gmh5225/android-reverse-engineering-skill · Archived

android-reverse-engineering

Decompile Android APK/XAPK/JAR/AAR files and extract/document HTTP APIs (Retrofit/OkHttp/URLs) with a repeatable workflow.

First seen Mar 16, 2026

Installation

$ npx skills add gmh5225/android-reverse-engineering-skill --skill android-reverse-engineering

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1
License LICENSE
Default branch master
Status Archived

Skill metadata

Parsed from SKILL.md frontmatter.

Version1.0.0
Declared agents claude-code

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,397 B
  • docs SUMMARY.md 157 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 7 installs

SKILL.md

Android Reverse Engineering & API Extraction

This skill provides a structured workflow to:

  • decompile Android artifacts (APK/XAPK/JAR/AAR)
  • trace call flows from entry points to network layers
  • extract and document HTTP APIs (Retrofit endpoints, OkHttp calls, hardcoded URLs, auth patterns)

Prerequisites

  • Java JDK 17+
  • jadx (CLI)
  • Optional (recommended): Vineflower/Fernflower, dex2jar

Workflow (high-level)

  1. Decompile

- Use jadx first for a broad pass (resources + sources) - Use Fernflower/Vineflower for better Java output on tricky code; compare when needed

  1. Analyze structure

- Identify launcher Activity, Application class, and DI setup - Map packages: api, network, data, repository, service, retrofit, http

  1. Trace call flows

- UI entry point → ViewModel/Presenter → Repository → API service → HTTP client call

  1. Extract APIs

- Retrofit: interface annotations (@GET, @POST, …) - OkHttp: Request.Builder, HttpUrl, interceptors - URLs: string literals (http://, https://) and base URL builders

  1. Document endpoints

Use this template for each endpoint you discover:

### `METHOD /path`

- **Source**: `com.example.api.ApiService` (ApiService.java:42)
- **Base URL**: `https://api.example.com/v1`
- **Path params**: `id` (String)
- **Query params**: `page` (int), `limit` (int)
- **Headers**: `Authorization: Bearer <token>`
- **Request body**: `{ "email": "string", "password": "string" }`
- **Response**: `ApiResponse<User>`
- **Called from**: `LoginActivity → LoginViewModel → UserRepository → ApiService`

Notes

This repository is primarily a Claude Code plugin. The full implementation (scripts, references, and the /decompile slash command) lives under:

  • plugins/android-reverse-engineering/