Extract Android app APIs with a Claude Code reverse-engineering skill
Use this Claude Code skill to decompile APK, XAPK, JAR, and AAR files, recover Kotlin names, and extract Android HTTP API behavior for authorized analysis.
npx skills add agentskillexchange/skills --skill extract-android-app-apis-with-a-claude-code-reverse-engineering-skill
Use Android Reverse Engineering Skill when an agent is asked to inspect an Android application without original source code and produce usable reverse-engineering evidence. The workflow fingerprints APK or XAPK files, checks jadx and optional decompiler dependencies, decompiles Android artifacts, recovers R8-obfuscated Kotlin class names from metadata, extracts Retrofit, OkHttp, Volley, Ktor, Apollo GraphQL, Koin, URL, header, token, and signing patterns, and traces call flows from UI classes to network code. Invoke this instead of using the product normally when the operator needs Claude Code to run a repeatable, documented, lawful analysis workflow around a concrete app artifact and return source-backed API findings. The scope boundary is authorized Android reverse engineering and API extraction inside Claude Code; it is not a generic mobile testing framework, a standalone jadx listing, a broad security platform, or permission to analyze apps without legal authority.
What this skill actually does
Inputs and prerequisites: Claude Code plugin marketplace support, Java JDK 17+, jadx CLI, optional Vineflower or Fernflower, optional dex2jar, and an Android APK, XAPK, JAR, or AAR artifact the operator is authorized to analyze.
Setup notes: In Claude Code, run /plugin marketplace add SimoneAvogadro/android-reverse-engineering-skill, then /plugin install android-reverse-engineering@android-reverse-engineering-skill. Install Java JDK 17+ and jadx, add optional Vineflower/Fernflower and dex2jar for deeper analysis, then invoke /decompile path/to/app.apk or ask Claude Code to extract API endpoints from an authorized Android artifact.
Source and verification boundary: use https://github.com/SimoneAvogadro/android-reverse-engineering-skill as the canonical reference before running the workflow; keep commands, API calls, CLI usage, and generated outputs reviewable against that upstream source.
Framework fit: publish this as a Claude Code workflow only when the operator can invoke the documented toolchain directly, rather than treating the upstream project as a generic product listing.