How to Set Up Android Reverse Engineering Tools: Complete Installation Guide
The Android Reverse Engineering skill provides automated setup scripts that install Java JDK 17, jadx, Vineflower, dex2jar, apktool, and adb across Ubuntu, Fedora, Arch Linux, and macOS using a single command-line interface.
Setting up a complete Android reverse engineering environment typically requires installing multiple command-line utilities with specific version dependencies. The SimoneAvogadro/android-reverse-engineering-skill repository bundles OS-aware automation scripts that handle dependency detection, installation, and verification for decompiling APK, XAPK, JAR, and AAR files.
Automated Installation via install-dep.sh
The install-dep.sh script serves as the central installer that detects your operating system and package manager to automate tool deployment. Located at plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh, this script handles platform-specific logic for Ubuntu/Debian, Fedora, Arch Linux, and macOS via Homebrew.
You can invoke the installer for specific tools using the syntax:
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh <tool-name>
The script contains dedicated installation functions for each dependency, checking for existing installations before proceeding with OS-appropriate package manager commands or direct GitHub downloads.
Required Dependencies
Java JDK 17+
Java JDK 17+ is the foundational runtime required for all Java-based decompilers in the toolchain. The install-dep.sh script's Java installation block detects your platform and installs the correct package: openjdk-17-jdk for Debian/Ubuntu, java-17-openjdk-devel for Fedora, jdk17-openjdk for Arch Linux, or openjdk@17 via Homebrew for macOS.
Implementation details are found in lines 70-88 of plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh.
jadx Decompiler
jadx is the primary decompiler for DEX, APK, JAR, and AAR files. The installation logic in the install_jadx function (lines 101-146) first checks for Homebrew availability and executes brew install jadx when possible. If Homebrew is unavailable, the script downloads the latest jadx release from GitHub, extracts it to ~/.local/share/jadx, creates symlinks in ~/.local/bin, and updates the PATH environment variable.
Optional Dependencies for Enhanced Decompilation
Vineflower and Fernflower
Vineflower (formerly Fernflower) produces higher-quality decompiled Java output, particularly for complex constructs like lambdas and inner classes. The install_vineflower function (lines 152-170) checks for existing CLI binaries or the FERNFLOWER_JAR_PATH environment variable. If absent, it attempts Homebrew installation, then falls back to downloading the latest GitHub release, placing the JAR under ~/.local/share/vineflower, and creating a wrapper script at ~/.local/bin/vineflower.
dex2jar Converter
dex2jar is required only when using Fernflower/Vineflower on DEX or APK inputs, as it converts DEX bytecode to standard JAR format. The install_dex2jar function (lines 166-210) follows the same pattern: Homebrew first, then direct download from the latest GitHub release to ~/.local/share/dex2jar with symlinks in ~/.local/bin.
apktool and adb
apktool decodes Android resources (XML, drawables) that jadx may struggle with, while adb (Android Debug Bridge) enables pulling APKs directly from connected devices. The script installs apktool via the detected package manager (brew install apktool, apt install apktool, etc.) in lines 221-231, and handles adb installation via android-platform-tools (Homebrew) or Linux package managers in lines 236-250.
Verifying Your Environment with check-deps.sh
Before running decompilation tasks, use the check-deps.sh script to validate your environment. Located at plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/check-deps.sh, this utility scans for required and optional tools, prints human-readable status reports, and emits machine-readable tags (INSTALL_REQUIRED: and INSTALL_OPTIONAL:) for missing components.
The verification logic spans lines 12-30 for initialization and lines 41-100 for the actual dependency checking implementation.
# Verify all dependencies are installed
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/check-deps.sh
Complete Setup Walkthrough
Follow this sequence to configure your Android reverse engineering environment:
- Check current status to identify missing tools:
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/check-deps.sh
- Install required dependencies (Java and jadx):
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh java
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh jadx
- Install optional tools for enhanced analysis:
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh vineflower
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh dex2jar
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh apktool
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh adb
- Verify installation by running the dependency checker again or proceeding directly to decompilation:
# Decompile with default jadx engine
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/decompile.sh app.apk
# Or decompile with Vineflower (requires dex2jar for APK inputs)
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/decompile.sh --engine fernflower app.apk
For detailed, OS-specific manual installation steps, consult the setup-guide.md reference file at plugins/android-reverse-engineering/skills/android-reverse-engineering/references/setup-guide.md, which contains package manager commands for all supported platforms.
Summary
- Use
install-dep.shto automate installation of Java JDK 17+, jadx, Vineflower, dex2jar, apktool, and adb across Linux distributions and macOS. - Required tools include Java JDK 17+ and jadx, installed via OS package managers or direct GitHub downloads to
~/.local/share/. - Optional tools like Vineflower and dex2jar enhance decompilation quality but require specific PATH configurations and wrapper scripts.
- Verify setup using
check-deps.sh, which provides both human-readable output and machine-readable tags for automation. - Reference
setup-guide.mdfor manual installation instructions when automated scripts cannot complete installation.
Frequently Asked Questions
What is the minimum Java version required for these Android reverse engineering tools?
The toolchain requires Java JDK 17 or higher. This version is necessary to run both jadx and the Fernflower/Vineflower decompilers. The install-dep.sh script specifically targets openjdk-17-jdk and equivalent packages across all supported operating systems.
Can I install these tools manually without using the automated scripts?
Yes. The repository includes setup-guide.md at plugins/android-reverse-engineering/skills/android-reverse-engineering/references/setup-guide.md, which provides explicit package manager commands for Ubuntu/Debian (apt), Fedora (dnf), Arch Linux (pacman), and macOS (brew). However, the automated install-dep.sh script handles PATH configuration and version management that manual installation requires you to perform separately.
Why does dex2jar require separate installation from Vineflower?
dex2jar functions as a preprocessor that converts Android DEX bytecode into standard Java JAR format. While jadx can directly consume DEX files, Vineflower (Fernflower) requires plain JAR input. The install-dep.sh script manages this dependency chain automatically, but you only need dex2jar if you plan to use the Fernflower/Vineflower decompilation engine specifically.
How do I verify that all tools installed correctly?
Run the check-deps.sh script located at plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/check-deps.sh. This script performs comprehensive path lookups and version checks for all dependencies, outputting clear status indicators for each tool. It also emits machine-readable INSTALL_REQUIRED: and INSTALL_OPTIONAL: tags that automation systems can parse to determine if additional setup steps are needed.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →