jadx-mcp-plugin — security grade SAFE, quality 57/100

Security audit verdict: SAFE · quality 57/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by mobilehackinglab · MCP Server · ★ 102

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is jadx-mcp-plugin safe to install? View the security audit →

About jadx-mcp-plugin

⚙️ Jadx MCP Plugin — Decompiler Access for Claude via MCP This project provides a Jadx plugin written in Java, which exposes the Jadx API over HTTP — enabling live interaction through MCP clients like Claude via the Model Context Protocol (MCP). A lightweight FastMCP adapter in Python acts as a bridge between Claude and the plugin. This enables intelligent navigation and automation of reverse engineering workflows, ideal for AI-assisted security analysis of Android apps. 🧰 Setup Instructions Install Python dependencies 🧠 Setup Claude MCP CLient Integration To use this adapter in Claude Desktop, go to - - - - and add an MCP server pointing to the Python executable in the venv (to prevent depedency issues) and the full adapter path following below examples: Windows: json { "mcpServers": { "Jadx MCP Server": { "command": "C:\\Wo

Quick Facts

Stars102
Forks16
LanguageJava
CategoryMCP Server
Quality Score56.6125049682965/100
Open Issues2
Last Updated2026-02-04
Created2025-04-05
Platformsjava, mcp
Est. Tokens~5k

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Java Agent Tools

Frequently Asked Questions

What is jadx-mcp-plugin?

jadx-mcp-plugin is an open-source mcp server by mobilehackinglab with 102 GitHub stars.

What programming language is jadx-mcp-plugin written in?

jadx-mcp-plugin is primarily written in Java.

How do I install or use jadx-mcp-plugin?

You can find installation instructions and usage details in the jadx-mcp-plugin GitHub repository at github.com/mobilehackinglab/jadx-mcp-plugin. The project has 102 stars and 16 forks, indicating an active community.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools