# APKtool

> Use this tool when you need to analyze and reverse engineer Android APKs, solving problems such as decompilation, permission extraction, and smali code searching. It takes APK files as input and outputs decompiled data, manifest analysis, and permission audits, among other results. Ideal for mobile security research, malware analysis, and app modification projects, this tool streamlines Android application analysis workflows.

Canonical page: https://skillsregistry.net/skills/secfathy-apktool  
JSON: https://api.skillsregistry.net/v1/skills/secfathy-apktool

## Description

This MCP server provides complete Apktool integration for Android APK reverse engineering and analysis, enabling decompilation, recompilation, manifest analysis, permission extraction, and smali code searching through eight core tools. Built by SecFathy using Python with comprehensive error handling and resource management, it offers APK decoding with customizable options, framework installation for system apps, string resource extraction with locale support, permission auditing, pattern-based smali code analysis, and basic APK information retrieval using aapt when available. The implementation includes intelligent prompts for security analysis, privacy auditing, and reverse engineering workflows, plus resource access to decompiled APK data like AndroidManifest.xml and apktool.yml files, making it valuable for mobile security research, malware analysis, app modification projects, and building AI assistants that need deep Android application analysis capabilities without manual apktool command execution.

## Trust

- **Trust score (0–1):** 0.65
- **Verification tier:** scanned
- **Last scanned:** 2026-09-02

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-09-02

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/secfathy-apktool)
- **Repository:** <https://github.com/secfathy/apktool-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "secfathy-apktool"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/secfathy-apktool` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/secfathy-apktool/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
