。 禁止将本项目用于未经授权的破解、绕过版权/许可保护、窃取数据、攻击第三方系统或任何违反当地法律的行为。作者不对任何滥用或由此产生的后果负责。继续使用即表示你已理解并接受以上条款。 For authorized security research and educational use only. You are responsible for having proper authorization for any device/app you analyze.

快速开始

PC 端(一键装 MCP 工具)

支持两种 AI 客户端:Claude Code(写 ~/.claude.json)与 ChatGPT Codex(写 ~/.codex/config.toml)。默认 both=自动探测:只注册进「已安装」的客户端(Claude 看 ~/.claude.json/~/.claude/,Codex 看 ~/.codex/),没装的那个自动跳过、不建目录;两个都没检测到就只装工具本体、不写任何配置(等你装好客户端再重跑注册,或用 --target 强制写入)。另需 adb(Android platform-tools,连真机用)。

推荐:一行在线安装(Windows,无需 clone 仓库、无需 Python)

irm https://github.com/lm060719/reconbridge/releases/latest/download/install.ps1 | iex

自动下载打包好的 MCP exe、解压到 %LOCALAPPDATA%\ReconBridge\、注册进客户端用户级配置,并铺一个 reconbridge skill(逆向类任务时新会话自动加载工作流):

  • Claude Code → ~/.claude.json 的 mcpServers.reconbridge + skill 到 ~/.claude/skills/
  • ChatGPT Codex → ~/.codex/config.toml 的 [mcp_servers.reconbridge] + skill 到 ~/.codex/skills/

装完重启对应客户端即用。

exe 内含 MCP server 与核心依赖(含 androguard);jadx / Ghidra 仍为可选反编译工具,解压到 %LOCALAPPDATA%\ReconBridge\tools\ 即被自动探测(toolchain_status 查看)。 强制只装一个(跳过探测):先设 $env:RB_TARGET="codex"(或 `"cl
Read from source at commit 3d4f7bbeeff0OBSERVED · 2026-10-09
02

Exposed tools (79)

68 read · 8 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_scenario_divergenceread从 A/B 调用图场景首次分叉自动定位源码条件。
capture_call_graph_scenarioread围绕同一目标方法采集一次可做 A/B 差分的真实调用图场景。
capture_divergence_proberead采集 A/B 首次分叉条件的一个运行时值探针。
capture_scenarioread记录一个「场景」的命中时间线,存盘供 diff_scenarios 比对(P2)。
close_investigationread结束分析会话;默认同时清理该目标包由分析过程留下的 hook。
collect_eventsread连 hook 事件流(SSE)收集命中事件(参数/返回值/调用栈/dump 通知)。
compare_divergence_probesread比较已经采集的 A/B 条件探针值,并判断是否与源码 true/false 分支方向一致。
compare_root_cause_hypothesisread重新比较已采集的根因假设实验,并返回验证前/后的根因排名变化。
compare_value_lineage_runtimeread比较已采集的 A/B Runtime Value Lineage,找最早稳定值差异。
decompile_apkread用 jadx 反编译 apk 到 Java 源码目录,返回反编译输出目录。
device_statusread探测手机守护进程状态与连接方式,返回 /health 及当前传输配置。用于排查连不上的问题。
dexkit_searchread用 DexKit 在 apk 的 dex 里做链式查询(定位类/方法/字段)。
diff_call_graph_scenariosread比较两个调用图场景,直接找共同链路、仅 A/仅 B、首次分叉和共享边耗时差。
diff_scenariosread比对两个已捕获场景,给出**方法级差异**(P2)——直接回答
dump_dexread通用内存 dex dump(M4):hook dex 加载入口,把内存中已解密的 dex 回传落盘。
evidence_graphread查看分析会话证据图。
explain_evidenceread解释某个关键词/类/方法/字段当前已有的证据链。
ghidra_analyzeread用 Ghidra headless 分析 .so,返回导出表 / 导入表 / 字符串 / 函数列表 / 可疑函数。
hermes_decompileread反编译 React Native Hermes 字节码 .hbc(通常在 apk 的 assets/index.android.bundle)。
inspect_call_graphread递归展开一个 Java 方法的静态调用图,并叠加会话里已有的 runtime 命中证据。
inspect_condition_originread从已确认的 A/B 分叉条件继续追踪字段 writer/readers 或条件方法返回值来源。
inspect_methodread展开一个已知 Java 方法:调用者、被调用方法、关联字符串、同类字段和 JADX 源码上下文。
inspect_value_lineageread跨方法递归追踪已确认 A/B 分叉条件的值来源。
investigateread执行一轮自动调查:目标解析 → DEX 索引 → 多词候选排序 → 可选运行时验证 → 方法上下文 → 证据汇总。
investigation_statusread查看分析会话当前绑定的 APK、JADX 目录、发现记录和运行时游标。
list_artifactsread列出 PC 工作目录里某包(或全部包)已产出的物件:已拉的 apk、已拉的 native so、
list_call_graph_scenariosread列出当前 Investigation 会话保存的调用图动态场景。
list_dumpsread列出已落盘的内存 dump(用 read_remote_file 或 pull 取回)。
list_hooksread列出当前磁盘上的期望 hook 配置。
list_packagesread列出设备上已安装应用(包名 / versionCode / 安装路径 / 是否系统应用)。
list_scenariosread列出已捕获的场景(work/scenarios/ 下)及各自命中数。
open_targetread开启一个持久化分析会话,并自动绑定该包现有 APK/JADX/so 产物。
patch_javawrite实时篡改与高级动作流水线(M5 v2):改参数 / 改返回值 / 字段深层路径篡改 / 条件执行 / 副作用动作。
post_hookwrite下发原始 hook 配置(M3 native / M5 Java)。
prepare_indexread预热当前目标的 DEX SQLite 索引;首次解析 APK,之后所有新查询直接查数据库。
prepare_targetread为会话准备 JADX 源码。已有反编译产物时直接复用,否则只反编译当前主 APK。
proc_inforead读取 /proc/<pid>/<what>,what ∈ maps|status|cmdline。
pull_apkread拉取某应用的**全部** apk(base.apk + 所有 split_config.*.apk)到 PC 工作目录。
pull_libsread拉取某应用 lib 目录下已落地的 native .so 到 PC 工作目录。
rank_candidatesread从字符串 xref、方法名、类名与 Evidence Graph 中生成可解释的候选方法排序。
rank_root_causesread综合静态来源、Runtime Lineage 与 writer 变化,对根因节点做可解释排序。
read_remote_filereadroot 读取设备上任意文件(流式)。
recent_eventsread取守护进程环形缓冲里**最近的命中事件**(事后采集,P0-1)——无需正连着 SSE。
remote_shellread在设备上以 root 执行**白名单内**命令。优先用 argv 数组(安全,无需引号)。
runtime_activity_actionread在当前 Activity 上直接执行现有 Action Pipeline,不创建 Java Hook。
runtime_context_statusread实时读取目标进程当前 Application/Context/Activity/Lifecycle 状态。
runtime_event_emitread从 PC 直接向在线 M5 Runtime EventBus 发事件。
runtime_hook_statusread查看运行中 M5 Runtime 的真实状态。
runtime_program_approveread持久批准一个 Program 的 ask 权限;跨 revision 有效,deny 仍不可覆盖。
runtime_program_disablewrite禁用 Runtime Program;只移除该 Program 的 targets,并执行 state_cleanup。
runtime_program_enablewrite启用已安装 Runtime Program,并 live reconcile + 应用 state_init。
runtime_program_exportread把设备上的 Runtime Program 导出为 Ed25519 签名 .rbprog.json 包。
runtime_program_importwrite验签后把 .rbprog.json 安装/替换到目标包。
runtime_program_installwrite安装一个命名 Runtime Program。
runtime_program_policy_setwrite设置设备端 Program 权限策略;策略收紧会立即禁用不再允许的在线 Program。
runtime_program_policy_statusread查看设备端 Runtime Program 权限策略、批准和每个 Program 的有效状态。
runtime_program_replaceread替换已安装 Runtime Program,并把旧版本压入最多 5 层 rollback 历史。
runtime_program_revoke_approvaldestructive撤销 Program 的持久权限批准;若当前运行依赖该批准,会立即 live disable/cleanup。
runtime_program_rollbackread回滚 Runtime Program 到上一份 manifest;revision 继续单调递增。
runtime_program_signer_statusread查看 PC 本地 Runtime Program signer 与已信任公钥;绝不返回私钥。
runtime_program_statusread查看一个包已持久化的 Runtime Program、版本、启用状态和 rollback 深度。
runtime_program_trust_signerread把一个 Ed25519 Runtime Program signer 公钥加入本机信任列表。
runtime_program_verify_packageread离线校验 Runtime Program Package 的 SHA-256、Ed25519 签名、权限与包作用域。
runtime_state_appendread向在线 Runtime State 列表追加一个 JSON 值。
runtime_state_cleardestructive清空在线 Runtime 的一个 State scope;hook scope 需指定 hook_id。
runtime_state_getread直接读取在线 M5 Runtime State,不创建临时 Hook。
runtime_state_incrementread原子增加在线 Runtime State 数值;不存在时从 0 开始。
runtime_state_removedestructive删除在线 M5 Runtime State 的一个 key,并返回旧值。
runtime_state_setwrite直接写入在线 M5 Runtime State;支持 JSON 标量、对象和数组。
search_targetread在当前分析目标中统一搜索源码 / 字符串 / 类 / 方法 / 字段。
toolchain_statusread检查 PC 本地反编译工具链(jadx / DexKit / Ghidra / Hermes)是否就绪及其路径。
trace_javaread一步下发一个 Java 方法 trace 并采集命中(M5)。
trace_targetread在当前会话目标上临时 trace 一个 Java 方法,命中即返回,并默认自动卸载 Hook。
unhookread移除某包 hook;运行中的 M5 Tracer 会立即 live unhook。
verify_call_pathread一次性动态验证一条代表业务路径,并按方法入口时间还原真实执行顺序。
verify_candidatesread把排名靠前的多个 Java 候选一次性装 Hook,并在一个共享窗口里验证谁真实命中。
verify_condition_writerread动态验证字段 writer 是否真的在一次行为中改变已确认的分叉条件字段。
verify_root_cause_hypothesisread对一个方法根因候选执行最小 A/B 输入输出实验。
verify_value_lineageread一次性动态验证一条 Value Lineage 的方法返回顺序与最终字段变化。
03

