reconbridgeCAUTION
通用逆向分析 KernelSU 模块:手机侧只做原子能力,智能全在 PC 侧(Claude Code + MCP)。仅限授权安全研究与教育用途。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
中文 | English
QQ交流群:1076516767
在 Android(KernelSU root)设备上运行的通用逆向能力后端。手机侧只做原子能力(拉包 / 读文件 / 列 so / 注入 hook),所有智能(定位函数、生成 hook、分析结果)都在 PC 侧(Claude Code + MCP)完成。
📌 给 AI agent / 新会话的一页纸速查:`AGENTS_QUICKSTART.md` —— 全部 MCP 工具签名、M5 用法、典型工作流、高频坑,读一篇即可上手。
进度:M1 / M2 / M3 / M4 / M5 均已完成并真机验证(Xiaomi SM8750 / Android 16 / KernelSU + ZygiskNext + LSPosed)。 - M5:通用 Java trace + 实时篡改与 Action Pipeline(LSPosed 模块,trace_java/patch_java)—— 见m5/README.md、m5/JAVA_HOOK_PROTOCOL.md。
## ⚠️ 免责声明 / Disclaimer 本项目仅供已获授权的安全研究、CTF、逆向学习与防御性研究使用。使用者须对自己所分析的设备与应用拥有合法授权(自有设备、明确授权的渗透测试、公开的教学样本等)。 禁止将本项目用于未经授权的破解、绕过版权/许可保护、窃取数据、攻击第三方系统或任何违反当地法律的行为。作者不对任何滥用或由此产生的后果负责。继续使用即表示你已理解并接受以上条款。 For authorized security research and educational use only. You are responsible for having proper authorization for any device/app you analyze.
快速开始
PC 端(一键装 MCP 工具)
支持两种 AI 客户端:Claude Code(写 ~/.claude.json)与 ChatGPT Codex(写 ~/.codex/config.toml)。默认 both=自动探测:只注册进「已安装」的客户端(Claude 看 ~/.claude.json/~/.claude/,Codex 看 ~/.codex/),没装的那个自动跳过、不建目录;两个都没检测到就只装工具本体、不写任何配置(等你装好客户端再重跑注册,或用 --target 强制写入)。另需 adb(Android platform-tools,连真机用)。
推荐:一行在线安装(Windows,无需 clone 仓库、无需 Python)
irm https://github.com/lm060719/reconbridge/releases/latest/download/install.ps1 | iex
自动下载打包好的 MCP exe、解压到 %LOCALAPPDATA%\ReconBridge\、注册进客户端用户级配置,并铺一个 reconbridge skill(逆向类任务时新会话自动加载工作流):
- Claude Code →
~/.claude.json的mcpServers.reconbridge+ skill 到~/.claude/skills/ - ChatGPT Codex →
~/.codex/config.toml的[mcp_servers.reconbridge]+ skill 到~/.codex/skills/
装完重启对应客户端即用。
exe 内含 MCP server 与核心依赖(含 androguard);jadx / Ghidra 仍为可选反编译工具,解压到%LOCALAPPDATA%\ReconBridge\tools\即被自动探测(toolchain_status查看)。 强制只装一个(跳过探测):先设$env:RB_TARGET="codex"(或 `"cl
3d4f7bbeeff0OBSERVED · 2026-10-09Exposed tools (79)
68 read · 8 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_scenario_divergence | read | 从 A/B 调用图场景首次分叉自动定位源码条件。 |
capture_call_graph_scenario | read | 围绕同一目标方法采集一次可做 A/B 差分的真实调用图场景。 |
capture_divergence_probe | read | 采集 A/B 首次分叉条件的一个运行时值探针。 |
capture_scenario | read | 记录一个「场景」的命中时间线,存盘供 diff_scenarios 比对(P2)。 |
close_investigation | read | 结束分析会话;默认同时清理该目标包由分析过程留下的 hook。 |
collect_events | read | 连 hook 事件流(SSE)收集命中事件(参数/返回值/调用栈/dump 通知)。 |
compare_divergence_probes | read | 比较已经采集的 A/B 条件探针值,并判断是否与源码 true/false 分支方向一致。 |
compare_root_cause_hypothesis | read | 重新比较已采集的根因假设实验,并返回验证前/后的根因排名变化。 |
compare_value_lineage_runtime | read | 比较已采集的 A/B Runtime Value Lineage,找最早稳定值差异。 |
decompile_apk | read | 用 jadx 反编译 apk 到 Java 源码目录,返回反编译输出目录。 |
device_status | read | 探测手机守护进程状态与连接方式,返回 /health 及当前传输配置。用于排查连不上的问题。 |
dexkit_search | read | 用 DexKit 在 apk 的 dex 里做链式查询(定位类/方法/字段)。 |
diff_call_graph_scenarios | read | 比较两个调用图场景,直接找共同链路、仅 A/仅 B、首次分叉和共享边耗时差。 |
diff_scenarios | read | 比对两个已捕获场景,给出**方法级差异**(P2)——直接回答 |
dump_dex | read | 通用内存 dex dump(M4):hook dex 加载入口,把内存中已解密的 dex 回传落盘。 |
evidence_graph | read | 查看分析会话证据图。 |
explain_evidence | read | 解释某个关键词/类/方法/字段当前已有的证据链。 |
ghidra_analyze | read | 用 Ghidra headless 分析 .so,返回导出表 / 导入表 / 字符串 / 函数列表 / 可疑函数。 |
hermes_decompile | read | 反编译 React Native Hermes 字节码 .hbc(通常在 apk 的 assets/index.android.bundle)。 |
inspect_call_graph | read | 递归展开一个 Java 方法的静态调用图,并叠加会话里已有的 runtime 命中证据。 |
inspect_condition_origin | read | 从已确认的 A/B 分叉条件继续追踪字段 writer/readers 或条件方法返回值来源。 |
inspect_method | read | 展开一个已知 Java 方法:调用者、被调用方法、关联字符串、同类字段和 JADX 源码上下文。 |
inspect_value_lineage | read | 跨方法递归追踪已确认 A/B 分叉条件的值来源。 |
investigate | read | 执行一轮自动调查:目标解析 → DEX 索引 → 多词候选排序 → 可选运行时验证 → 方法上下文 → 证据汇总。 |
investigation_status | read | 查看分析会话当前绑定的 APK、JADX 目录、发现记录和运行时游标。 |
list_artifacts | read | 列出 PC 工作目录里某包(或全部包)已产出的物件:已拉的 apk、已拉的 native so、 |
list_call_graph_scenarios | read | 列出当前 Investigation 会话保存的调用图动态场景。 |
list_dumps | read | 列出已落盘的内存 dump(用 read_remote_file 或 pull 取回)。 |
list_hooks | read | 列出当前磁盘上的期望 hook 配置。 |
list_packages | read | 列出设备上已安装应用(包名 / versionCode / 安装路径 / 是否系统应用)。 |
list_scenarios | read | 列出已捕获的场景(work/scenarios/ 下)及各自命中数。 |
open_target | read | 开启一个持久化分析会话,并自动绑定该包现有 APK/JADX/so 产物。 |
patch_java | write | 实时篡改与高级动作流水线(M5 v2):改参数 / 改返回值 / 字段深层路径篡改 / 条件执行 / 副作用动作。 |
post_hook | write | 下发原始 hook 配置(M3 native / M5 Java)。 |
prepare_index | read | 预热当前目标的 DEX SQLite 索引;首次解析 APK,之后所有新查询直接查数据库。 |
prepare_target | read | 为会话准备 JADX 源码。已有反编译产物时直接复用,否则只反编译当前主 APK。 |
proc_info | read | 读取 /proc/<pid>/<what>,what ∈ maps|status|cmdline。 |
pull_apk | read | 拉取某应用的**全部** apk(base.apk + 所有 split_config.*.apk)到 PC 工作目录。 |
pull_libs | read | 拉取某应用 lib 目录下已落地的 native .so 到 PC 工作目录。 |
rank_candidates | read | 从字符串 xref、方法名、类名与 Evidence Graph 中生成可解释的候选方法排序。 |
rank_root_causes | read | 综合静态来源、Runtime Lineage 与 writer 变化,对根因节点做可解释排序。 |
read_remote_file | read | root 读取设备上任意文件(流式)。 |
recent_events | read | 取守护进程环形缓冲里**最近的命中事件**(事后采集,P0-1)——无需正连着 SSE。 |
remote_shell | read | 在设备上以 root 执行**白名单内**命令。优先用 argv 数组(安全,无需引号)。 |
runtime_activity_action | read | 在当前 Activity 上直接执行现有 Action Pipeline,不创建 Java Hook。 |
runtime_context_status | read | 实时读取目标进程当前 Application/Context/Activity/Lifecycle 状态。 |
runtime_event_emit | read | 从 PC 直接向在线 M5 Runtime EventBus 发事件。 |
runtime_hook_status | read | 查看运行中 M5 Runtime 的真实状态。 |
runtime_program_approve | read | 持久批准一个 Program 的 ask 权限;跨 revision 有效,deny 仍不可覆盖。 |
runtime_program_disable | write | 禁用 Runtime Program;只移除该 Program 的 targets,并执行 state_cleanup。 |
runtime_program_enable | write | 启用已安装 Runtime Program,并 live reconcile + 应用 state_init。 |
runtime_program_export | read | 把设备上的 Runtime Program 导出为 Ed25519 签名 .rbprog.json 包。 |
runtime_program_import | write | 验签后把 .rbprog.json 安装/替换到目标包。 |
runtime_program_install | write | 安装一个命名 Runtime Program。 |
runtime_program_policy_set | write | 设置设备端 Program 权限策略;策略收紧会立即禁用不再允许的在线 Program。 |
runtime_program_policy_status | read | 查看设备端 Runtime Program 权限策略、批准和每个 Program 的有效状态。 |
runtime_program_replace | read | 替换已安装 Runtime Program,并把旧版本压入最多 5 层 rollback 历史。 |
runtime_program_revoke_approval | destructive | 撤销 Program 的持久权限批准;若当前运行依赖该批准,会立即 live disable/cleanup。 |
runtime_program_rollback | read | 回滚 Runtime Program 到上一份 manifest;revision 继续单调递增。 |
runtime_program_signer_status | read | 查看 PC 本地 Runtime Program signer 与已信任公钥;绝不返回私钥。 |
runtime_program_status | read | 查看一个包已持久化的 Runtime Program、版本、启用状态和 rollback 深度。 |
runtime_program_trust_signer | read | 把一个 Ed25519 Runtime Program signer 公钥加入本机信任列表。 |
runtime_program_verify_package | read | 离线校验 Runtime Program Package 的 SHA-256、Ed25519 签名、权限与包作用域。 |
runtime_state_append | read | 向在线 Runtime State 列表追加一个 JSON 值。 |
runtime_state_clear | destructive | 清空在线 Runtime 的一个 State scope;hook scope 需指定 hook_id。 |
runtime_state_get | read | 直接读取在线 M5 Runtime State,不创建临时 Hook。 |
runtime_state_increment | read | 原子增加在线 Runtime State 数值;不存在时从 0 开始。 |
runtime_state_remove | destructive | 删除在线 M5 Runtime State 的一个 key,并返回旧值。 |
runtime_state_set | write | 直接写入在线 M5 Runtime State;支持 JSON 标量、对象和数组。 |
search_target | read | 在当前分析目标中统一搜索源码 / 字符串 / 类 / 方法 / 字段。 |
toolchain_status | read | 检查 PC 本地反编译工具链(jadx / DexKit / Ghidra / Hermes)是否就绪及其路径。 |
trace_java | read | 一步下发一个 Java 方法 trace 并采集命中(M5)。 |
trace_target | read | 在当前会话目标上临时 trace 一个 Java 方法,命中即返回,并默认自动卸载 Hook。 |
unhook | read | 移除某包 hook;运行中的 M5 Tracer 会立即 live unhook。 |
verify_call_path | read | 一次性动态验证一条代表业务路径,并按方法入口时间还原真实执行顺序。 |
verify_candidates | read | 把排名靠前的多个 Java 候选一次性装 Hook,并在一个共享窗口里验证谁真实命中。 |
verify_condition_writer | read | 动态验证字段 writer 是否真的在一次行为中改变已确认的分叉条件字段。 |
verify_root_cause_hypothesis | read | 对一个方法根因候选执行最小 A/B 输入输出实验。 |
verify_value_lineage | read | 一次性动态验证一条 Value Lineage 的方法返回顺序与最终字段变化。 |
Trust audit
CAUTIONgrade C · trust 70/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
libdobby_x86_64.so
libshadowhook.so
libshadowhook_nothing.so
gradle-wrapper.jar
libshadowhook.so
self._base = f"http://127.0.0.1:{port}"# ReconBridge M1 构建脚本(Windows / PowerShell)
# ReconBridge —— 把 PC 侧 MCP server 打成 onedir exe 并压成发布 zip(Windows / PowerShell)。
# 构建 m3\prebuilt\libdobby_x86_64.so ——
runtime_program_revoke_approval, runtime_state_clear, runtime_state_remove
.mcp.json.example
return hashlib.sha1(value.encode("utf-8", errors="replace")).hexdigest()[:16]String[] KW = {"encrypt","decrypt","sign","md5","sha","aes","des","rc4","hmac","crypt",return hashlib.sha1(value.encode("utf-8", errors="replace")).hexdigest()[:16]"../../etc/passwd",
"../../etc/passwd",
**手机 AI 本地直连**:在 AI 软件中添加 MCP 配置时选择 `Streamable HTTP`,URL 填 `http://127.0.0.1:8790/mcp`。必须在「自定义请求头 / Custom Headers」中新增请求头:名称填 `X-Token`,值填 KernelSU WebUI 中显示的完整 token;不要把 token 填进 URL、MCP 名称或请求体。手机本地
URL:http://127.0.0.1:8790/mcp
URL: http://127.0.0.1:8790/mcp
$("mcpUrlVal").textContent = mcpOn ? `http://127.0.0.1:${info.mcp_port}/mcp` : "(MCP 关闭)";return base64.b64decode(
mcp, httpx, androguard, pytest, pytest-asyncio, cryptography
curl -H "X-Token: TOKEN" -X POST "http://IP:8787/shell" \
curl -H "X-Token: TOKEN" -X POST "http://IP:8787/shell" \
curl -H "X-Token: $T" -X POST http://IP:8787/hook -d '{Gates applied: no_behavioural_pass.
3d4f7bbeeff0full audit observations/trust-audit/mcp-server/lm060719__reconbridge.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 3d4f7bbeeff0 | CAUTION | C | 70 | first audit |
Questions
What is the reconbridge MCP server?
通用逆向分析 KernelSU 模块:手机侧只做原子能力,智能全在 PC 侧(Claude Code + MCP)。仅限授权安全研究与教育用途。
What tools does reconbridge expose?
79 in total: 68 read-only, 8 that write, and 3 that can delete or overwrite (runtime_program_revoke_approval, runtime_state_clear, runtime_state_remove). Every one is listed on this page with its risk.
Is reconbridge safe to connect to an agent?
With care. The audit graded it C (70/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does reconbridge need?
It reads RECONBRIDGE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does reconbridge run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (3d4f7bbeeff0), read on 2026-10-09. The repository is watched and re-audited when it changes.