Android ProxyCAUTION
基于 MCP 的 Android 抓包服务,让 AI 助手通过自然语言分析网络请求。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
基于 MCP (Model Context Protocol) 的 Android 抓包服务,让 AI 助手能够帮你抓取和分析 HTTP/HTTPS 流量。
功能特点
- 抓包: 捕获 HTTP/HTTPS 流量,支持按域名、状态码、资源类型筛选
- 智能搜索: 搜索请求/响应内容,支持大响应分片读取
- AI 驱动: 通过自然语言让 Claude 帮你分析网络请求
架构
┌─────────────────┐ SQLite ┌─────────────────┐ │ 代理服务 │ ─────────────→ │ MCP 服务 │ │ (终端手动启动) │ 流量数据共享 │ (Claude 调用) │ │ mitmdump │ │ 查询/搜索/分析 │ └─────────────────┘ └─────────────────┘ ↑ │ HTTP/HTTPS │ ┌─────────┐ │ 手机 │ └─────────┘
快速开始
1. 环境要求
- Python 3.11+
- uv (Python 包管理器)
安装 uv:
# macOS / Linux curl -LsSf https://astral.sh/uv/install.sh | sh # Windows (PowerShell) powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex" # 或通过 pip pip install uv
2. 安装
# 克隆项目 git clone https://github.com/yourname/android-proxy-mcp.git cd android-proxy-mcp # 安装依赖 uv sync
3. 配置 Claude Desktop
编辑 Claude Desktop 配置文件:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"android-proxy": {
"command": "uv",
"args": ["--directory", "/path/to/android-proxy-mcp", "run", "android-proxy-mcp"]
}
}
}将 /path/to/android-proxy-mcp 替换为实际项目路径4. 重启 Claude Desktop
配置完成后,重启 Claude Desktop 使配置生效。
使用方法
第一步:启动代理
在终端中运行:
uv run android-proxy-start
你会看到如下输出:
╔════════════════════════════════════════════════════════════╗ ║ 🚀 Android Proxy MCP 启动向导 ║ ╚════════════════════════════════════════════════════════════╝ ════════════════════════════════════════════════════════════ 环境检测 ════════════════════════════════════════════════════════════ ✓ 端口 8288 可用 ════════════════════════════════════════════════════════════ 手机配置 ═════
48f6a59e5ce7OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add android-proxy-mcp -- uvx android-proxy-mcp
{
"mcpServers": {
"android-proxy-mcp": {
"command": "uvx",
"args": [
"android-proxy-mcp"
]
}
}
}Exposed tools (11)
9 read · 0 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
android_clear_proxy | destructive | 清除 Android 设备上的代理设置 |
android_get_device_info | read | 获取指定 Android 设备的详细信息(型号、版本、是否 root 等) |
android_list_devices | read | 列出所有连接的 Android 设备 |
android_setup_proxy | read | 在 Android 设备上设置 HTTP 代理。注意:此方式对部分应用可能无效,建议在 Wi-Fi 设置中手动配置。 |
get_cert_info | read | 获取 CA 证书信息和安装指南。抓取 HTTPS 流量需要在设备上安装此证书。 |
proxy_status | read | 获取代理服务器状态。注意:需要先在终端运行 |
traffic_clear | destructive | 清空所有捕获的流量 |
traffic_get_detail | read | 获取单个请求的元数据(请求头、响应头、参数等)。注意:不包含请求体和响应体内容,使用 traffic_read_body 读取。 |
traffic_list | read | 列出捕获的 HTTP/HTTPS 流量。默认返回最近 10 条,支持分页和筛选。 |
traffic_read_body | read | 分片读取请求体或响应体。用于查看大内容,支持分页读取。 |
traffic_search | read | 搜索流量内容。可搜索 URL、请求头、请求体、响应头、响应体。返回匹配的片段而非完整内容。 |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
MoveCertificate-v1.5.5.zip
android_clear_proxy, traffic_clear
assert CDPConverter.extract_domain("http://192.168.1.1:8080/api") == "192.168.1.1"assert base64.b64decode(body) == data
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
48f6a59e5ce7full audit observations/trust-audit/mcp-server/zhizhuodemao__android-proxy.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 48f6a59e5ce7 | CAUTION | B | 89 | first audit |
Questions
What is the Android Proxy MCP server?
基于 MCP 的 Android 抓包服务,让 AI 助手通过自然语言分析网络请求。
What tools does Android Proxy expose?
11 in total: 9 read-only, 0 that write, and 2 that can delete or overwrite (android_clear_proxy, traffic_clear). Every one is listed on this page with its risk.
Is Android Proxy safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Android Proxy need?
No credential environment variables were found in its source, so it appears to need none.
How does Android Proxy run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as android-proxy-mcp.
How current is this page?
The grade is for one exact copy of the source (48f6a59e5ce7), read on 2026-10-06. The repository is watched and re-audited when it changes.