areclaw — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by TheQmaks · Claude Skill · ★ 61

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is areclaw safe to install? View the security audit →

About areclaw

areclaw Android Reverse Engineering Command-Line Automation Workspace. Self-contained environment for Android application security analysis: decompilation, traffic interception, dynamic instrumentation, secret scanning, and API discovery. Powered by Claude Code as the AI-driven orchestrator. Quick Start Platform Developed and tested on Windows 10/11 with Git Bash. Linux and WSL are supported but less tested. The automated installer () downloads Windows binaries — Linux users will need to adjust tool downloads manually. Requirements OS: Windows 10/11 with Git Bash (ships with Git for Windows) Java: 17+ (for jadx, apktool, Ghidra, deobfuscators) Python: 3.10+ with pip Android SDK: adb, aapt2 (see setup below) Device or emulator: rooted for Frida, traffic interception, runtime analysis Git: for narumii-deobfuscator build from source Disk: 2 GB for tools + workspace Android SDK Setup Install Android Studio and use SDK Manager to install: SD

androidandroid-securityapkclaude-codedecompilerfridamobile-securitypenetration-testingreverse-engineeringsecurity

Quick Facts

Stars61
Forks9
LanguageJavaScript
CategoryClaude Skill
LicenseMIT
Quality Score67.7576684077069/100
Last Updated2026-07-31
Created2026-02-28
Platformsclaude-code, node
Est. Tokens~10k

Compatible Skills

These tools work well together with areclaw for enhanced workflows:

areclaw alternative? Top 6 similar tools

Looking for a areclaw alternative? If you're comparing areclaw with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • reverse-engineering-is-over by yasminefolo · ⭐ 116

    LLMs have ended reverse engineering as a high-barrier skill. Case study: reconstructing 6/7 custom HTTP signin

  • red-run by blacklanternsecurity · ⭐ 253

    Offensive security toolkit for Claude Code

  • ghidra-cli by akiselev · ⭐ 210

    Automate Ghidra reverse engineering from the command line — headless analysis, decompilation, and structured J

  • frida-analykit by ZSA233 · ⭐ 152

    Frida 工具包 - 主要面向安卓端逆向,解决frida环境版本管理和对Agent端常用底层工具方法封装,支持MCP。(目前主要由AI开发维护代码)

  • algokiller-plugin by icloudza · ⭐ 77

    ARM64 trace evidence analysis & cipher algorithm recovery — Claude Desktop plugin with skills + local MCP serv

  • perseus by kaivyy · ⭐ 67

    AI-powered security assessment SKILLS for your codebase. Multi-language (JS, Go, Python, Rust, Java, PHP, Ruby

More Claude Skill Tools

Explore other popular claude skill tools:

View all Claude Skill tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is areclaw?

areclaw is Android Reverse Engineering Command-Line Automation Workspace. AI-driven security analysis with Claude Code.. It is categorized as a Claude Skill with 61 GitHub stars.

What programming language is areclaw written in?

areclaw is primarily written in JavaScript. It covers topics such as android, android-security, apk.

How do I install or use areclaw?

You can find installation instructions and usage details in the areclaw GitHub repository at github.com/TheQmaks/areclaw. The project has 61 stars and 9 forks, indicating an active community.

What license does areclaw use?

areclaw is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to areclaw?

The top alternatives to areclaw on Agent Skills Hub include reverse-engineering-is-over, red-run, ghidra-cli. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Claude Skill tools