Atlas / MCP servers / qtty / Jadx

JadxSAFE

mcp/qtty/jadx-2

A Pure-Java MCP Server for JaDX Android Reverse Engineering Tool

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
23 21r · 2w · 0d
Transport
—
License
—
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides Android APK reverse engineering capabilities using JADX (Java Android Decompiler). This server enables AI assistants like Claude to analyze APK files, decompile code, extract components, and perform security assessments on Android applications.

Two processes

Claude ──stdio──►  mcp_server/jadx_mcp.py  ──HTTP──►  JVM daemon (JADX)
the MCP protocol          :8765     decompilation only

The MCP layer is Python; the JVM is a long-lived local HTTP service that owns decompilation and nothing else. mcp_server/daemon.py starts and supervises it, so a client only ever launches the Python script.

Why not a Java MCP server. It was one, until concurrent tool calls proved unsurvivable. The official MCP Java SDK emits each response onto a Reactor sink built with Sinks.many().unicast().onBackpressureBuffer(), which is not safe for concurrent emission: when several tool calls finish at the same instant tryEmitNext returns FAIL_NON_SERIALIZED, the SDK raises Failed to enqueue message, nothing handles it, and the transport dies. The JVM then stays alive with no reader thread, so the client never sees EOF and every request hangs forever. That is java-sdk#686, still open, and still present in the SDK's 2.0.0 source. Over HTTP, concurrency is just concurrent requests — there is no shared sink to race on.

Two things fall out of the split:

  • The APK stays loaded between sessions. The JVM is a daemon, not a

per-session subprocess, so re-analysing the same APK is free rather than a fresh parse every run.

  • Failure is loud. If the JVM dies, calls fail immediately and the next

start respawns it, instead of blocking indefinitely.

Overview

This project implements an MCP server that wraps the powerful JADX decompiler, making Android APK analysis accessible through standardized MCP tools. It's desi

Read from source at commit e3061b5e6ccdOBSERVED · 2026-10-08
02

Exposed tools (23)

21 read · 2 write · 0 destructive.

ToolRiskDescription
find_sink_call_sitesreadFind every place the APK calls a framework sink, across the whole
get_all_classesreadList class names in the loaded APK, inner classes included.
get_all_resource_file_namesreadList resource file names in the APK, including assets and the
get_android_manifestreadGet the AndroidManifest.xml content, references and all.
get_calleesreadFind the methods a method calls -- the forward direction, for sink
get_class_sourcereadGet the decompiled source of a class, or its outline if it is large.
get_deeplink_componentsreadGet components a link or a co-located app can reach: the launcher
get_exported_componentswriteGet the components any app on the device can start directly: every
get_fields_of_classreadList a class
get_main_activity_classreadGet the main launcher activity class name
get_method_by_namereadGet the source code of a specific method. methodName may be bare or
get_methods_of_classreadList a class
get_overridesreadGet the methods overriding a method, plus the base methods it
get_resource_filereadGet the content of a specific resource file.
get_smali_of_classreadGet the smali code of a specific class.
get_smali_of_methodreadGet the smali code of a specific method. Takes the same names every
get_type_hierarchyreadGet supertypes, interfaces, subclasses and nesting for a class.
get_xrefs_to_classreadFind all references to a class. Every entry has the same three keys --
get_xrefs_to_fieldwriteFind all methods that read or write a field. fieldName may be the
get_xrefs_to_methodreadFind all callers of a method. Each entry gives the calling class,
load_apkreadLoad and analyze an APK file
search_classes_by_keywordreadSearch for classes whose name contains a keyword (case-insensitive).
search_method_by_namereadSearch for methods across all classes. Returns a map of class name ->
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (11 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (7)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp_server/jadx_mcp.py:32
BASE = os.environ.get("JADX_URL", "http://127.0.0.1:8765")
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:135
| `JADX_URL` | `http://127.0.0.1:8765` | Where the daemon listens. The supervisor spawns the JVM on **this** port |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:161
JADX_PORT=8791 JADX_URL=http://127.0.0.1:8791 ./run-api.sh   # prints its own log path
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:402
curl -XPOST http://127.0.0.1:8765/api/jadx/load-apk -H 'Content-Type: application/json' \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:404
curl "http://127.0.0.1:8765/api/jadx/class-source?className=jakhar.aseem.diva.MainActivity"
INFOInventory / provenance · inv.oversize · CWE-1104
misc/DivaApplication.apk
misc/DivaApplication.apk
Why it matters. 1502294 bytes not read

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha e3061b5e6ccdfull audit observations/trust-audit/mcp-server/qtty__jadx-2.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e3061b5e6ccdSAFEB89first audit
05

Questions

What is the Jadx MCP server?

A Pure-Java MCP Server for JaDX Android Reverse Engineering Tool

What tools does Jadx expose?

23 in total: 21 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Jadx safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Jadx need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (e3061b5e6ccd), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement