Atlas / MCP servers / zinja-coder / Apktool

ApktoolCAUTION

mcp/zinja-coder/apktool

A MCP Server for APK Tool (Part of Android Reverse Engineering MCP Suites)

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
16 14r · 2w · 0d
Transport
streamable-http
License
Apache-2.0
Stars
659
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚡ Fully automated MCP server built on top of apktool to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.

[](http://www.apache.org/licenses/LICENSE-2.0.html)

Image generated using AI tools.

🤖 What is apktool-mcp-server?

apktool-mcp-server is a MCP server for the Apk Tool that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

Think: "Decompile → Context-Aware Code Review → AI Recommendations" — all in real time.

Watch the demo!

https://github.com/user-attachments/assets/d50251b8-6b1c-4341-b18e-ae54eb24a847

  • Solving the CTFs

https://github.com/user-attachments/assets/c783a604-a636-4e70-9fa8-37e3d219b20b

Other projects in Zin MCP Suite

  • [JADX-AI-MCP](https://github.com/zinja-coder/jadx-ai-mcp)
  • **[JADX-MCP-Server](https:/
Read from source at commit bc557703f910OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add apktool-mcp-server -- uvx apktool-mcp-server
claude-desktop
{
  "mcpServers": {
    "apktool-mcp-server": {
      "command": "uvx",
      "args": [
        "apktool-mcp-server"
      ]
    }
  }
}
03

Exposed tools (16)

14 read · 2 write · 0 destructive.

ToolRiskDescription
analyze_project_structureread
build_apkread
clean_projectread
decode_apkread
get_apktool_ymlread
get_manifestread
get_resource_fileread
get_smali_fileread
get_workspace_inforead
health_checkread
list_resourcesread
list_smali_directoriesread
list_smali_filesread
modify_resource_filewrite
modify_smali_filewrite
search_in_filesread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apktool_mcp_server.py:1860
print(f"Server will be available at: http://127.0.0.1:{args.port}")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
test.sh:17
MCP_URL="${MCP_URL:-http://127.0.0.1:8652/mcp/}"
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, logging
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:173
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/apktool-mcp-server-banner.png
docs/assets/apktool-mcp-server-banner.png
Why it matters. 1508800 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha bc557703f910full audit observations/trust-audit/mcp-server/zinja-coder__apktool.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28bc557703f910CAUTIONB89first audit
06

Questions

What is the Apktool MCP server?

A MCP Server for APK Tool (Part of Android Reverse Engineering MCP Suites)

What tools does Apktool expose?

16 in total: 14 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Apktool safe to connect to an agent?

With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Apktool need?

No credential environment variables were found in its source, so it appears to need none.

How does Apktool run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as apktool-mcp-server.

How current is this page?

The grade is for one exact copy of the source (bc557703f910), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement