Atlas / MCP servers / zinja-coder / JADX

JADXCAUTION

mcp/zinja-coder/jadx

MCP server for JADX-AI Plugin

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
34 27r · 6w · 1d
Transport
streamable-http
License
Apache-2.0
Stars
795
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚡ Fully automated MCP server built to communicate with JADX-AI-MCP Plugin to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.

[](http://www.apache.org/licenses/LICENSE-2.0.html)

⭐ Contributors

Thanks to these wonderful people for their contributions ⭐

ljt270864457

badmonkey7

p0px

bx33661

Read from source at commit 63757364088aOBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add jadx-mcp-server -- uvx jadx-mcp-server
claude-desktop
{
  "mcpServers": {
    "jadx-mcp-server": {
      "command": "uvx",
      "args": [
        "jadx-mcp-server"
      ]
    }
  }
}
03

Exposed tools (34)

27 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_commentwriteAdd a comment to decompiled code, shown in JADX-GUI and saved with the project.
clear_cachedestructiveClear the decompilation source cache and reset counters. Use when switching APKs or to free memory.
debug_get_stack_framesreadGet current stack frames (call stack).
debug_get_threadsreadGet all threads in the debugged process.
debug_get_variablesreadGet current variables when process is suspended.
fetch_current_classreadFetch the currently selected class and its code from the JADX-GUI plugin.
get_all_classesreadReturns a list of all classes in the project with pagination support.
get_all_resource_file_namesreadRetrieve all resource files names.
get_android_manifestreadRetrieve and return the AndroidManifest.xml content.
get_cache_statsreadGet decompilation cache statistics: hits, misses, hit_rate, cached_classes, compressed_mb, compression_ratio.
get_class_sourcereadFetch the Java source of a specific class.
get_fields_of_classreadList all field names in a class.
get_main_activity_classreadFetch the main activity class from AndroidManifest.xml.
get_main_application_classes_codereadFetch main application classes
get_main_application_classes_namesreadFetch main application classes
get_manifest_componentreadRetrieve specified component data from AndroidManifest.xml, support filter exported components.
get_method_by_namereadFetch the source code of a method from a specific class.
get_methods_of_classreadList all method names in a class.
get_package_treereadGet all packages in the APK sorted by class count. Shows total_classes, total_packages, and per-package name, class_count, is_likely_library. Use this first to understand the APK structure before searching.
get_resource_filereadRetrieve resource file content.
get_selected_textreadReturns the currently selected text in the decompiled code view.
get_smali_of_classreadFetch the smali representation of a class.
get_stringsreadRetrieve contents of strings.xml files.
get_xrefs_to_classreadFind all references to a class.
get_xrefs_to_fieldreadFind all references to a field.
get_xrefs_to_methodreadFind all references to a method.
list_commentsreadList the comments already stored in the project, optionally filtered to one class.
rename_classwriteRenames a specific class.
rename_fieldwriteRenames a specific field.
rename_methodwriteRenames a specific method, optionally scoped to class_name.
rename_packagewriteRenames a package and all its classes.
rename_variablewriteRenames a specific variable in a method.
search_classes_by_keywordreadSearch for classes containing a specific keyword with flexible filtering options.
search_method_by_namereadSearch for a method name across all classes.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (1 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
test.sh:14
MCP_URL="${MCP_URL:-http://127.0.0.1:9000/mcp}"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_cache
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, httpx, requests
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
static/image.png
static/image.png
Why it matters. 1729301 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha 63757364088afull audit observations/trust-audit/mcp-server/zinja-coder__jadx.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2763757364088aCAUTIONB89first audit
06

Questions

What is the JADX MCP server?

MCP server for JADX-AI Plugin

What tools does JADX expose?

34 in total: 27 read-only, 6 that write, and 1 that can delete or overwrite (clear_cache). Every one is listed on this page with its risk.

Is JADX safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does JADX need?

No credential environment variables were found in its source, so it appears to need none.

How does JADX run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as jadx-mcp-server.

How current is this page?

The grade is for one exact copy of the source (63757364088a), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement