Android Security Analyzer

MCP server for static security analysis of Android source code

Should I use this

Quality & Safety

A
Description quality
93%
Schema completeness
80%
Naming quality
90%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (1)

  • LOWTool 'health' description lacks action verbin health

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~466Tokens (tool definitions)
~973 BTypical response size
Minimal attention impact (0.36% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "android-security-analyzer": {
      "url": "https://android-security-analyzer.ako-labs.workers.dev/mcp"
    }
  }
}

Remote endpoints

https://android-security-analyzer.ako-labs.workers.dev/mcpstreamable-http

What it can do

Tool inventory

Tools (4)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢analyze_android_project(projectName, files, options)

Analyzes an Android project's source code for security vulnerabilities. Accepts project files (AndroidManifest.xml, build.gradle, Java/Kotlin sources, XML configs) and returns a structured security report with findings, severity scores, and recommendations.

Input Schema

{
  "type": "object",
  "properties": {
    "projectName": {
      "type": "string",
      "description": "Name of the Android project being analyzed"
    },
    "files": {
      "type": "array",
      "description": "Array of project files to analyze",
      "items": {
        "type": "object",
        "required": [
          "path",
          "content"
        ],
        "properties": {
          "path": {
            "type": "string",
            "description": "Relative file path within the project (e.g., app/src/main/AndroidManifest.xml)"
          },
          "content": {
            "type": "string",
            "description": "File content as text"
          }
        }
      }
    },
    "options": {
      "type": "object",
      "description": "Analysis options",
      "properties": {
        "includeInfoLevel": {
          "type": "boolean",
          "description": "Include informational findings (default: true)"
        },
        "maxFileSizeKb": {
          "type": "number",
          "description": "Maximum file size in KB to process (default: 512)"
        },
        "enableSecretScan": {
          "type": "boolean",
          "description": "Enable secret/credential scanning (default: true)"
        }
      }
    }
  },
  "required": [
    "projectName",
    "files"
  ]
}
🟢list_android_security_checks(category)

Returns the list of all implemented security checks/rules with their IDs, categories, severity levels, and descriptions.

Input Schema

{
  "type": "object",
  "properties": {
    "category": {
      "type": "string",
      "description": "Filter rules by category (manifest, gradle, source, xml-config, secret). Leave empty for all rules.",
      "enum": [
        "manifest",
        "gradle",
        "source",
        "xml-config",
        "secret"
      ]
    }
  }
}
🟢explain_finding(findingId)

Explains a specific security finding by its rule ID. Returns why it is a risk, how to fix it, and false positive considerations.

Input Schema

{
  "type": "object",
  "properties": {
    "findingId": {
      "type": "string",
      "description": "The rule/finding ID (e.g., MAN-001, SRC-003, SEC-002)"
    }
  },
  "required": [
    "findingId"
  ]
}
⚪health

Returns the server health status, version, and rule engine statistics.

Input Schema

{
  "type": "object",
  "properties": {}
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded4 tools
verifiedversion not recorded4 tools
verifiedversion not recorded4 tools