JadxSAFE
A Pure-Java MCP Server for JaDX Android Reverse Engineering Tool
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that provides Android APK reverse engineering capabilities using JADX (Java Android Decompiler). This server enables AI assistants like Claude to analyze APK files, decompile code, extract components, and perform security assessments on Android applications.
Two processes
Claude ──stdio──► mcp_server/jadx_mcp.py ──HTTP──► JVM daemon (JADX) the MCP protocol :8765 decompilation only
The MCP layer is Python; the JVM is a long-lived local HTTP service that owns decompilation and nothing else. mcp_server/daemon.py starts and supervises it, so a client only ever launches the Python script.
Why not a Java MCP server. It was one, until concurrent tool calls proved unsurvivable. The official MCP Java SDK emits each response onto a Reactor sink built with Sinks.many().unicast().onBackpressureBuffer(), which is not safe for concurrent emission: when several tool calls finish at the same instant tryEmitNext returns FAIL_NON_SERIALIZED, the SDK raises Failed to enqueue message, nothing handles it, and the transport dies. The JVM then stays alive with no reader thread, so the client never sees EOF and every request hangs forever. That is java-sdk#686, still open, and still present in the SDK's 2.0.0 source. Over HTTP, concurrency is just concurrent requests — there is no shared sink to race on.
Two things fall out of the split:
- The APK stays loaded between sessions. The JVM is a daemon, not a
per-session subprocess, so re-analysing the same APK is free rather than a fresh parse every run.
- Failure is loud. If the JVM dies, calls fail immediately and the next
start respawns it, instead of blocking indefinitely.
Overview
This project implements an MCP server that wraps the powerful JADX decompiler, making Android APK analysis accessible through standardized MCP tools. It's desi
e3061b5e6ccdOBSERVED · 2026-10-08Exposed tools (23)
21 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
find_sink_call_sites | read | Find every place the APK calls a framework sink, across the whole |
get_all_classes | read | List class names in the loaded APK, inner classes included. |
get_all_resource_file_names | read | List resource file names in the APK, including assets and the |
get_android_manifest | read | Get the AndroidManifest.xml content, references and all. |
get_callees | read | Find the methods a method calls -- the forward direction, for sink |
get_class_source | read | Get the decompiled source of a class, or its outline if it is large. |
get_deeplink_components | read | Get components a link or a co-located app can reach: the launcher |
get_exported_components | write | Get the components any app on the device can start directly: every |
get_fields_of_class | read | List a class |
get_main_activity_class | read | Get the main launcher activity class name |
get_method_by_name | read | Get the source code of a specific method. methodName may be bare or |
get_methods_of_class | read | List a class |
get_overrides | read | Get the methods overriding a method, plus the base methods it |
get_resource_file | read | Get the content of a specific resource file. |
get_smali_of_class | read | Get the smali code of a specific class. |
get_smali_of_method | read | Get the smali code of a specific method. Takes the same names every |
get_type_hierarchy | read | Get supertypes, interfaces, subclasses and nesting for a class. |
get_xrefs_to_class | read | Find all references to a class. Every entry has the same three keys -- |
get_xrefs_to_field | write | Find all methods that read or write a field. fieldName may be the |
get_xrefs_to_method | read | Find all callers of a method. Each entry gives the calling class, |
load_apk | read | Load and analyze an APK file |
search_classes_by_keyword | read | Search for classes whose name contains a keyword (case-insensitive). |
search_method_by_name | read | Search for methods across all classes. Returns a map of class name -> |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (11 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
BASE = os.environ.get("JADX_URL", "http://127.0.0.1:8765")| `JADX_URL` | `http://127.0.0.1:8765` | Where the daemon listens. The supervisor spawns the JVM on **this** port |
JADX_PORT=8791 JADX_URL=http://127.0.0.1:8791 ./run-api.sh # prints its own log path
curl -XPOST http://127.0.0.1:8765/api/jadx/load-apk -H 'Content-Type: application/json' \
curl "http://127.0.0.1:8765/api/jadx/class-source?className=jakhar.aseem.diva.MainActivity"
misc/DivaApplication.apk
Gates applied: no_behavioural_pass, no_license.
e3061b5e6ccdfull audit observations/trust-audit/mcp-server/qtty__jadx-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e3061b5e6ccd | SAFE | B | 89 | first audit |
Questions
What is the Jadx MCP server?
A Pure-Java MCP Server for JaDX Android Reverse Engineering Tool
What tools does Jadx expose?
23 in total: 21 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Jadx safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Jadx need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (e3061b5e6ccd), read on 2026-10-08. The repository is watched and re-audited when it changes.