No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by TheQmaks · Claude Skill · ★ 61
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is areclaw safe to install? View the security audit →
areclaw Android Reverse Engineering Command-Line Automation Workspace. Self-contained environment for Android application security analysis: decompilation, traffic interception, dynamic instrumentation, secret scanning, and API discovery. Powered by Claude Code as the AI-driven orchestrator. Quick Start Platform Developed and tested on Windows 10/11 with Git Bash. Linux and WSL are supported but less tested. The automated installer () downloads Windows binaries — Linux users will need to adjust tool downloads manually. Requirements OS: Windows 10/11 with Git Bash (ships with Git for Windows) Java: 17+ (for jadx, apktool, Ghidra, deobfuscators) Python: 3.10+ with pip Android SDK: adb, aapt2 (see setup below) Device or emulator: rooted for Frida, traffic interception, runtime analysis Git: for narumii-deobfuscator build from source Disk: 2 GB for tools + workspace Android SDK Setup Install Android Studio and use SDK Manager to install: SD
| Stars | 61 |
| Forks | 9 |
| Language | JavaScript |
| Category | Claude Skill |
| License | MIT |
| Quality Score | 67.7576684077069/100 |
| Last Updated | 2026-07-31 |
| Created | 2026-02-28 |
| Platforms | claude-code, node |
| Est. Tokens | ~10k |
These tools work well together with areclaw for enhanced workflows:
Looking for a areclaw alternative? If you're comparing areclaw with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
LLMs have ended reverse engineering as a high-barrier skill. Case study: reconstructing 6/7 custom HTTP signin
Offensive security toolkit for Claude Code
Automate Ghidra reverse engineering from the command line — headless analysis, decompilation, and structured J
Frida 工具包 - 主要面向安卓端逆向,解决frida环境版本管理和对Agent端常用底层工具方法封装,支持MCP。(目前主要由AI开发维护代码)
ARM64 trace evidence analysis & cipher algorithm recovery — Claude Desktop plugin with skills + local MCP serv
AI-powered security assessment SKILLS for your codebase. Multi-language (JS, Go, Python, Rust, Java, PHP, Ruby
Explore other popular claude skill tools:
areclaw is Android Reverse Engineering Command-Line Automation Workspace. AI-driven security analysis with Claude Code.. It is categorized as a Claude Skill with 61 GitHub stars.
areclaw is primarily written in JavaScript. It covers topics such as android, android-security, apk.
You can find installation instructions and usage details in the areclaw GitHub repository at github.com/TheQmaks/areclaw. The project has 61 stars and 9 forks, indicating an active community.
areclaw is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to areclaw on Agent Skills Hub include reverse-engineering-is-over, red-run, ghidra-cli. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: