Android Reverse Engineering Skill Repository Project Structure Explained

The SimoneAvogadro/android-reverse-engineering-skill repository organizes its Claude Code plugin as a hierarchical structure that separates marketplace metadata, skill definitions, automation scripts, and reference documentation into distinct, navigable directories.

The SimoneAvogadro/android-reverse-engineering-skill repository packages a complete Android reverse engineering workflow as a Claude Code plugin. Its project structure follows strict conventions required by the Claude Plugin Marketplace while providing modular access to decompilation tools and analysis scripts. The layout centers on a single plugin directory that encapsulates everything needed to execute a five-phase reverse engineering pipeline.

Root-Level Configuration and Marketplace Metadata

The repository root contains two critical entry points for discovery and usage. The .claude-plugin/marketplace.json file registers the repository in the Claude Plugin Marketplace, declaring the plugin's name, version, and visibility. This JSON file allows Claude to index and display the skill to users browsing available extensions.

Alongside this configuration, the README.md provides the public-facing documentation with installation instructions, a high-level overview of capabilities, and a condensed repository structure diagram. These root files serve as the gateway, but contain no executable logic—all functional components reside deeper in the hierarchy.

Core Plugin Architecture

All operational code lives within plugins/android-reverse-engineering/, following Claude Code's nested convention for plugin isolation. This directory contains the complete runtime environment for the Android reverse engineering skill.

Plugin Manifest Declaration

The plugins/android-reverse-engineering/.claude-plugin/plugin.json file declares the plugin's identity and entry points to the Claude runtime. This manifest specifies the plugin name (android-reverse-engineering), version constraints, and initialization parameters required for Claude to load and activate the skill correctly.

Skill Definition and Workflow Documentation

At plugins/android-reverse-engineering/skills/android-reverse-engineering/SKILL.md, the repository stores the authoritative skill specification. This markdown file defines the five-phase workflow that governs all reverse engineering operations:

  1. Dependency verification—ensuring Java JDK 17+ and decompilers are available
  2. Decompilation—converting APK/XAPK/JAR/AAR files to readable source
  3. Structure analysis—mapping package hierarchies and entry points
  4. Call-flow tracing—identifying execution paths between components
  5. API extraction—locating Retrofit interfaces, OkHttp clients, and hard-coded endpoints

The SKILL.md file also contains trigger phrases that activate the skill when users mention specific keywords related to Android analysis.

Reference Documentation Directory

The references/ subdirectory within the skill folder contains specialized guides for tool usage and methodology:

These files support both the automation scripts and human users performing manual analysis.

Automation Scripts Implementation

The scripts/ directory contains four Bash utilities that implement the SKILL.md workflow phases:

  • check-deps.sh—Validates the presence of Java JDK 17+, jadx, and optionally vineflower/dex2jar
  • install-dep.sh—Cross-platform dependency installer supporting apt, yum, and manual downloads
  • decompile.sh—Wrapper script handling APK/XAPK/JAR/AAR processing with configurable engines (jadx, vineflower, or both)
  • find-api-calls.sh—Searches decompiled source trees for Retrofit interfaces, OkHttp builders, hard-coded URLs, and authentication patterns

These scripts accept standardized arguments and return structured output suitable for Claude's context window.

Slash Command Definitions

User-facing commands are defined in plugins/android-reverse-engineering/commands/decompile.md. This file documents the /decompile slash command syntax, including required parameters like file paths and optional flags for engine selection. When users type /decompile path/to/app.apk in Claude Code, the system references this definition to validate arguments before executing the underlying scripts.

The Five-Phase Workflow in Practice

The project structure directly supports the workflow defined in SKILL.md through predictable file paths. Claude loads the plugin manifest, reads the skill definition to understand the five phases, then invokes scripts from the scripts/ directory to execute each phase sequentially.

The decompilation phase demonstrates this integration: the /decompile command triggers decompile.sh, which checks dependencies via check-deps.sh, extracts the APK contents using jadx (or vineflower), then passes the output directory to find-api-calls.sh for API extraction.

Practical Usage Examples

Execute the dependency verification script to ensure your environment supports the full workflow:

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/check-deps.sh

Install a missing decompiler using the automated installer:

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh jadx

Decompile an Android application using the default jadx engine:

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/decompile.sh app.apk

Run comparative analysis using both decompilation engines for redundancy:

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/decompile.sh \
    --engine both app.apk

Extract API endpoints and authentication patterns from decompiled sources:

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/find-api-calls.sh \
    output/app-decompiled/sources/

Summary

  • The repository follows Claude Code's standardized plugin hierarchy with root-level marketplace registration and nested operational code.
  • Configuration flows from .claude-plugin/marketplace.json (discovery) to plugin.json (runtime loading) to SKILL.md (workflow definition).
  • The scripts/ directory contains four Bash utilities implementing dependency management, installation, decompilation, and API extraction.
  • Reference documentation in references/ provides detailed guides for manual tool usage and analysis patterns.
  • User interaction occurs through the /decompile slash command defined in commands/decompile.md, which orchestrates the five-phase workflow.

Frequently Asked Questions

What is the purpose of the marketplace.json file?

The .claude-plugin/marketplace.json file serves as the repository's registration entry for the Claude Plugin Marketplace, containing metadata required for indexing and display. This file enables users to discover the Android reverse engineering skill when browsing available Claude extensions, separate from the runtime configuration found in plugin.json.

How does the decompile.sh script handle different decompilation engines?

The decompile.sh script accepts an --engine parameter supporting three values: jadx (the default), vineflower (or fernflower), and both. When invoked with --engine both, the script runs both decompilers in parallel and produces output directories for each engine, allowing analysts to compare results and resolve obfuscation ambiguities by cross-referencing the generated Java source.

What is the difference between SKILL.md and README.md?

The README.md provides a high-level repository overview intended for GitHub visitors and new users, covering installation and general capabilities. In contrast, SKILL.md—located at plugins/android-reverse-engineering/skills/android-reverse-engineering/SKILL.md—contains the technical specification read by Claude Code, including the five-phase workflow definition, trigger phrases, and detailed behavioral instructions for the AI assistant.

Where are the API extraction patterns documented?

Detailed patterns for identifying Retrofit interfaces, OkHttp implementations, and hard-coded authentication tokens reside in plugins/android-reverse-engineering/skills/android-reverse-engineering/references/api-extraction-patterns.md. This file catalogs the regex patterns used by find-api-calls.sh and provides context for interpreting the discovered API structures within decompiled Android applications.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →