Analyzing Android Application Permissions: A Complete Guide to the android-reverse-engineering-skill Workflow

The android-reverse-engineering-skill repository treats permission analysis as a foundational static analysis step, instructing analysts to inspect the AndroidManifest.xml file for <uses-permission> tags immediately after decompiling an APK, with special attention to network-related permissions like INTERNET and ACCESS_NETWORK_STATE.

The SimoneAvogadro/android-reverse-engineering-skill repository provides a structured workflow for reverse engineering Android applications, with analyzing Android application permissions serving as a critical first step in the security assessment process. This open-source skill emphasizes static analysis of the AndroidManifest.xml file to identify declared permissions before diving into code-level analysis.

Locating the AndroidManifest.xml in Decompiled Output

After decompiling an APK using the skill's recommended tools, the generated output contains a resources directory where the manifest resides. The file path follows the pattern <output>/resources/AndroidManifest.xml, which serves as the primary source for analyzing Android application permissions.

According to the skill's documentation in references/call-flow-analysis.md, the manifest not only lists application components and entry points but also contains the <uses-permission> tags that define the app's security requirements【call-flow-analysis.md L5-L12】.

Identifying Dangerous and Network Permissions

The workflow specifically highlights certain permissions as high-priority indicators during static analysis.

Core Permissions Listed in SKILL.md

The SKILL.md file explicitly directs analysts to note permissions, particularly INTERNET and ACCESS_NETWORK_STATE, when reviewing the manifest【SKILL.md L91-L95】. These network permissions often indicate:

  • Potential for external data exfiltration
  • Communication with command-and-control servers
  • API calls to third-party services

Understanding the Manifest Structure

Within AndroidManifest.xml, permissions appear as direct children of the root <manifest> element using the syntax:

<uses-permission android:name="android.permission.INTERNET" />
<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
<uses-permission android:name="android.permission.READ_CONTACTS" />

The android:name attribute contains the fully qualified permission string that analysts must evaluate against Android's permission protection levels (normal, dangerous, signature).

Practical Commands for Extracting Permission Data

The repository provides shell-based approaches for automating analyzing Android application permissions during large-scale assessments.

Listing All Declared Permissions

To extract every permission line from the manifest with line numbers for reference:


# From the root of the decompiled output

grep -n '<uses-permission' resources/AndroidManifest.xml

Expected output format:


12:<uses-permission android:name="android.permission.INTERNET"/>
23:<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE"/>
45:<uses-permission android:name="android.permission.READ_CONTACTS"/>

Extracting Clean Permission Names

For further processing or comparison against permission databases, extract just the permission strings:

grep -oP 'android:name="\K[^"]+' resources/AndroidManifest.xml

This outputs:


android.permission.INTERNET
android.permission.ACCESS_NETWORK_STATE
android.permission.READ_CONTACTS

Filtering for Network Permissions

To quickly identify potentially dangerous network capabilities:

grep -E 'INTERNET|ACCESS_NETWORK_STATE|ACCESS_WIFI_STATE' resources/AndroidManifest.xml

Scripting the Analysis

The repository's find-api-calls.sh script demonstrates similar grep-based patterns that can be extended for permission auditing. A custom automation script following the skill's conventions would look like:

#!/usr/bin/env bash
OUTPUT_DIR=$1
MANIFEST="${OUTPUT_DIR}/resources/AndroidManifest.xml"

echo "=== Permissions declared in $MANIFEST ==="
grep -n '<uses-permission' "$MANIFEST"

Key Source Files for Permission Analysis

Understanding the repository structure helps analysts locate the authoritative documentation for analyzing Android application permissions:

Summary

  • Analyzing Android application permissions begins with locating AndroidManifest.xml in the decompiled output under resources/AndroidManifest.xml.
  • The SKILL.md documentation explicitly directs reverse engineers to note network permissions like INTERNET and ACCESS_NETWORK_STATE immediately after decompilation.
  • Shell commands using grep provide efficient methods for extracting <uses-permission> tags and filtering for security-critical permissions.
  • Permission analysis serves as the foundation for subsequent investigation of API calls, network behavior, and potential data exfiltration vectors.

Frequently Asked Questions

Where does the android-reverse-engineering-skill repository instruct analysts to look for permission declarations?

According to the call-flow-analysis.md reference file, analysts should examine the AndroidManifest.xml file located at <output>/resources/AndroidManifest.xml immediately after decompiling an APK. This file contains the <uses-permission> tags that declare all required permissions【call-flow-analysis.md L5-L12】.

Which specific permissions does the SKILL.md file flag as high-priority during static analysis?

The SKILL.md file explicitly instructs analysts to note permissions, with special emphasis on INTERNET and ACCESS_NETWORK_STATE. These network-related permissions are flagged because they indicate potential for external communication, data exfiltration, and API interactions that require deeper investigation【SKILL.md L91-L95】.

What command-line tools does the repository recommend for extracting permission data from the manifest?

The repository demonstrates grep-based approaches for permission extraction. Recommended commands include grep -n '<uses-permission' for listing permissions with line numbers, grep -oP 'android:name="\K[^"]+' for extracting clean permission strings, and grep -E for filtering specific dangerous permissions like INTERNET or READ_CONTACTS.

How does permission analysis fit into the broader reverse engineering workflow described in the repository?

Permission analysis constitutes the foundational static analysis phase that informs subsequent dynamic and behavioral analysis. By identifying declared permissions in the manifest, analysts can predict which APIs and system services the application might access, guiding targeted searches for network code, database access, or sensitive data handling in the decompiled source code.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →