# Key Directories and Files in the android-reverse-engineering-skill Project

> Explore the android-reverse-engineering-skill project's key directories like .claude-plugin and plugins/android-reverse-engineering. Understand JSON manifests scripts Bash utilities for APKs.

- Repository: [Simone Avogadro/android-reverse-engineering-skill](https://github.com/SimoneAvogadro/android-reverse-engineering-skill)
- Tags: getting-started
- Published: 2026-04-17

---

**The android-reverse-engineering-skill repository organizes its Claude Code plugin across `.claude-plugin/`, `plugins/android-reverse-engineering/skills/`, and executable `scripts/` directories, using JSON manifests for registration, Markdown references for reverse-engineering workflows, and Bash utilities for APK decompilation and API extraction.**

The **android-reverse-engineering-skill** project is a Claude Code plugin that exposes the `/decompile` slash command to analyze Android packages. Understanding the key directories and files in this repository reveals how the skill orchestrates dependency validation, decompilation via **jadx** and **Fernflower**, and HTTP API extraction. The layout cleanly isolates plugin metadata, skill logic, reference documentation, and reusable Bash utilities.

## Root-Level Metadata and Marketplace Configuration

The repository root contains standard project files plus a special directory that makes the plugin discoverable.

- **[`README.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/README.md)** and **`LICENSE`** – Provide project overview, quick-start instructions, and licensing terms.
- **[`.claude-plugin/marketplace.json`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/.claude-plugin/marketplace.json)** – The marketplace descriptor that registers the skill in the Claude Code ecosystem. This file tells the Claude marketplace that a plugin named *android-reverse-engineering* exists and is available for installation.

## Core Plugin Implementation

Located at `plugins/android-reverse-engineering/`, this directory houses the actual plugin code loaded by Claude Code.

- **[`plugins/android-reverse-engineering/.claude-plugin/plugin.json`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/plugins/android-reverse-engineering/.claude-plugin/plugin.json)** – The plugin manifest consumed by Claude Code at runtime. It defines the skill name, entry points, and available commands.
- **[`plugins/android-reverse-engineering/commands/decompile.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/plugins/android-reverse-engineering/commands/decompile.md)** – Documentation file rendered when users request help for the `/decompile` slash command. It describes accepted arguments (APK, JAR, AAR, or XAPK paths) and optional flags.

## Skill Logic and Workflow Documentation

The subdirectory `plugins/android-reverse-engineering/skills/android-reverse-engineering/` contains the operational brain of the plugin.

- **[`SKILL.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/SKILL.md)** – Defines the five-phase workflow executed on each invocation:
  1. Dependency check
  2. Decompilation
  3. Initial analysis
  4. API extraction
  5. Call-flow tracing

- **`references/`** – In-depth guides referenced by the skill UI:
  - [`setup-guide.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/setup-guide.md) – Environment preparation and tool installation.
  - [`jadx-usage.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/jadx-usage.md) – Command-line options and deobfuscation settings for jadx.
  - [`fernflower-usage.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/fernflower-usage.md) – Configuration for the Fernflower/Vineflower decompiler.
  - [`api-extraction-patterns.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/api-extraction-patterns.md) – Regex and AST patterns to detect Retrofit annotations, OkHttp builders, and hard-coded endpoints.
  - [`call-flow-analysis.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/call-flow-analysis.md) – Techniques for tracing authentication headers and request chains.

## Bash Scripts for Decompilation and Analysis

The `scripts/` directory contains the executable helpers that perform the heavy lifting. These scripts are called by the skill logic but can also run standalone.

- **[`check-deps.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/check-deps.sh)** – Validates the presence of required external binaries: JDK, **jadx**, **Fernflower** (or Vineflower), and **dex2jar**. Returns non-zero exit codes if any dependency is missing.

- **[`install-dep.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/install-dep.sh)** – Auto-installs missing tools using the host OS package manager. For example, `bash install-dep.sh jadx` downloads and installs the jadx decompiler.

- **[`decompile.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/decompile.sh)** – The core decompilation driver. It accepts an APK/JAR/AAR/XAPK path and supports flags such as `--engine jadx|fernflower|both` and `--deobf` to enable deobfuscation. Output is written to `output/sources/`.

- **[`find-api-calls.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/find-api-calls.sh)** – Scans decompiled Java sources for network-related signatures. Supports targeted extraction via `--retrofit`, `--okhttp`, `--urls`, or combinations thereof to identify hard-coded endpoints and authentication headers.

## How the Components Work Together

When a user invokes `/decompile path/to/app.apk`, Claude Code follows this resolution chain:

1. **[`marketplace.json`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/marketplace.json)** exposes the plugin to the marketplace.
2. **[`plugin.json`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/plugin.json)** loads the skill definition into the Claude session.
3. **[`SKILL.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/SKILL.md)** instructs Claude to execute the five-phase workflow.
4. **[`check-deps.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/check-deps.sh)** ensures the environment has JDK and decompilers available.
5. **[`decompile.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/decompile.sh)** generates Java sources using the requested engine (defaulting to jadx).
6. **[`find-api-calls.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/find-api-calls.sh)** analyzes `output/sources/` and returns a structured list of discovered API endpoints to the user.

## Practical Usage Examples

You can interact with the skill via the Claude Code interface or run the Bash scripts directly for automation pipelines.

### Using the Slash Command

```text
/decompile /path/to/my-app.apk

```

*The skill automatically validates dependencies, decompiles the APK with jadx, and returns extracted API endpoints.*

### Running Scripts Manually

```bash

# Verify environment

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/check-deps.sh

# Install missing jadx binary if check fails

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh jadx

# Decompile with both engines for comparison

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/decompile.sh \
    --engine both --deobf my-app.apk

# Extract Retrofit endpoints and hard-coded URLs

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/find-api-calls.sh \
    output/sources/ --retrofit --urls

```

## Summary

- **[`.claude-plugin/marketplace.json`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/.claude-plugin/marketplace.json)** registers the plugin in the Claude Code marketplace.
- **[`plugins/android-reverse-engineering/.claude-plugin/plugin.json`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/plugins/android-reverse-engineering/.claude-plugin/plugin.json)** provides the runtime manifest.
- **[`SKILL.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/SKILL.md)** defines the five-phase decompilation and analysis workflow.
- **`references/`** contains detailed guides for setup, tool usage, and API extraction patterns.
- **`scripts/`** holds executable Bash utilities ([`check-deps.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/check-deps.sh), [`install-dep.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/install-dep.sh), [`decompile.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/decompile.sh), [`find-api-calls.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/find-api-calls.sh)) that perform dependency management, decompilation, and static analysis.
- **[`commands/decompile.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/commands/decompile.md)** documents the `/decompile` slash command interface.

## Frequently Asked Questions

### What is the purpose of the [`.claude-plugin/marketplace.json`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/.claude-plugin/marketplace.json) file?

The [`marketplace.json`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/marketplace.json) file acts as a public descriptor that makes the skill discoverable within the Claude Code marketplace. It contains metadata such as the plugin name, version, and description, allowing users to search for and install the android-reverse-engineering-skill without manually cloning the repository.

### How does the [`decompile.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/decompile.sh) script handle different decompilation engines?

The [`decompile.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/decompile.sh) script accepts an `--engine` parameter that accepts `jadx`, `fernflower`, or `both`. When `both` is specified, the script runs the APK through jadx and Fernflower/Vineflower sequentially, writing outputs to separate subdirectories under `output/sources/` so analysts can compare decompilation quality. The `--deobf` flag enables automatic deobfuscation renaming for jadx.

### Where can I find documentation on API extraction patterns?

Documentation for identifying Retrofit interfaces, OkHttp builders, and hard-coded URLs resides in **[`plugins/android-reverse-engineering/skills/android-reverse-engineering/references/api-extraction-patterns.md`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/plugins/android-reverse-engineering/skills/android-reverse-engineering/references/api-extraction-patterns.md)**. This file catalogs regex patterns and AST signatures used by the [`find-api-calls.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/find-api-calls.sh) script to locate network-related code in decompiled sources.

### Can I run the scripts independently without Claude Code?

Yes. All Bash scripts in `plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/` are standalone executables. You can invoke [`check-deps.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/check-deps.sh), [`decompile.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/decompile.sh), and [`find-api-calls.sh`](https://github.com/SimoneAvogadro/android-reverse-engineering-skill/blob/main/find-api-calls.sh) directly from the terminal to integrate Android reverse engineering into CI/CD pipelines or custom automation workflows without launching the Claude Code interface.