Analyzing Android Application Permissions: A Complete Guide to the android-reverse-engineering-skill Workflow
The android-reverse-engineering-skill repository treats permission analysis as a foundational static analysis step, instructing analysts to inspect the AndroidManifest.xml file for <uses-permission> tags immediately after decompiling an APK, with special attention to network-related permissions like INTERNET and ACCESS_NETWORK_STATE.
The SimoneAvogadro/android-reverse-engineering-skill repository provides a structured workflow for reverse engineering Android applications, with analyzing Android application permissions serving as a critical first step in the security assessment process. This open-source skill emphasizes static analysis of the AndroidManifest.xml file to identify declared permissions before diving into code-level analysis.
Locating the AndroidManifest.xml in Decompiled Output
After decompiling an APK using the skill's recommended tools, the generated output contains a resources directory where the manifest resides. The file path follows the pattern <output>/resources/AndroidManifest.xml, which serves as the primary source for analyzing Android application permissions.
According to the skill's documentation in references/call-flow-analysis.md, the manifest not only lists application components and entry points but also contains the <uses-permission> tags that define the app's security requirements【call-flow-analysis.md L5-L12】.
Identifying Dangerous and Network Permissions
The workflow specifically highlights certain permissions as high-priority indicators during static analysis.
Core Permissions Listed in SKILL.md
The SKILL.md file explicitly directs analysts to note permissions, particularly INTERNET and ACCESS_NETWORK_STATE, when reviewing the manifest【SKILL.md L91-L95】. These network permissions often indicate:
- Potential for external data exfiltration
- Communication with command-and-control servers
- API calls to third-party services
Understanding the Manifest Structure
Within AndroidManifest.xml, permissions appear as direct children of the root <manifest> element using the syntax:
<uses-permission android:name="android.permission.INTERNET" />
<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
<uses-permission android:name="android.permission.READ_CONTACTS" />
The android:name attribute contains the fully qualified permission string that analysts must evaluate against Android's permission protection levels (normal, dangerous, signature).
Practical Commands for Extracting Permission Data
The repository provides shell-based approaches for automating analyzing Android application permissions during large-scale assessments.
Listing All Declared Permissions
To extract every permission line from the manifest with line numbers for reference:
# From the root of the decompiled output
grep -n '<uses-permission' resources/AndroidManifest.xml
Expected output format:
12:<uses-permission android:name="android.permission.INTERNET"/>
23:<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE"/>
45:<uses-permission android:name="android.permission.READ_CONTACTS"/>
Extracting Clean Permission Names
For further processing or comparison against permission databases, extract just the permission strings:
grep -oP 'android:name="\K[^"]+' resources/AndroidManifest.xml
This outputs:
android.permission.INTERNET
android.permission.ACCESS_NETWORK_STATE
android.permission.READ_CONTACTS
Filtering for Network Permissions
To quickly identify potentially dangerous network capabilities:
grep -E 'INTERNET|ACCESS_NETWORK_STATE|ACCESS_WIFI_STATE' resources/AndroidManifest.xml
Scripting the Analysis
The repository's find-api-calls.sh script demonstrates similar grep-based patterns that can be extended for permission auditing. A custom automation script following the skill's conventions would look like:
#!/usr/bin/env bash
OUTPUT_DIR=$1
MANIFEST="${OUTPUT_DIR}/resources/AndroidManifest.xml"
echo "=== Permissions declared in $MANIFEST ==="
grep -n '<uses-permission' "$MANIFEST"
Key Source Files for Permission Analysis
Understanding the repository structure helps analysts locate the authoritative documentation for analyzing Android application permissions:
-
plugins/android-reverse-engineering/skills/android-reverse-engineering/SKILL.md(lines 91-95): Defines the core workflow and explicitly instructs analysts to note permissions, particularlyINTERNETandACCESS_NETWORK_STATE【SKILL.md L91-L95】. -
plugins/android-reverse-engineering/skills/android-reverse-engineering/references/call-flow-analysis.md(lines 5-12): Provides technical details on locating the manifest and understanding how<uses-permission>tags define the application's security requirements【call-flow-analysis.md L5-L12】. -
README.md(root): Summarizes the skill's capabilities, noting that it "Analyzes app structure: manifest, packages, architecture patterns," which includes permission inspection as a fundamental component【README.md L10】. -
plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/find-api-calls.sh: Contains grep-based search patterns that demonstrate the shell-based approach to extracting structured data from decompiled sources, applicable to permission extraction.
Summary
- Analyzing Android application permissions begins with locating
AndroidManifest.xmlin the decompiled output underresources/AndroidManifest.xml. - The
SKILL.mddocumentation explicitly directs reverse engineers to note network permissions likeINTERNETandACCESS_NETWORK_STATEimmediately after decompilation. - Shell commands using
grepprovide efficient methods for extracting<uses-permission>tags and filtering for security-critical permissions. - Permission analysis serves as the foundation for subsequent investigation of API calls, network behavior, and potential data exfiltration vectors.
Frequently Asked Questions
Where does the android-reverse-engineering-skill repository instruct analysts to look for permission declarations?
According to the call-flow-analysis.md reference file, analysts should examine the AndroidManifest.xml file located at <output>/resources/AndroidManifest.xml immediately after decompiling an APK. This file contains the <uses-permission> tags that declare all required permissions【call-flow-analysis.md L5-L12】.
Which specific permissions does the SKILL.md file flag as high-priority during static analysis?
The SKILL.md file explicitly instructs analysts to note permissions, with special emphasis on INTERNET and ACCESS_NETWORK_STATE. These network-related permissions are flagged because they indicate potential for external communication, data exfiltration, and API interactions that require deeper investigation【SKILL.md L91-L95】.
What command-line tools does the repository recommend for extracting permission data from the manifest?
The repository demonstrates grep-based approaches for permission extraction. Recommended commands include grep -n '<uses-permission' for listing permissions with line numbers, grep -oP 'android:name="\K[^"]+' for extracting clean permission strings, and grep -E for filtering specific dangerous permissions like INTERNET or READ_CONTACTS.
How does permission analysis fit into the broader reverse engineering workflow described in the repository?
Permission analysis constitutes the foundational static analysis phase that informs subsequent dynamic and behavioral analysis. By identifying declared permissions in the manifest, analysts can predict which APIs and system services the application might access, guiding targeted searches for network code, database access, or sensitive data handling in the decompiled source code.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →