
Reverse engineering and pentesting for Android applications

Androguard 5 is a Python toolkit for Android reverse engineering: open an APK, inspect the manifest and DEX, disassemble or decompile code, hunt references and vulnerabilities, and optionally patch or analyze native ARM — from the CLI, a high-level Application API, Claude Code skills, or an MCP server for LLM hosts.
apkparser-ag, dexparser-ag, axml)androguard[disasm]androguard[decompile]findrefs, vulnerability scanners, method emulation.so code via androguard[arm]androguard[patch]androguard-mcp) for Claude Code, Cursor, and other MCP clientsscan_vulns in docs/mastg-coverage.mdDo you think your phone has been pwned? Please check IsMyPhonePwned.
Androguard 5 is this repository. It is not the package currently published on PyPI (androguard 4.1.4). From a checkout, install the local tree. A bare pip install androguard or pip install 'androguard[full]' downloads 4.1.4 and uninstalls 5.0.0.
# from this repo (Rust toolchain required for the optional extras)
# Python 3.14+ needs the PyO3 forward-compat flag (bindings use PyO3 0.23, max 3.13)
export PYO3_USE_ABI3_FORWARD_COMPATIBILITY=1
# Rust apk-parser + dex-parser (siblings under ../)
pip install -e ../apk-parser
pip install -e ../dex-parser
pip install -e .
pip install -e '.[full]'
After 5.0.0 is published, the same extras install from PyPI:
pip install androguard
pip install 'androguard[full]'
[!IMPORTANT] Versions >= 4.0.0 are new releases after a long time, where the project has substantial differences from the previous stable version 3.3.5 from 2019. This means that certain functionalities have been removed. If you notice an issue with your project using the latest version, please open up an issue.
Androguard v5 is built on dedicated libraries:
| Layer | Library | Role |
|---|---|---|
| APK archive | apk-parser (apkparser-ag) | ZIP structure, signatures, manifest hooks |
| DEX structure | dex-parser (dexparser-ag) | Rust core + Python bindings: classes, methods, fields, bytecode |
| Binary XML / ARSC | axml / axml-parser (Rust) | AndroidManifest.xml, resources.arsc |
| Bytecode (optional) | dex-bytecode | Dalvik disassembly / CFG / patch via androguard[disasm] |
| Decompiler (optional) | dex-decompiler | DEX → Java, ASC getclass/findrefs, vulns via androguard[decompile] |
| ARM64 (optional) | arm_disassembler / arm_decompiler | Native code via androguard[arm] |
| APK patch (optional) | apk-patch | In-memory decode/build via androguard[patch] |
Runnable demos live in examples/ and are also executed by the
test suite (tests/test_examples.py):
python -m examples.application_summary
python -m examples.disassemble # androguard[disasm]
python -m examples.decompile # androguard[decompile]
python -m examples.arm # androguard[arm]
python -m examples.patch_decode # androguard[patch]
python -m examples.run_all
See examples/README.md.
This repo ships Claude Code project support (similar in spirit to areclaw, but driven by Androguard itself):
| Path | Role |
|---|---|
CLAUDE.md | Project instructions for the agent |
.claude/agents/androguard-analyst.md | Analyst agent |
.claude/skills/ | /analyze-apk, /decompile-apk, /find-refs, /scan-vulns |
workspace/ | Samples, decompiled output, reports |
claude /agent androguard-analyst
claude /analyze-apk path/to/app.apk
claude /decompile-apk path/to/app.apk com.example.app
Androguard can run as an MCP server so LLM hosts (Claude Code, Cursor, …) call typed analysis tools instead of shelling out to the CLI.
pip install -e '.[mcp,decompile]' # add [disasm] for disassembly tools
androguard-mcp # or: python -m androguard.mcp
Example client config:
{
"mcpServers": {
"androguard": {
"command": "androguard-mcp",
"env": {
"ANDROGUARD_MCP_ROOTS": "/path/to/androguard"
}
}
}
}
Typical flow: open_apk → session_id → list_classes / find_refs / decompile_method / scan_vulns.
On launch the server prints a stderr banner (versions, tools, path roots, extras). Use --log-tools to log each tool call, and --log-level DEBUG for more detail.
Full tool list, env vars, and security notes: docs/mcp-server.md. Design background: docs/mcp-server-plan.md.
# Summary: package, main activity, dex count, classes, methods
androguard -i my.apk
# List classes or methods
androguard -i my.apk --list-classes
androguard -i my.apk --list-methods
# Disassemble methods matching regex (requires androguard[disasm])
androguard -i my.apk --disasm --class 'TestActivity' --method 'onCreate'
androguard -i my.apk --disasm --class 'Ltests/androguard/.*' --method '<init>'
androguard -i my.apk --disasm --method 'onCreate' --limit 10
androguard -i my.apk --disasm --class TestActivity --method onCreate --cfg