Android Reverse Engineering Skill Repository Project Structure Explained
The SimoneAvogadro/android-reverse-engineering-skill repository organizes its Claude Code plugin as a hierarchical structure that separates marketplace metadata, skill definitions, automation scripts, and reference documentation into distinct, navigable directories.
The SimoneAvogadro/android-reverse-engineering-skill repository packages a complete Android reverse engineering workflow as a Claude Code plugin. Its project structure follows strict conventions required by the Claude Plugin Marketplace while providing modular access to decompilation tools and analysis scripts. The layout centers on a single plugin directory that encapsulates everything needed to execute a five-phase reverse engineering pipeline.
Root-Level Configuration and Marketplace Metadata
The repository root contains two critical entry points for discovery and usage. The .claude-plugin/marketplace.json file registers the repository in the Claude Plugin Marketplace, declaring the plugin's name, version, and visibility. This JSON file allows Claude to index and display the skill to users browsing available extensions.
Alongside this configuration, the README.md provides the public-facing documentation with installation instructions, a high-level overview of capabilities, and a condensed repository structure diagram. These root files serve as the gateway, but contain no executable logic—all functional components reside deeper in the hierarchy.
Core Plugin Architecture
All operational code lives within plugins/android-reverse-engineering/, following Claude Code's nested convention for plugin isolation. This directory contains the complete runtime environment for the Android reverse engineering skill.
Plugin Manifest Declaration
The plugins/android-reverse-engineering/.claude-plugin/plugin.json file declares the plugin's identity and entry points to the Claude runtime. This manifest specifies the plugin name (android-reverse-engineering), version constraints, and initialization parameters required for Claude to load and activate the skill correctly.
Skill Definition and Workflow Documentation
At plugins/android-reverse-engineering/skills/android-reverse-engineering/SKILL.md, the repository stores the authoritative skill specification. This markdown file defines the five-phase workflow that governs all reverse engineering operations:
- Dependency verification—ensuring Java JDK 17+ and decompilers are available
- Decompilation—converting APK/XAPK/JAR/AAR files to readable source
- Structure analysis—mapping package hierarchies and entry points
- Call-flow tracing—identifying execution paths between components
- API extraction—locating Retrofit interfaces, OkHttp clients, and hard-coded endpoints
The SKILL.md file also contains trigger phrases that activate the skill when users mention specific keywords related to Android analysis.
Reference Documentation Directory
The references/ subdirectory within the skill folder contains specialized guides for tool usage and methodology:
setup-guide.md—Installation instructions for Java, jadx, vineflower, and dex2jarjadx-usage.md—Command reference for the primary decompilerfernflower-usage.md(orvineflower-usage.md)—Alternative Java decompiler documentationapi-extraction-patterns.md—Regex and grep patterns for finding authentication keys and endpointscall-flow-analysis.md—Techniques for tracing inter-component communication
These files support both the automation scripts and human users performing manual analysis.
Automation Scripts Implementation
The scripts/ directory contains four Bash utilities that implement the SKILL.md workflow phases:
check-deps.sh—Validates the presence of Java JDK 17+, jadx, and optionally vineflower/dex2jarinstall-dep.sh—Cross-platform dependency installer supporting apt, yum, and manual downloadsdecompile.sh—Wrapper script handling APK/XAPK/JAR/AAR processing with configurable engines (jadx,vineflower, orboth)find-api-calls.sh—Searches decompiled source trees for Retrofit interfaces, OkHttp builders, hard-coded URLs, and authentication patterns
These scripts accept standardized arguments and return structured output suitable for Claude's context window.
Slash Command Definitions
User-facing commands are defined in plugins/android-reverse-engineering/commands/decompile.md. This file documents the /decompile slash command syntax, including required parameters like file paths and optional flags for engine selection. When users type /decompile path/to/app.apk in Claude Code, the system references this definition to validate arguments before executing the underlying scripts.
The Five-Phase Workflow in Practice
The project structure directly supports the workflow defined in SKILL.md through predictable file paths. Claude loads the plugin manifest, reads the skill definition to understand the five phases, then invokes scripts from the scripts/ directory to execute each phase sequentially.
The decompilation phase demonstrates this integration: the /decompile command triggers decompile.sh, which checks dependencies via check-deps.sh, extracts the APK contents using jadx (or vineflower), then passes the output directory to find-api-calls.sh for API extraction.
Practical Usage Examples
Execute the dependency verification script to ensure your environment supports the full workflow:
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/check-deps.sh
Install a missing decompiler using the automated installer:
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh jadx
Decompile an Android application using the default jadx engine:
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/decompile.sh app.apk
Run comparative analysis using both decompilation engines for redundancy:
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/decompile.sh \
--engine both app.apk
Extract API endpoints and authentication patterns from decompiled sources:
bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/find-api-calls.sh \
output/app-decompiled/sources/
Summary
- The repository follows Claude Code's standardized plugin hierarchy with root-level marketplace registration and nested operational code.
- Configuration flows from
.claude-plugin/marketplace.json(discovery) toplugin.json(runtime loading) toSKILL.md(workflow definition). - The
scripts/directory contains four Bash utilities implementing dependency management, installation, decompilation, and API extraction. - Reference documentation in
references/provides detailed guides for manual tool usage and analysis patterns. - User interaction occurs through the
/decompileslash command defined incommands/decompile.md, which orchestrates the five-phase workflow.
Frequently Asked Questions
What is the purpose of the marketplace.json file?
The .claude-plugin/marketplace.json file serves as the repository's registration entry for the Claude Plugin Marketplace, containing metadata required for indexing and display. This file enables users to discover the Android reverse engineering skill when browsing available Claude extensions, separate from the runtime configuration found in plugin.json.
How does the decompile.sh script handle different decompilation engines?
The decompile.sh script accepts an --engine parameter supporting three values: jadx (the default), vineflower (or fernflower), and both. When invoked with --engine both, the script runs both decompilers in parallel and produces output directories for each engine, allowing analysts to compare results and resolve obfuscation ambiguities by cross-referencing the generated Java source.
What is the difference between SKILL.md and README.md?
The README.md provides a high-level repository overview intended for GitHub visitors and new users, covering installation and general capabilities. In contrast, SKILL.md—located at plugins/android-reverse-engineering/skills/android-reverse-engineering/SKILL.md—contains the technical specification read by Claude Code, including the five-phase workflow definition, trigger phrases, and detailed behavioral instructions for the AI assistant.
Where are the API extraction patterns documented?
Detailed patterns for identifying Retrofit interfaces, OkHttp implementations, and hard-coded authentication tokens reside in plugins/android-reverse-engineering/skills/android-reverse-engineering/references/api-extraction-patterns.md. This file catalogs the regex patterns used by find-api-calls.sh and provides context for interpreting the discovered API structures within decompiled Android applications.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →