Key Directories and Files in the android-reverse-engineering-skill Project

The android-reverse-engineering-skill repository organizes its Claude Code plugin across .claude-plugin/, plugins/android-reverse-engineering/skills/, and executable scripts/ directories, using JSON manifests for registration, Markdown references for reverse-engineering workflows, and Bash utilities for APK decompilation and API extraction.

The android-reverse-engineering-skill project is a Claude Code plugin that exposes the /decompile slash command to analyze Android packages. Understanding the key directories and files in this repository reveals how the skill orchestrates dependency validation, decompilation via jadx and Fernflower, and HTTP API extraction. The layout cleanly isolates plugin metadata, skill logic, reference documentation, and reusable Bash utilities.

Root-Level Metadata and Marketplace Configuration

The repository root contains standard project files plus a special directory that makes the plugin discoverable.

  • README.md and LICENSE – Provide project overview, quick-start instructions, and licensing terms.
  • .claude-plugin/marketplace.json – The marketplace descriptor that registers the skill in the Claude Code ecosystem. This file tells the Claude marketplace that a plugin named android-reverse-engineering exists and is available for installation.

Core Plugin Implementation

Located at plugins/android-reverse-engineering/, this directory houses the actual plugin code loaded by Claude Code.

Skill Logic and Workflow Documentation

The subdirectory plugins/android-reverse-engineering/skills/android-reverse-engineering/ contains the operational brain of the plugin.

  • SKILL.md – Defines the five-phase workflow executed on each invocation:

    1. Dependency check
    2. Decompilation
    3. Initial analysis
    4. API extraction
    5. Call-flow tracing
  • references/ – In-depth guides referenced by the skill UI:

Bash Scripts for Decompilation and Analysis

The scripts/ directory contains the executable helpers that perform the heavy lifting. These scripts are called by the skill logic but can also run standalone.

  • check-deps.sh – Validates the presence of required external binaries: JDK, jadx, Fernflower (or Vineflower), and dex2jar. Returns non-zero exit codes if any dependency is missing.

  • install-dep.sh – Auto-installs missing tools using the host OS package manager. For example, bash install-dep.sh jadx downloads and installs the jadx decompiler.

  • decompile.sh – The core decompilation driver. It accepts an APK/JAR/AAR/XAPK path and supports flags such as --engine jadx|fernflower|both and --deobf to enable deobfuscation. Output is written to output/sources/.

  • find-api-calls.sh – Scans decompiled Java sources for network-related signatures. Supports targeted extraction via --retrofit, --okhttp, --urls, or combinations thereof to identify hard-coded endpoints and authentication headers.

How the Components Work Together

When a user invokes /decompile path/to/app.apk, Claude Code follows this resolution chain:

  1. marketplace.json exposes the plugin to the marketplace.
  2. plugin.json loads the skill definition into the Claude session.
  3. SKILL.md instructs Claude to execute the five-phase workflow.
  4. check-deps.sh ensures the environment has JDK and decompilers available.
  5. decompile.sh generates Java sources using the requested engine (defaulting to jadx).
  6. find-api-calls.sh analyzes output/sources/ and returns a structured list of discovered API endpoints to the user.

Practical Usage Examples

You can interact with the skill via the Claude Code interface or run the Bash scripts directly for automation pipelines.

Using the Slash Command

/decompile /path/to/my-app.apk

The skill automatically validates dependencies, decompiles the APK with jadx, and returns extracted API endpoints.

Running Scripts Manually


# Verify environment

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/check-deps.sh

# Install missing jadx binary if check fails

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh jadx

# Decompile with both engines for comparison

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/decompile.sh \
    --engine both --deobf my-app.apk

# Extract Retrofit endpoints and hard-coded URLs

bash plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/find-api-calls.sh \
    output/sources/ --retrofit --urls

Summary

Frequently Asked Questions

What is the purpose of the .claude-plugin/marketplace.json file?

The marketplace.json file acts as a public descriptor that makes the skill discoverable within the Claude Code marketplace. It contains metadata such as the plugin name, version, and description, allowing users to search for and install the android-reverse-engineering-skill without manually cloning the repository.

How does the decompile.sh script handle different decompilation engines?

The decompile.sh script accepts an --engine parameter that accepts jadx, fernflower, or both. When both is specified, the script runs the APK through jadx and Fernflower/Vineflower sequentially, writing outputs to separate subdirectories under output/sources/ so analysts can compare decompilation quality. The --deobf flag enables automatic deobfuscation renaming for jadx.

Where can I find documentation on API extraction patterns?

Documentation for identifying Retrofit interfaces, OkHttp builders, and hard-coded URLs resides in plugins/android-reverse-engineering/skills/android-reverse-engineering/references/api-extraction-patterns.md. This file catalogs regex patterns and AST signatures used by the find-api-calls.sh script to locate network-related code in decompiled sources.

Can I run the scripts independently without Claude Code?

Yes. All Bash scripts in plugins/android-reverse-engineering/skills/android-reverse-engineering/scripts/ are standalone executables. You can invoke check-deps.sh, decompile.sh, and find-api-calls.sh directly from the terminal to integrate Android reverse engineering into CI/CD pipelines or custom automation workflows without launching the Claude Code interface.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →