An MCP server plugin for JADX that provides tools for decompiled code analysis, navigation, refactoring, and debugging through HTTP endpoints
This server defines 33 tools with HTTP transport. Most tools have basic descriptions (10-150 chars) and flat JSON input schemas. However, the implementation has significant gaps that prevent a higher score: (1) Descriptions are present but often minimal and lack context about when to use each tool or what distinguishes similar tools; (2) Many tools lack comprehensive parameter descriptions, parameters exist but lack guidance on format, constraints, or expected values; (3) Output schemas are not documented anywhere in the provided code, no field-level descriptions or structure details are visible; (4) Error handling is not evident in the route code snippets; (5) Security considerations (permission gates, input validation) are not documented; (6) Tool naming is generally good (verb-first: get_, search_, rename_, etc.) but some names are generic or ambiguous (e.g., 'health', 'cache-stats', 'cache-clear' could benefit from more context). The server appears to be a working JADX plugin integration, but the MCP interface definitions lack the depth, structure, and error guidance expected of production-grade agent tools.
Get list of all classes decompiled from APK by JADX with pagination support
Clear decompilation cache
Get statistics about decompilation cache usage
Get decompiled source code of a specific class by class name
Get currently open/active/visible class code in JADX UI
Get stack frames from the debugger when debugging is suspended
Get list of threads from the debugger with selected thread information
Get debug variables including registers and 'this' object when debugging is suspended
No output schemas documented. The provided tool specifications show only input parameters; return types, field names, and structures are invisible. This forces LLMs to infer output structure, risking misinterpretation and failed downstream tool calls.
Parameter descriptions are minimal or missing guidance. While parameters exist (e.g., 'class', 'limit', 'keyword'), many lack descriptions explaining format, constraints, or valid ranges. For example, 'limit' appears in multiple tools but has no min/max guidance; 'class_name' lacks clarification on whether it accepts short names or fully qualified names.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 58 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 51 | - | v1 |
Get list of all fields in a specific class with their details
Get content of a specific resource file from the APK
Health-check request to verify if the plugin server is running
Get list of all resource file names in the APK
Get the main activity class from AndroidManifest.xml
Get decompiled code of main application classes (non-library classes)
Get list of main application class names (non-library classes)
Get AndroidManifest.xml content from the decompiled APK
Get a method by name with optional class name and method signature filtering
Get list of all methods in a specific class with their details
Get hierarchical package tree structure of the decompiled code
Rename a class in the decompiled code
Rename a field in a class
Rename a method in a class
Rename a package in the decompiled code
Rename a variable in a method
Search classes by keyword in class name, method name, field name, code, or comments
Search for methods by keyword across all classes
Get progress of ongoing class search operation
Get currently selected text from the active UI component in JADX
Get Smali representation of a class
Get all string resources from the APK
Get cross-references (xrefs) to a class - where the class is used
Get cross-references (xrefs) to a field - where the field is accessed
Get cross-references (xrefs) to a method - where the method is called
Error handling is not evident in provided code. No indication of how tools report failures, what error messages are returned, or how LLMs should recover. Missing error guidance forces agents to retry blindly without understanding the root cause.
No tool annotations present. Tools lack readOnlyHint, destructiveHint, or idempotentHint. LLMs cannot determine which tools are safe to retry or which modify state without explicit declarations. For example, 'cache-clear' and rename tools are destructive but unmarked.
Insufficient context in tool descriptions. Many descriptions are terse (60-100 chars) and lack guidance on when to use each tool vs. similar alternatives. For example, 'search-classes-by-keyword' and 'search-method' perform different searches but this distinction is buried in brief descriptions. LLMs may conflate or misuse them.
No security or permission documentation. Tools that modify code (rename-*) and tools that clear caches lack any mention of required permissions, access controls, or audit requirements. No indication of how to handle unauthorized access attempts.
Pagination implementation unclear. Tools like 'all-classes' and 'strings' accept 'limit' and 'page' parameters, but no output schema documents whether results include total_count, next_cursor, or other pagination metadata. Without this, LLMs cannot reliably paginate through large result sets.
Generic naming for utility tools. 'health', 'cache-stats', and 'cache-clear' are vague. 'health' could mean app health, plugin health, or JADX process health. Descriptions should clarify scope and purpose.