Skip to content
Graphify

android-reverse-engineering-skill

android-reverse-engineering-skill gives Claude Code a structured methodology for Android application analysis — APK decompilation, manifest review, static code analysis, and vulnerability detection — organized as a defined phase sequence rather than an ad-hoc workflow.

SimoneAvogadro/android-reverse-engineering-skill

Infrastructure

Installation

npx skills add SimoneAvogadro/android-reverse-engineering-skill

Summary

android-reverse-engineering-skill gives Claude Code a structured methodology for Android application analysis — APK decompilation, manifest review, static code analysis, and vulnerability detection — organized as a defined phase sequence rather than an ad-hoc workflow.

  • APK decompilation support
  • Code analysis workflows
  • Security vulnerability detection
  • Structured reverse engineering steps
  • Phase 1: Reconnaissance

About android-reverse-engineering-skill

What Is android-reverse-engineering-skill?

APK decompilation support

Structured workflows for jadx, apktool, and related decompilation tools

Code analysis workflows

Systematic review of decompiled code for logic, data flows, and behaviors

Security vulnerability detection

Detection patterns for common Android vulnerabilities (insecure storage, exported components, hardcoded secrets, etc.)

Structured reverse engineering steps

A defined phase sequence that ensures complete coverage

How It Works

The skill defines a structured reverse engineering methodology with discrete phases:

Phase 1: Reconnaissance

Extract APK metadata, manifest analysis, permissions review, and entry point identification. The skill guides Claude through AndroidManifest.xml analysis with attention to exported components, dangerous permissions, and debug flags.

Phase 2: Static Analysis

Systematic review of decompiled Java/Kotlin source via jadx. The skill provides analysis patterns for authentication logic, data storage practices, network communication, cryptographic implementation, and third-party SDK usage.

Phase 3: Vulnerability Assessment

Structured checks against common Android vulnerability classes: insecure data storage, improper platform usage, insecure communication, insecure authentication, insufficient cryptography, client-side injection, poor code quality, code tampering, and reverse engineering exposure.

Phase 4: Documentation

Findings structured in a consistent format: vulnerability class, location (class + method), severity, evidence, and remediation recommendation.

Use Cases

  • Security research: systematic analysis of apps for vulnerability disclosure
  • Penetration testing: client-authorized security assessments
  • Malware analysis: understanding suspicious APK behavior
  • Competitive analysis: understanding how competitor apps implement features (where legally permitted)
  • Compliance auditing: verifying your own apps meet security standards before release

How to Install android-reverse-engineering-skill?

npx skills add SimoneAvogadro/android-reverse-engineering-skill | Or download from GitHub https://github.com/SimoneAvogadro/android-reverse-engineering-skill

FAQ about android-reverse-engineering-skill

Do I need specific tools installed for this skill to work?

Yes. The skill references jadx, apktool, and related tools. You need them in your local environment. The skill includes setup guidance.

Is this skill legal to use?

Legality depends on jurisdiction, terms of service, and authorization. Always ensure you have appropriate permission before analyzing any app you do not own or have explicit authorization to test.

Does the skill automate the analysis, or does it assist with it?

It structures and guides the analysis. Claude helps interpret decompiled code, identify vulnerability patterns, and document findings. Decompilation and tool execution happen in your local environment.

What is the OWASP Mobile Top 10?

It is a standard reference for the most critical mobile application security risks. The skill's vulnerability assessment phase checks against the full list.

Sources

Editorial review · agent skill

What this page is based on

Skill behavior is described from the recorded repository or package evidence and its verification date.

Review basis
agent skill record and linked primary evidence
Last checked
Jul 11, 2026
Evidence links
2 recorded in the page data

Source snapshot is 91 days old; verify upstream details before relying on pricing, availability, or security claims.