Trust audit

CAUTIONgrade C · trust 70/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
m3/prebuilt/libdobby_x86_64.so
libdobby_x86_64.so
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
m3/prebuilt/libshadowhook.so
libshadowhook.so
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
m3/prebuilt/libshadowhook_nothing.so
libshadowhook_nothing.so
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
m5/tracer/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
module/system_lib64_arm64/libshadowhook.so
libshadowhook.so
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
pc/reconbridge_mcp/client.py:175
self._base = f"http://127.0.0.1:{port}"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
build.ps1:1
# ReconBridge M1 构建脚本(Windows / PowerShell)
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
build_exe.ps1:1
# ReconBridge —— 把 PC 侧 MCP server 打成 onedir exe 并压成发布 zip(Windows / PowerShell)。
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
m3/build_dobby_x86_64.ps1:1
# 构建 m3\prebuilt\libdobby_x86_64.so ——
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
runtime_program_revoke_approval, runtime_state_clear, runtime_state_remove
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp.json.example
.mcp.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
pc/reconbridge_mcp/evidence.py:21
return hashlib.sha1(value.encode("utf-8", errors="replace")).hexdigest()[:16]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
pc/reconbridge_mcp/external.py:519
String[] KW = {"encrypt","decrypt","sign","md5","sha","aes","des","rc4","hmac","crypt",
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
pc/reconbridge_mcp/value_lineage.py:19
return hashlib.sha1(value.encode("utf-8", errors="replace")).hexdigest()[:16]
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
pc/test_mcp_e2e.py:68
"../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
pc/test_mcp_e2e.py:86
"../../etc/passwd",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
AGENTS_QUICKSTART.md:37
**手机 AI 本地直连**:在 AI 软件中添加 MCP 配置时选择 `Streamable HTTP`,URL 填 `http://127.0.0.1:8790/mcp`。必须在「自定义请求头 / Custom Headers」中新增请求头:名称填 `X-Token`,值填 KernelSU WebUI 中显示的完整 token;不要把 token 填进 URL、MCP 名称或请求体。手机本地
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:124
URL:http://127.0.0.1:8790/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_en.md:120
URL: http://127.0.0.1:8790/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
module/webroot/index.html:283
$("mcpUrlVal").textContent = mcpOn ? `http://127.0.0.1:${info.mcp_port}/mcp` : "(MCP 关闭)";
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
pc/reconbridge_mcp/program_package.py:90
return base64.b64decode(
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
pc/requirements.txt
mcp, httpx, androguard, pytest, pytest-asyncio, cryptography
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:258
curl -H "X-Token: TOKEN" -X POST "http://IP:8787/shell" \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README_en.md:254
curl -H "X-Token: TOKEN" -X POST "http://IP:8787/shell" \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
m3/README.md:89
curl -H "X-Token: $T" -X POST http://IP:8787/hook -d '{
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 3d4f7bbeeff0full audit observations/trust-audit/mcp-server/lm060719__reconbridge.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-093d4f7bbeeff0CAUTIONC70first audit
05

Questions

What is the reconbridge MCP server?

通用逆向分析 KernelSU 模块:手机侧只做原子能力,智能全在 PC 侧(Claude Code + MCP)。仅限授权安全研究与教育用途。

What tools does reconbridge expose?

79 in total: 68 read-only, 8 that write, and 3 that can delete or overwrite (runtime_program_revoke_approval, runtime_state_clear, runtime_state_remove). Every one is listed on this page with its risk.

Is reconbridge safe to connect to an agent?

With care. The audit graded it C (70/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does reconbridge need?

It reads RECONBRIDGE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does reconbridge run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (3d4f7bbeeff0), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement