Atlas / MCP servers / mrmike / Android Source Explorer

Android Source ExplorerSAFE

mcp/mrmike/android-source-explorer

MCP server for exploring AOSP internals and Jetpack libraries

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
11 11r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
101
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP server for exploring AOSP internals and Jetpack libraries.

Purpose

When building Android applications, AI tools often rely on outdated training data or incomplete summaries of the Android Framework. This MCP server provides on-demand, precise access to the actual source code (AOSP and AndroidX), enabling the AI to understand complex framework internals like the Activity lifecycle, ViewModel restoration, or Compose internals directly from the truth.

Installation & Setup

Prerequisites

  • uv (Recommended) or Python 3.11+
  • Git

Recommended Installation (via uv)

The easiest way to install and keep android-source-explorer up to date is using uv. It handles dependencies (including native ones like Tree-sitter and Cryptography) reliably across platforms.

uv tool install git+https://github.com/mrmike/android-source-explorer-mcp

This will make the android-source-explorer command available globally in your PATH.

Initial Sync

After installation, you need to perform an initial sync to fetch the Android source code:

# Sync API 36 (Android 16) and common AndroidX packages
android-source-explorer sync --api-level 36 --androidx "compose,lifecycle,activity"

# (Optional) Download LSP servers for cross-file features
android-source-explorer sync --lsp

Check sync status:

android-source-explorer status

Keeping Sources Up-to-Date

To check for and download the latest available Android Framework revisions (AOSP tags) and newer stable versions of your synced AndroidX packages, run:

# Update all synced framework APIs and AndroidX packages, then rebuild the index
android-source-explorer update

# (Optional) Clean up older versions of updated AndroidX packages
android-source-explorer update --clean

# Update only a spe
Read from source at commit c326376171f9OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add android-source-explorer -- uvx android-source-explorer
claude-desktop
{
  "mcpServers": {
    "android-source-explorer": {
      "command": "uvx",
      "args": [
        "android-source-explorer"
      ]
    }
  }
}
03

Exposed tools (11)

11 read · 0 write · 0 destructive.

ToolRiskDescription
check_integrityreadCheck the integrity of the local source cache and index.
find_referencesreadFind all references to a symbol at a specific position (Requires LSP).
get_class_hierarchyreadGet the inheritance hierarchy (superclass and interfaces) for a class.
get_type_inforeadGet type information and documentation (hover) for a symbol (Requires LSP).
goto_definitionreadResolve the definition of a symbol at a specific position (Requires LSP).
list_available_versionsreadList available versions for an AndroidX artifact (e.g.
list_class_membersreadList all method and field signatures for a given class.
lookup_classreadRetrieve the full source code for a given Android Framework or AndroidX class.
lookup_methodreadLook up a specific method
search_classesreadSearch for classes by glob pattern or substring (e.g.
search_in_sourcereadSearch for a text/regex pattern within a specific class or across all synced files (if class_name is omitted).
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

INFOInventory / provenance · inv.oversize · CWE-1104
project-logo.png
project-logo.png
Why it matters. 5543945 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c326376171f9full audit observations/trust-audit/mcp-server/mrmike__android-source-explorer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c326376171f9SAFEB89first audit
06

Questions

What is the Android Source Explorer MCP server?

MCP server for exploring AOSP internals and Jetpack libraries

What tools does Android Source Explorer expose?

11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Android Source Explorer safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Android Source Explorer need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (c326376171f9), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement