JADXCAUTION
MCP server for JADX-AI Plugin
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
⚡ Fully automated MCP server built to communicate with JADX-AI-MCP Plugin to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.
[](http://www.apache.org/licenses/LICENSE-2.0.html)
⭐ Contributors
Thanks to these wonderful people for their contributions ⭐
ljt270864457
badmonkey7
p0px
bx33661
63757364088aOBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add jadx-mcp-server -- uvx jadx-mcp-server
{
"mcpServers": {
"jadx-mcp-server": {
"command": "uvx",
"args": [
"jadx-mcp-server"
]
}
}
}Exposed tools (34)
27 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_comment | write | Add a comment to decompiled code, shown in JADX-GUI and saved with the project. |
clear_cache | destructive | Clear the decompilation source cache and reset counters. Use when switching APKs or to free memory. |
debug_get_stack_frames | read | Get current stack frames (call stack). |
debug_get_threads | read | Get all threads in the debugged process. |
debug_get_variables | read | Get current variables when process is suspended. |
fetch_current_class | read | Fetch the currently selected class and its code from the JADX-GUI plugin. |
get_all_classes | read | Returns a list of all classes in the project with pagination support. |
get_all_resource_file_names | read | Retrieve all resource files names. |
get_android_manifest | read | Retrieve and return the AndroidManifest.xml content. |
get_cache_stats | read | Get decompilation cache statistics: hits, misses, hit_rate, cached_classes, compressed_mb, compression_ratio. |
get_class_source | read | Fetch the Java source of a specific class. |
get_fields_of_class | read | List all field names in a class. |
get_main_activity_class | read | Fetch the main activity class from AndroidManifest.xml. |
get_main_application_classes_code | read | Fetch main application classes |
get_main_application_classes_names | read | Fetch main application classes |
get_manifest_component | read | Retrieve specified component data from AndroidManifest.xml, support filter exported components. |
get_method_by_name | read | Fetch the source code of a method from a specific class. |
get_methods_of_class | read | List all method names in a class. |
get_package_tree | read | Get all packages in the APK sorted by class count. Shows total_classes, total_packages, and per-package name, class_count, is_likely_library. Use this first to understand the APK structure before searching. |
get_resource_file | read | Retrieve resource file content. |
get_selected_text | read | Returns the currently selected text in the decompiled code view. |
get_smali_of_class | read | Fetch the smali representation of a class. |
get_strings | read | Retrieve contents of strings.xml files. |
get_xrefs_to_class | read | Find all references to a class. |
get_xrefs_to_field | read | Find all references to a field. |
get_xrefs_to_method | read | Find all references to a method. |
list_comments | read | List the comments already stored in the project, optionally filtered to one class. |
rename_class | write | Renames a specific class. |
rename_field | write | Renames a specific field. |
rename_method | write | Renames a specific method, optionally scoped to class_name. |
rename_package | write | Renames a package and all its classes. |
rename_variable | write | Renames a specific variable in a method. |
search_classes_by_keyword | read | Search for classes containing a specific keyword with flexible filtering options. |
search_method_by_name | read | Search for a method name across all classes. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (1 observation(s))
- Network
- declared (10 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
MCP_URL="${MCP_URL:-http://127.0.0.1:9000/mcp}"clear_cache
streamable-http
fastmcp, httpx, requests
static/image.png
Gates applied: no_behavioural_pass.
63757364088afull audit observations/trust-audit/mcp-server/zinja-coder__jadx.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | 63757364088a | CAUTION | B | 89 | first audit |
Questions
What is the JADX MCP server?
MCP server for JADX-AI Plugin
What tools does JADX expose?
34 in total: 27 read-only, 6 that write, and 1 that can delete or overwrite (clear_cache). Every one is listed on this page with its risk.
Is JADX safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does JADX need?
No credential environment variables were found in its source, so it appears to need none.
How does JADX run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as jadx-mcp-server.
How current is this page?
The grade is for one exact copy of the source (63757364088a), read on 2026-09-27. The repository is watched and re-audited when it changes.