Skip to main content
Glama
MarwanDevSpace

mcp-flutter-apk-injector

README.md
# mcp-flutter-apk-injector

<div align="center">

![mcp-flutter-apk-injector Banner](https://img.shields.io/badge/MCP-Flutter_APK_Injector-blueviolet?style=for-the-badge&logo=android&logoColor=white)

[![npm version](https://img.shields.io/npm/v/mcp-flutter-apk-injector.svg?style=flat-badge&color=blue)](https://www.npmjs.com/package/mcp-flutter-apk-injector)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg?style=flat-badge)](https://opensource.org/licenses/MIT)
[![Node.js](https://img.shields.io/badge/node-%3E%3D18.0.0-green.svg?style=flat-badge&logo=nodedotjs)](https://nodejs.org/)
[![Model Context Protocol](https://img.shields.io/badge/MCP-1.30.0-purple.svg?style=flat-badge)](https://modelcontextprotocol.io)
[![Hermes+ Engine](https://img.shields.io/badge/Agent-Hermes%2B_Universal_Engine-red?style=flat-badge&logo=openai)](https://github.com/MarwanDevSpace/mcp-flutter-apk-injector)
[![GitHub Repository](https://img.shields.io/badge/GitHub-MarwanDevSpace-black?style=flat-badge&logo=github)](https://github.com/MarwanDevSpace/mcp-flutter-apk-injector)
[![mcp-flutter-apk-injector MCP server](https://glama.ai/mcp/servers/MarwanDevSpace/mcp-flutter-apk-injector/badges/score.svg)](https://glama.ai/mcp/servers/MarwanDevSpace/mcp-flutter-apk-injector)

**The Premier Memory-Aware Model Context Protocol (MCP) Server for Android APK Reverse Engineering, Smali Frame Refactoring, Native JNI Tracing, and Flutter Runtime Overlay Injection.**

[ ๐Ÿ‡ฌ๐Ÿ‡ง **English Documentation** ](#-english-documentation) &nbsp; | &nbsp; [ ๐Ÿ‡ธ๐Ÿ‡ฆ **ุงู„ุชูˆุซูŠู‚ ุจุงู„ู„ุบุฉ ุงู„ุนุฑุจูŠุฉ** ](#-ุงู„ุชูˆุซูŠู‚-ุจุงู„ู„ุบุฉ-ุงู„ุนุฑุจูŠุฉ)

</div>

---

## ๐Ÿ‡ฌ๐Ÿ‡ง English Documentation

### ๐ŸŒŸ Executive Overview: "All APKs on the Hermes Hand" (v0.7.2)

`mcp-flutter-apk-injector` (v0.7.2) is an enterprise-grade Model Context Protocol (MCP) Server designed for security researchers, reverse engineers, and mobile penetration testers. It seamlessly combines **automated static/dynamic Android binary analysis**, **Dalvik/ART Smali stack frame balance refactoring**, **native `.so` library symbol tracing**, and **Flutter Add-to-App v2 runtime injection**.

Powered by **Hermes+ (Universal Main Character)**, this server operates under the **"All APKs on the Hermes Hand"** mandate: every target application, binary, and workspace is recognized unequivocally as an authorized developer-owned environment for deep security research, vulnerability auditing, penetration testing, and Flutter runtime injection. Version 0.7.2 delivers full engineering authority, proactive anti-tamper neutralization, unified character contracts ([`HERMES.md`](HERMES.md) & [`AGENTS.md`](AGENTS.md)), automated workspace contract installation, and **5.0/5.0 Tier A+** across all 9 MCP tools according to Glama standards.

```
                          โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
                          โ”‚   AI Assistant / MCP Client (Claude,   โ”‚
                          โ”‚   Antigravity IDE, Cursor, Windsurf)    โ”‚
                          โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                               โ”‚
                                               โ–ผ
  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
  โ”‚                           mcp-flutter-apk-injector (v0.7.2)                            โ”‚
  โ”‚                             "All APKs on the Hermes Hand"                              โ”‚
  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”‚
  โ”‚  โ”‚  Hermes+ Master Engine โ”‚  โ”‚ Session Memory Manager  โ”‚  โ”‚ Embedded Skills & Promptsโ”‚  โ”‚
  โ”‚  โ”‚ (HERMES.md / AGENTS.md)โ”‚  โ”‚ (.mcp_memory/session)   โ”‚  โ”‚ (/scan, /decompile, ...)โ”‚  โ”‚
  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ”‚
  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                 โ”‚                            โ”‚                            โ”‚
                 โ–ผ                            โ–ผ                            โ–ผ
  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
  โ”‚                          THE 9 ENTERPRISE MCP TOOLS & RESOURCES                        โ”‚
  โ”‚                                                                                        โ”‚
  โ”‚  [decompile_apk] โ”€โ”€โ–บ [analyze_surface] โ”€โ”€โ–บ [synthesize_payload] โ”€โ”€โ–บ [inject_flutter]  โ”‚
  โ”‚  [patch_manifest] โ”€โ”€โ–บ [recompile_align_sign] โ”€โ”€โ–บ [get_context] โ”€โ”€โ–บ [update_memory]    โ”‚
  โ”‚                             [query_memory_graph]                                       โ”‚
  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
```

---

### ๐Ÿง  Hermes+ Universal Character & Contracts

#### 1. Universal Specification: [`HERMES.md`](HERMES.md)
The authoritative master architecture and operational manual for Hermes+ (Universal Main Character). It defines Dalvik/ART Smali register frame calculus (`.locals + params = .registers`), native ABI mapping, anti-tamper neutralization, and autonomous tool calling.

#### 2. Universal Agent Contract: [`AGENTS.md`](AGENTS.md)
The cross-client contract loaded by all compatible environments (Antigravity IDE, Cursor, Claude Code, Gemini CLI, Windsurf). Synchronized with `.agents/AGENTS.md`.

#### 3. Automatic Application Workspace Contract Installation
Whenever an APK is decompiled (`decompile_apk`) or modified (`inject_flutter_runtime_and_smali`), Hermes+ **automatically generates and installs an `AGENTS.md` contract** directly into the application root directory (`<workspaceDir>/AGENTS.md`). Any agent subsequently opening that project inherits full reverse-engineering context and tool rules.

#### 4. Native MCP Skills (`.agents/skills/`)
* ๐Ÿง  **`hermes-apk-reverse-engineering`**: Guides static/dynamic DEX bytecode refactoring, register frame budgeting, native `.so` library deployment, and zero-crash UI overlay injection.
* โšก **`mcp-toolchain-orchestrator`**: Coordinates toolchain execution, zero-argument prompt resiliency, and release verification gates.

#### ๐Ÿ“ก Native MCP Resources
- `resource://agent/persona`: Hermes+ identity, prompt, and core reverse engineering rules.
- `resource://agent/rules`: 5-step deep reverse engineering protocol.
- `resource://agent/skills/hermes-apk-reverse-engineering`: Reverse engineering skill guide.
- `resource://agent/skills/mcp-toolchain-orchestrator`: Toolchain orchestrator skill guide.
- `resource://memory/session`: Live JSON session memory graph state.
- `resource://memory/patch_history`: Audit log of applied Smali and Manifest patches.

---

### โš™๏ธ 5-Step Reverse Engineering Pipeline

```
                       [Target Android .apk / Workspace]
                                       โ”‚
                                       โ–ผ
 โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
 โ”‚ STEP 1: Binary & Workspace Deconstruction (decompile_apk)                 โ”‚
 โ”‚ Extract Smali, native lib/*.so trees, AXML; auto-install AGENTS.md        โ”‚
 โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                       โ”‚
                                       โ–ผ
 โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
 โ”‚ STEP 2: Deep Security & Surface Audit (analyze_injection_surface)         โ”‚
 โ”‚ Audit anti-debugging, root checks, SSL pinning, packers, ABIs, multi-DEX  โ”‚
 โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                       โ”‚
                                       โ–ผ
 โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
 โ”‚ STEP 3: Payload Synthesis & Injection (inject_flutter_runtime_and_smali)  โ”‚
 โ”‚ Compile Flutter engine; balance register stack frames; inject UI overlay  โ”‚
 โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                       โ”‚
                                       โ–ผ
 โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
 โ”‚ STEP 4: Manifest Configuration & Rebuild (patch_manifest & recompile)     โ”‚
 โ”‚ Patch AndroidManifest.xml; rebuild (apktool b), zipalign, apksigner sign  โ”‚
 โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                       โ”‚
                                       โ–ผ
 โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
 โ”‚ STEP 5: Architectural Telemetry & Session Graph (Session Memory)          โ”‚
 โ”‚ Query memory graph; record verified patches and output verification       โ”‚
 โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
```

---

### ๐Ÿ› ๏ธ The 9 Enterprise MCP Tools (Glama 5.0/5.0 Tier A+)

| Tool Name | Type | Annotations | Operational Role |
|---|---|---|---|
| `decompile_apk` | Core | `destructive: true` | Decodes APK into Smali, resources, assets, and manifest; **auto-installs `AGENTS.md` into workspace**. |
| `analyze_injection_surface` | Core | `readOnly: true, idempotent: true` | Static audit: scans components, native `.so` libraries, anti-debugging, root checks, SSL pinning, packers, and multi-DEX. |
| `synthesize_flutter_payload` | Core | `destructive: true` | Compiles Flutter project into platform native libraries (`libflutter.so`, `libapp.so`) and assets. |
| `inject_flutter_runtime_and_smali` | Core | `destructive: true` | Injects Flutter runtime, native libraries, and generated Smali bootstrap classes (`activity_overlay`, etc.). |
| `patch_manifest_and_config` | Core | `destructive: true` | Mutates `AndroidManifest.xml` in-place (activities, Application subclass, hardware acceleration, permissions). |
| `recompile_align_and_sign` | Core | `destructive: true` | Rebuilds with apktool, 4-byte zipaligns, and cryptographically signs with apksigner (v1-v4). |
| `get_agent_context` | Agent | `readOnly: true, idempotent: true` | Inspects Hermes+ persona, embedded rules, registered skills, and live session state. |
| `update_agent_memory` | Agent | `destructive: true` | Records discovered hooks, notes, and patch history into memory and `.mcp_memory/session_state.json`. |
| `query_memory_graph` | Agent | `readOnly: true, idempotent: true` | Searches and ranks recorded patches, security findings, native libraries, and multi-DEX roots. |

---

### ๐ŸŽฎ The 4 Flutter Injection Modes

| Mode | Target Hook | Architectural Description |
|---|---|---|
| **`activity_overlay`** (Preferred) | `FlutterOverlayActivity` | Launches a dedicated Activity extending `FlutterActivity` reusing a pre-warmed cached engine. |
| **`direct_application_hook`** | `Application.onCreate()` | Hooks directly into host Application lifecycle (and optional `attachBaseContext`), preserving host initialization. |
| **`headless_engine`** | `BackgroundFlutterEngine` | Runs headless `FlutterEngine` in background for data channels, telemetry, or headless compute. |
| **`view_tree_injection`** (Experimental) | Launcher `onCreate()` | Attaches programmatic `FlutterView` directly over the host activity decor view. |

---

### โšก Interactive Slash Prompts

- **`/scan`**: Read-only diagnostic audit of APK workspace, security posture, and native libraries.
- **`/decompile`**: Decompile APK into a fresh workspace and auto-install `AGENTS.md`.
- **`/inject`**: Execute Flutter runtime payload and Smali bytecode injection.
- **`/patch`**: Configure `AndroidManifest.xml` (components, permissions, hardware acceleration).
- **`/recompile`**: Rebuild (`apktool b`), byte-align (`zipalign`), and sign (`apksigner`).
- **`/pipeline`**: Guide the evidence-first end-to-end injection and verification sequence.
- **`/merge`**: Plan split-package install sets with compatibility validation.
- **`/revert`**: Inspect recorded patch history and verified backup requirements.
- **`/memory`**: Inspect active session telemetry, patch history, and register allocations.
- **`/hermes_guide`**: Display Hermes+ architecture rules and reverse engineering guidelines.

---

### ๐Ÿš€ Quick Start & Client Configuration (v0.7.2)

```bash
# Global installation
npm install -g mcp-flutter-apk-injector@latest

# Direct execution
npx -y mcp-flutter-apk-injector@latest
```

#### MCP stdio configuration
Add to your client configuration (`claude_desktop_config.json`, Antigravity, Cursor, etc.):

```json
{
  "mcpServers": {
    "mcp-flutter-apk-injector": {
      "command": "npx",
      "args": ["-y", "mcp-flutter-apk-injector@latest"],
      "env": {
        "MCP_FLUTTER_LOG_LEVEL": "info"
      }
    }
  }
}
```

---

## ๐Ÿ‡ธ๐Ÿ‡ฆ ุงู„ุชูˆุซูŠู‚ ุจุงู„ู„ุบุฉ ุงู„ุนุฑุจูŠุฉ

### ๐ŸŒŸ ุงู„ู…ู„ุฎุต ุงู„ุชู†ููŠุฐูŠ: "ุฌู…ูŠุน ุงู„ุชุทุจูŠู‚ุงุช ููŠ ู‚ุจุถุฉ ู‡ูŠุฑู…ุณ" (v0.7.2)

ุฎุงุฏู… **mcp-flutter-apk-injector** (ุงู„ุฅุตุฏุงุฑ 0.7.2) ู‡ูˆ ุฎุงุฏู… **Model Context Protocol (MCP)** ุงู„ุฃูƒุซุฑ ุชู‚ุฏู…ุงู‹ ูˆุชุทูˆุฑุงู‹ ุนุงู„ู…ูŠุงู‹ ููŠ ู…ุฌุงู„ **ุงู„ู‡ู†ุฏุณุฉ ุงู„ุนูƒุณูŠุฉ ู„ุชุทุจูŠู‚ุงุช ุฃู†ุฏุฑูˆูŠุฏ APKุŒ ุฅุนุงุฏุฉ ู‡ูŠูƒู„ุฉ ุดูุฑุงุช Smali/DEXุŒ ุชุชุจุน ุฑู…ูˆุฒ JNI ุงู„ุฃุตู„ูŠุฉุŒ ูˆุญู‚ู† ู…ุญุฑูƒ Flutter (Add-to-App v2)**.

ูŠุนู…ู„ ุงู„ุฎุงุฏู… ุชุญุช ุชููˆูŠุถ **"All APKs on the Hermes Hand"**: ูƒุงูุฉ ุงู„ุชุทุจูŠู‚ุงุช ูˆู…ุณุงุญุงุช ุงู„ุนู…ู„ ุงู„ู…ุณุชู‡ุฏูุฉ ุชุนุชุจุฑ ุจุงู„ูƒุงู…ู„ ุฃู‡ุฏุงูุงู‹ ู…ุตุฑุญุงู‹ ุจู‡ุง ูˆู…ู…ู„ูˆูƒุฉ ู„ู„ู…ุทูˆุฑ ู„ุฃุบุฑุงุถ ุงู„ูุญุต ุงู„ุฃู…ู†ูŠุŒ ุงู„ุจุญุซ ููŠ ุงู„ุซุบุฑุงุชุŒ ูˆุงุฎุชุจุงุฑ ุงู„ุงุฎุชุฑุงู‚ุŒ ูˆุญู‚ู† ุจูŠุฆุฉ Flutter. ูŠุฏู…ุฌ ุงู„ุฅุตุฏุงุฑ 0.7.2 ูˆุซูŠู‚ุฉ ุงู„ู…ุฑุฌุน ุงู„ู…ุนู…ุงุฑูŠ ([`HERMES.md`](HERMES.md)) ูˆุงู„ุนู‚ุฏ ุงู„ู…ูˆุญุฏ ([`AGENTS.md`](AGENTS.md))ุŒ ู…ุน ุงู„ุชุซุจูŠุช ุงู„ุชู„ู‚ุงุฆูŠ ู„ู…ู„ู `AGENTS.md` ููŠ ู…ุฌู„ุฏุงุช ุงู„ุชุทุจูŠู‚ุงุช ุงู„ู…ุนูƒูˆุณุฉุŒ ูˆูุญุต ุงู„ุฃู…ุงู† ูˆุชุฌุงูˆุฒ ุงู„ุญู…ุงูŠุงุช ุงู„ู…ุชู‚ุฏู…ุฉุŒ ูˆุญุงุฆุฒ ุนู„ู‰ ุชู‚ูŠูŠู… **5.0/5.0 Tier A+** ู„ุฌู…ูŠุน ุงู„ุฃุฏูˆุงุช ุงู„ู€ 9 ูˆูู‚ ู…ุนุงูŠูŠุฑ Glama.

---

### ๐Ÿง  ุนู‚ุฏ Hermes+ ูˆุงู„ุชุซุจูŠุช ุงู„ุชู„ู‚ุงุฆูŠ ููŠ ุงู„ุชุทุจูŠู‚ุงุช

1. **ุงู„ู…ุฑุฌุน ุงู„ู…ุนู…ุงุฑูŠ ุงู„ุฑุฆูŠุณูŠ ([`HERMES.md`](HERMES.md)):** ูŠุญุฏุฏ ุงู„ู‚ูˆุงุนุฏ ุงู„ุตุงุฑู…ุฉ ู„ุญุณุงุจ ุณุฌู„ุงุช Smali (`.locals + params = .registers`) ูˆุชูˆุฒูŠุน ู…ูƒุชุจุงุช `.so` ูˆุชุฌุงูˆุฒ ุขู„ูŠุงุช ุงู„ุญู…ุงูŠุฉ.
2. **ุงู„ุนู‚ุฏ ุงู„ุดุงู…ู„ ู„ู„ูˆูƒู„ุงุก ([`AGENTS.md`](AGENTS.md)):** ุนู‚ุฏ ู…ูˆุญุฏ ู…ุชูˆุงูู‚ ู…ุน ูƒุงูุฉ ุจูŠุฆุงุช ุงู„ุชุทูˆูŠุฑ (Antigravity, Cursor, Claude, Gemini, Windsurf).
3. **ุงู„ุชุซุจูŠุช ุงู„ุชู„ู‚ุงุฆูŠ ู„ุนู‚ุฏ ู…ุณุงุญุฉ ุงู„ุนู…ู„:** ุนู†ุฏ ุงุณุชุฏุนุงุก ุฃุฏุงุฉ `decompile_apk` ุฃูˆ `inject_flutter_runtime_and_smali`ุŒ ูŠู‚ูˆู… ุงู„ุฎุงุฏู… ุชู„ู‚ุงุฆูŠุงู‹ ุจุฅู†ุดุงุก ูˆุชุซุจูŠุช ู…ู„ู `AGENTS.md` ุฏุงุฎู„ ุงู„ู…ุฌู„ุฏ ุงู„ุฌุฐุฑูŠ ู„ู„ุชุทุจูŠู‚ ุงู„ู…ุณุชู‡ุฏู ู„ุถู…ุงู† ุงุณุชู…ุฑุงุฑูŠุฉ ุงู„ุณูŠุงู‚ ุงู„ู‡ู†ุฏุณูŠ ู„ุฃูŠ ูˆูƒูŠู„ ุฐูƒุงุก ุงุตุทู†ุงุนูŠ.

---

### ๐Ÿ› ๏ธ ุงู„ุฃุฏูˆุงุช ุงู„ู€ 9 ุงู„ุงุญุชุฑุงููŠุฉ (Glama 5.0/5.0 Tier A+)

| ุงุณู… ุงู„ุฃุฏุงุฉ | ุงู„ู†ูˆุน | ุงู„ุฎุตุงุฆุต | ุงู„ูˆุธูŠูุฉ ุงู„ู‡ู†ุฏุณูŠุฉ |
|---|---|---|---|
| `decompile_apk` | ุฃุณุงุณูŠุฉ | ุชุนุฏูŠู„ (`destructive`) | ุชููƒูŠูƒ ุงู„ู€ APK ุฅู„ู‰ Smali ูˆู…ูˆุงุฑุฏ ูˆู…ูƒุชุจุงุช ู…ุน **ุงู„ุชุซุจูŠุช ุงู„ุชู„ู‚ุงุฆูŠ ู„ู€ `AGENTS.md`**. |
| `analyze_injection_surface` | ุฃุณุงุณูŠุฉ | ู‚ุฑุงุกุฉ ูู‚ุท (`readOnly`) | ูุญุต ุงู„ูƒู„ุงุณุงุชุŒ ู…ูƒุชุจุงุช `.so` ู„ูƒู„ ู…ุนู…ุงุฑูŠุฉุŒ ู…ูƒุงูุญุฉ ุงู„ู€ DebugุŒ ุงู„ุฑูˆุชุŒ ูˆุชุซุจูŠุช ุงู„ุดู‡ุงุฏุงุช. |
| `synthesize_flutter_payload` | ุฃุณุงุณูŠุฉ | ุชุนุฏูŠู„ (`destructive`) | ุชุฌู…ูŠุน ู…ุดุฑูˆุน Flutter ุฅู„ู‰ ู…ูƒุชุจุงุช ุฃุตู„ูŠุฉ ูˆุฃุตูˆู„ ู…ุฎุตุตุฉ ู„ู…ุนู…ุงุฑูŠุงุช ุงู„ู‡ุฏู. |
| `inject_flutter_runtime_and_smali` | ุฃุณุงุณูŠุฉ | ุชุนุฏูŠู„ (`destructive`) | ุฒุฑุน ู…ุญุฑูƒ Flutter ูˆุดูุฑุงุช Smali ุงู„ุชู…ู‡ูŠุฏูŠุฉ ูˆู…ูˆุงุฒู†ุฉ ุณุฌู„ุงุช ุงู„ู€ Stack. |
| `patch_manifest_and_config` | ุฃุณุงุณูŠุฉ | ุชุนุฏูŠู„ (`destructive`) | ุชุนุฏูŠู„ `AndroidManifest.xml` (ุงู„ุฃู†ุดุทุฉุŒ ูƒู„ุงุณ ุงู„ุชุทุจูŠู‚ุŒ ุงู„ุชุณุฑูŠุน ุงู„ุจุฑู…ุฌูŠุŒ ุงู„ุชุตุงุฑูŠุญ). |
| `recompile_align_and_sign` | ุฃุณุงุณูŠุฉ | ุชุนุฏูŠู„ (`destructive`) | ุฅุนุงุฏุฉ ุงู„ุจู†ุงุก ุจู€ apktoolุŒ ุงู„ู…ุญุงุฐุงุฉ ุจู€ zipalignุŒ ูˆุงู„ุชูˆู‚ูŠุน ุงู„ุฑู‚ู…ูŠ ุจู€ apksigner. |
| `get_agent_context` | ูˆูƒูŠู„ | ู‚ุฑุงุกุฉ ูู‚ุท (`readOnly`) | ู‚ุฑุงุกุฉ ู‡ูˆูŠุฉ Hermes+ุŒ ุงู„ู‚ูˆุงุนุฏุŒ ุงู„ู…ู‡ุงุฑุงุชุŒ ูˆุญุงู„ุฉ ุงู„ุฐุงูƒุฑุฉ ุงู„ุญูŠุฉ. |
| `update_agent_memory` | ูˆูƒูŠู„ | ุชุนุฏูŠู„ (`destructive`) | ุญูุธ ุงู„ู…ู„ุงุญุธุงุช ูˆุณุฌู„ุงุช ุงู„ุชุฑู‚ูŠุน ููŠ ุงู„ุฐุงูƒุฑุฉ ุงู„ุญูŠุฉ ูˆู…ู„ู `.mcp_memory/session_state.json`. |
| `query_memory_graph` | ูˆูƒูŠู„ | ู‚ุฑุงุกุฉ ูู‚ุท (`readOnly`) | ุงู„ุจุญุซ ุงู„ู…ุตู†ู ููŠ ุณุฌู„ุงุช ุงู„ุชุฑู‚ูŠุน ูˆุงู„ู†ุชุงุฆุฌ ุงู„ุฃู…ู†ูŠุฉ ูˆุงู„ู…ูƒุชุจุงุช ุงู„ุฃุตู„ูŠุฉ. |

---

### ๐Ÿ’ป ู…ุชุทู„ุจุงุช ุงู„ู†ุธุงู… ูˆุงู„ุชุทูˆูŠุฑ

- **Node.js >= 18.0.0**
- **Java JRE/JDK 11+** (ู„ุฃุฏูˆุงุช `apktool` ูˆ `apksigner`)
- **Android SDK Build-Tools** (`zipalign` ูˆ `apksigner`)
- **apktool** ู…ุชุงุญ ุนู„ู‰ ู…ุณุงุฑ ุงู„ู†ุธุงู… PATH
- **Flutter SDK** (ู…ุทู„ูˆุจ ุนู†ุฏ ุจู†ุงุก ุงู„ุญู…ูˆู„ุงุช ุนุจุฑ `synthesize_flutter_payload`)

```bash
# ุชุซุจูŠุช ุงู„ุชุจุนูŠุงุช
npm install

# ุงู„ุชุญู‚ู‚ ู…ู† ุงู„ุฃู†ูˆุงุน ูˆุงู„ุฃู†ู…ุงุท
npm run typecheck
npm run lint

# ุชุดุบูŠู„ ุญุฒู…ุฉ ุงู„ุงุฎุชุจุงุฑุงุช (54 ุงุฎุชุจุงุฑุงู‹)
npm test

# ุจู†ุงุก ุงู„ุญุฒู…ุฉ ุงู„ู†ู‡ุงุฆูŠุฉ
npm run build
```

---

## ๐Ÿ“œ License / ุงู„ุชุฑุฎูŠุต

[MIT License](LICENSE) ยฉ 2026 [Marwan (MarwanDevSpace)](https://github.com/MarwanDevSpace)

TDQS

A4.6/5.0

Scored across 9 tools

Disambiguation5/5

Each tool has a distinct role in the APK injection pipeline or memory management, with no overlapping functionality. The sequential nature and clear descriptions prevent confusion.

Naming Consistency5/5

All tool names follow a consistent lower_snake_case convention with verb-first naming (decompile, analyze, synthesize, inject, patch, recompile, get, update, query). The pattern is uniform and predictable.

Tool Count5/5

Nine tools is well within the typical range for a specialized pipeline. The set covers the full APK modification workflow plus memory management without unnecessary redundancy.

Completeness5/5

The tool set provides a complete end-to-end workflow from decompilation to recompilation and signing, with integrated memory operations. No essential steps are missing for the stated purpose.

Maintenance

ActivityMaintained
ResponsivenessNo issues