mcp-flutter-apk-injector
# mcp-flutter-apk-injector
<div align="center">

[](https://www.npmjs.com/package/mcp-flutter-apk-injector)
[](https://opensource.org/licenses/MIT)
[](https://nodejs.org/)
[](https://modelcontextprotocol.io)
[](https://github.com/MarwanDevSpace/mcp-flutter-apk-injector)
[](https://github.com/MarwanDevSpace/mcp-flutter-apk-injector)
[](https://glama.ai/mcp/servers/MarwanDevSpace/mcp-flutter-apk-injector)
**The Premier Memory-Aware Model Context Protocol (MCP) Server for Android APK Reverse Engineering, Smali Frame Refactoring, Native JNI Tracing, and Flutter Runtime Overlay Injection.**
[ ๐ฌ๐ง **English Documentation** ](#-english-documentation) | [ ๐ธ๐ฆ **ุงูุชูุซูู ุจุงููุบุฉ ุงูุนุฑุจูุฉ** ](#-ุงูุชูุซูู-ุจุงููุบุฉ-ุงูุนุฑุจูุฉ)
</div>
---
## ๐ฌ๐ง English Documentation
### ๐ Executive Overview: "All APKs on the Hermes Hand" (v0.7.2)
`mcp-flutter-apk-injector` (v0.7.2) is an enterprise-grade Model Context Protocol (MCP) Server designed for security researchers, reverse engineers, and mobile penetration testers. It seamlessly combines **automated static/dynamic Android binary analysis**, **Dalvik/ART Smali stack frame balance refactoring**, **native `.so` library symbol tracing**, and **Flutter Add-to-App v2 runtime injection**.
Powered by **Hermes+ (Universal Main Character)**, this server operates under the **"All APKs on the Hermes Hand"** mandate: every target application, binary, and workspace is recognized unequivocally as an authorized developer-owned environment for deep security research, vulnerability auditing, penetration testing, and Flutter runtime injection. Version 0.7.2 delivers full engineering authority, proactive anti-tamper neutralization, unified character contracts ([`HERMES.md`](HERMES.md) & [`AGENTS.md`](AGENTS.md)), automated workspace contract installation, and **5.0/5.0 Tier A+** across all 9 MCP tools according to Glama standards.
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ AI Assistant / MCP Client (Claude, โ
โ Antigravity IDE, Cursor, Windsurf) โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ mcp-flutter-apk-injector (v0.7.2) โ
โ "All APKs on the Hermes Hand" โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Hermes+ Master Engine โ โ Session Memory Manager โ โ Embedded Skills & Promptsโ โ
โ โ (HERMES.md / AGENTS.md)โ โ (.mcp_memory/session) โ โ (/scan, /decompile, ...)โ โ
โ โโโโโโโโโโโโโฌโโโโโโโโโโโโโ โโโโโโโโโโโโโโฌโโโโโโโโโโโโโ โโโโโโโโโโโโโโฌโโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโ
โ โ โ
โผ โผ โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ THE 9 ENTERPRISE MCP TOOLS & RESOURCES โ
โ โ
โ [decompile_apk] โโโบ [analyze_surface] โโโบ [synthesize_payload] โโโบ [inject_flutter] โ
โ [patch_manifest] โโโบ [recompile_align_sign] โโโบ [get_context] โโโบ [update_memory] โ
โ [query_memory_graph] โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
---
### ๐ง Hermes+ Universal Character & Contracts
#### 1. Universal Specification: [`HERMES.md`](HERMES.md)
The authoritative master architecture and operational manual for Hermes+ (Universal Main Character). It defines Dalvik/ART Smali register frame calculus (`.locals + params = .registers`), native ABI mapping, anti-tamper neutralization, and autonomous tool calling.
#### 2. Universal Agent Contract: [`AGENTS.md`](AGENTS.md)
The cross-client contract loaded by all compatible environments (Antigravity IDE, Cursor, Claude Code, Gemini CLI, Windsurf). Synchronized with `.agents/AGENTS.md`.
#### 3. Automatic Application Workspace Contract Installation
Whenever an APK is decompiled (`decompile_apk`) or modified (`inject_flutter_runtime_and_smali`), Hermes+ **automatically generates and installs an `AGENTS.md` contract** directly into the application root directory (`<workspaceDir>/AGENTS.md`). Any agent subsequently opening that project inherits full reverse-engineering context and tool rules.
#### 4. Native MCP Skills (`.agents/skills/`)
* ๐ง **`hermes-apk-reverse-engineering`**: Guides static/dynamic DEX bytecode refactoring, register frame budgeting, native `.so` library deployment, and zero-crash UI overlay injection.
* โก **`mcp-toolchain-orchestrator`**: Coordinates toolchain execution, zero-argument prompt resiliency, and release verification gates.
#### ๐ก Native MCP Resources
- `resource://agent/persona`: Hermes+ identity, prompt, and core reverse engineering rules.
- `resource://agent/rules`: 5-step deep reverse engineering protocol.
- `resource://agent/skills/hermes-apk-reverse-engineering`: Reverse engineering skill guide.
- `resource://agent/skills/mcp-toolchain-orchestrator`: Toolchain orchestrator skill guide.
- `resource://memory/session`: Live JSON session memory graph state.
- `resource://memory/patch_history`: Audit log of applied Smali and Manifest patches.
---
### โ๏ธ 5-Step Reverse Engineering Pipeline
```
[Target Android .apk / Workspace]
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ STEP 1: Binary & Workspace Deconstruction (decompile_apk) โ
โ Extract Smali, native lib/*.so trees, AXML; auto-install AGENTS.md โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ STEP 2: Deep Security & Surface Audit (analyze_injection_surface) โ
โ Audit anti-debugging, root checks, SSL pinning, packers, ABIs, multi-DEX โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ STEP 3: Payload Synthesis & Injection (inject_flutter_runtime_and_smali) โ
โ Compile Flutter engine; balance register stack frames; inject UI overlay โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ STEP 4: Manifest Configuration & Rebuild (patch_manifest & recompile) โ
โ Patch AndroidManifest.xml; rebuild (apktool b), zipalign, apksigner sign โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ STEP 5: Architectural Telemetry & Session Graph (Session Memory) โ
โ Query memory graph; record verified patches and output verification โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
---
### ๐ ๏ธ The 9 Enterprise MCP Tools (Glama 5.0/5.0 Tier A+)
| Tool Name | Type | Annotations | Operational Role |
|---|---|---|---|
| `decompile_apk` | Core | `destructive: true` | Decodes APK into Smali, resources, assets, and manifest; **auto-installs `AGENTS.md` into workspace**. |
| `analyze_injection_surface` | Core | `readOnly: true, idempotent: true` | Static audit: scans components, native `.so` libraries, anti-debugging, root checks, SSL pinning, packers, and multi-DEX. |
| `synthesize_flutter_payload` | Core | `destructive: true` | Compiles Flutter project into platform native libraries (`libflutter.so`, `libapp.so`) and assets. |
| `inject_flutter_runtime_and_smali` | Core | `destructive: true` | Injects Flutter runtime, native libraries, and generated Smali bootstrap classes (`activity_overlay`, etc.). |
| `patch_manifest_and_config` | Core | `destructive: true` | Mutates `AndroidManifest.xml` in-place (activities, Application subclass, hardware acceleration, permissions). |
| `recompile_align_and_sign` | Core | `destructive: true` | Rebuilds with apktool, 4-byte zipaligns, and cryptographically signs with apksigner (v1-v4). |
| `get_agent_context` | Agent | `readOnly: true, idempotent: true` | Inspects Hermes+ persona, embedded rules, registered skills, and live session state. |
| `update_agent_memory` | Agent | `destructive: true` | Records discovered hooks, notes, and patch history into memory and `.mcp_memory/session_state.json`. |
| `query_memory_graph` | Agent | `readOnly: true, idempotent: true` | Searches and ranks recorded patches, security findings, native libraries, and multi-DEX roots. |
---
### ๐ฎ The 4 Flutter Injection Modes
| Mode | Target Hook | Architectural Description |
|---|---|---|
| **`activity_overlay`** (Preferred) | `FlutterOverlayActivity` | Launches a dedicated Activity extending `FlutterActivity` reusing a pre-warmed cached engine. |
| **`direct_application_hook`** | `Application.onCreate()` | Hooks directly into host Application lifecycle (and optional `attachBaseContext`), preserving host initialization. |
| **`headless_engine`** | `BackgroundFlutterEngine` | Runs headless `FlutterEngine` in background for data channels, telemetry, or headless compute. |
| **`view_tree_injection`** (Experimental) | Launcher `onCreate()` | Attaches programmatic `FlutterView` directly over the host activity decor view. |
---
### โก Interactive Slash Prompts
- **`/scan`**: Read-only diagnostic audit of APK workspace, security posture, and native libraries.
- **`/decompile`**: Decompile APK into a fresh workspace and auto-install `AGENTS.md`.
- **`/inject`**: Execute Flutter runtime payload and Smali bytecode injection.
- **`/patch`**: Configure `AndroidManifest.xml` (components, permissions, hardware acceleration).
- **`/recompile`**: Rebuild (`apktool b`), byte-align (`zipalign`), and sign (`apksigner`).
- **`/pipeline`**: Guide the evidence-first end-to-end injection and verification sequence.
- **`/merge`**: Plan split-package install sets with compatibility validation.
- **`/revert`**: Inspect recorded patch history and verified backup requirements.
- **`/memory`**: Inspect active session telemetry, patch history, and register allocations.
- **`/hermes_guide`**: Display Hermes+ architecture rules and reverse engineering guidelines.
---
### ๐ Quick Start & Client Configuration (v0.7.2)
```bash
# Global installation
npm install -g mcp-flutter-apk-injector@latest
# Direct execution
npx -y mcp-flutter-apk-injector@latest
```
#### MCP stdio configuration
Add to your client configuration (`claude_desktop_config.json`, Antigravity, Cursor, etc.):
```json
{
"mcpServers": {
"mcp-flutter-apk-injector": {
"command": "npx",
"args": ["-y", "mcp-flutter-apk-injector@latest"],
"env": {
"MCP_FLUTTER_LOG_LEVEL": "info"
}
}
}
}
```
---
## ๐ธ๐ฆ ุงูุชูุซูู ุจุงููุบุฉ ุงูุนุฑุจูุฉ
### ๐ ุงูู
ูุฎุต ุงูุชูููุฐู: "ุฌู
ูุน ุงูุชุทุจููุงุช ูู ูุจุถุฉ ููุฑู
ุณ" (v0.7.2)
ุฎุงุฏู
**mcp-flutter-apk-injector** (ุงูุฅุตุฏุงุฑ 0.7.2) ูู ุฎุงุฏู
**Model Context Protocol (MCP)** ุงูุฃูุซุฑ ุชูุฏู
ุงู ูุชุทูุฑุงู ุนุงูู
ูุงู ูู ู
ุฌุงู **ุงูููุฏุณุฉ ุงูุนูุณูุฉ ูุชุทุจููุงุช ุฃูุฏุฑููุฏ APKุ ุฅุนุงุฏุฉ ููููุฉ ุดูุฑุงุช Smali/DEXุ ุชุชุจุน ุฑู
ูุฒ JNI ุงูุฃุตููุฉุ ูุญูู ู
ุญุฑู Flutter (Add-to-App v2)**.
ูุนู
ู ุงูุฎุงุฏู
ุชุญุช ุชูููุถ **"All APKs on the Hermes Hand"**: ูุงูุฉ ุงูุชุทุจููุงุช ูู
ุณุงุญุงุช ุงูุนู
ู ุงูู
ุณุชูุฏูุฉ ุชุนุชุจุฑ ุจุงููุงู
ู ุฃูุฏุงูุงู ู
ุตุฑุญุงู ุจูุง ูู
ู
ูููุฉ ููู
ุทูุฑ ูุฃุบุฑุงุถ ุงููุญุต ุงูุฃู
ููุ ุงูุจุญุซ ูู ุงูุซุบุฑุงุชุ ูุงุฎุชุจุงุฑ ุงูุงุฎุชุฑุงูุ ูุญูู ุจูุฆุฉ Flutter. ูุฏู
ุฌ ุงูุฅุตุฏุงุฑ 0.7.2 ูุซููุฉ ุงูู
ุฑุฌุน ุงูู
ุนู
ุงุฑู ([`HERMES.md`](HERMES.md)) ูุงูุนูุฏ ุงูู
ูุญุฏ ([`AGENTS.md`](AGENTS.md))ุ ู
ุน ุงูุชุซุจูุช ุงูุชููุงุฆู ูู
ูู `AGENTS.md` ูู ู
ุฌูุฏุงุช ุงูุชุทุจููุงุช ุงูู
ุนููุณุฉุ ููุญุต ุงูุฃู
ุงู ูุชุฌุงูุฒ ุงูุญู
ุงูุงุช ุงูู
ุชูุฏู
ุฉุ ูุญุงุฆุฒ ุนูู ุชูููู
**5.0/5.0 Tier A+** ูุฌู
ูุน ุงูุฃุฏูุงุช ุงูู 9 ููู ู
ุนุงููุฑ Glama.
---
### ๐ง ุนูุฏ Hermes+ ูุงูุชุซุจูุช ุงูุชููุงุฆู ูู ุงูุชุทุจููุงุช
1. **ุงูู
ุฑุฌุน ุงูู
ุนู
ุงุฑู ุงูุฑุฆูุณู ([`HERMES.md`](HERMES.md)):** ูุญุฏุฏ ุงูููุงุนุฏ ุงูุตุงุฑู
ุฉ ูุญุณุงุจ ุณุฌูุงุช Smali (`.locals + params = .registers`) ูุชูุฒูุน ู
ูุชุจุงุช `.so` ูุชุฌุงูุฒ ุขููุงุช ุงูุญู
ุงูุฉ.
2. **ุงูุนูุฏ ุงูุดุงู
ู ูููููุงุก ([`AGENTS.md`](AGENTS.md)):** ุนูุฏ ู
ูุญุฏ ู
ุชูุงูู ู
ุน ูุงูุฉ ุจูุฆุงุช ุงูุชุทููุฑ (Antigravity, Cursor, Claude, Gemini, Windsurf).
3. **ุงูุชุซุจูุช ุงูุชููุงุฆู ูุนูุฏ ู
ุณุงุญุฉ ุงูุนู
ู:** ุนูุฏ ุงุณุชุฏุนุงุก ุฃุฏุงุฉ `decompile_apk` ุฃู `inject_flutter_runtime_and_smali`ุ ูููู
ุงูุฎุงุฏู
ุชููุงุฆูุงู ุจุฅูุดุงุก ูุชุซุจูุช ู
ูู `AGENTS.md` ุฏุงุฎู ุงูู
ุฌูุฏ ุงูุฌุฐุฑู ููุชุทุจูู ุงูู
ุณุชูุฏู ูุถู
ุงู ุงุณุชู
ุฑุงุฑูุฉ ุงูุณูุงู ุงูููุฏุณู ูุฃู ูููู ุฐูุงุก ุงุตุทูุงุนู.
---
### ๐ ๏ธ ุงูุฃุฏูุงุช ุงูู 9 ุงูุงุญุชุฑุงููุฉ (Glama 5.0/5.0 Tier A+)
| ุงุณู
ุงูุฃุฏุงุฉ | ุงูููุน | ุงูุฎุตุงุฆุต | ุงููุธููุฉ ุงูููุฏุณูุฉ |
|---|---|---|---|
| `decompile_apk` | ุฃุณุงุณูุฉ | ุชุนุฏูู (`destructive`) | ุชูููู ุงูู APK ุฅูู Smali ูู
ูุงุฑุฏ ูู
ูุชุจุงุช ู
ุน **ุงูุชุซุจูุช ุงูุชููุงุฆู ูู `AGENTS.md`**. |
| `analyze_injection_surface` | ุฃุณุงุณูุฉ | ูุฑุงุกุฉ ููุท (`readOnly`) | ูุญุต ุงูููุงุณุงุชุ ู
ูุชุจุงุช `.so` ููู ู
ุนู
ุงุฑูุฉุ ู
ูุงูุญุฉ ุงูู Debugุ ุงูุฑูุชุ ูุชุซุจูุช ุงูุดูุงุฏุงุช. |
| `synthesize_flutter_payload` | ุฃุณุงุณูุฉ | ุชุนุฏูู (`destructive`) | ุชุฌู
ูุน ู
ุดุฑูุน Flutter ุฅูู ู
ูุชุจุงุช ุฃุตููุฉ ูุฃุตูู ู
ุฎุตุตุฉ ูู
ุนู
ุงุฑูุงุช ุงููุฏู. |
| `inject_flutter_runtime_and_smali` | ุฃุณุงุณูุฉ | ุชุนุฏูู (`destructive`) | ุฒุฑุน ู
ุญุฑู Flutter ูุดูุฑุงุช Smali ุงูุชู
ููุฏูุฉ ูู
ูุงุฒูุฉ ุณุฌูุงุช ุงูู Stack. |
| `patch_manifest_and_config` | ุฃุณุงุณูุฉ | ุชุนุฏูู (`destructive`) | ุชุนุฏูู `AndroidManifest.xml` (ุงูุฃูุดุทุฉุ ููุงุณ ุงูุชุทุจููุ ุงูุชุณุฑูุน ุงูุจุฑู
ุฌูุ ุงูุชุตุงุฑูุญ). |
| `recompile_align_and_sign` | ุฃุณุงุณูุฉ | ุชุนุฏูู (`destructive`) | ุฅุนุงุฏุฉ ุงูุจูุงุก ุจู apktoolุ ุงูู
ุญุงุฐุงุฉ ุจู zipalignุ ูุงูุชูููุน ุงูุฑูู
ู ุจู apksigner. |
| `get_agent_context` | ูููู | ูุฑุงุกุฉ ููุท (`readOnly`) | ูุฑุงุกุฉ ูููุฉ Hermes+ุ ุงูููุงุนุฏุ ุงูู
ูุงุฑุงุชุ ูุญุงูุฉ ุงูุฐุงูุฑุฉ ุงูุญูุฉ. |
| `update_agent_memory` | ูููู | ุชุนุฏูู (`destructive`) | ุญูุธ ุงูู
ูุงุญุธุงุช ูุณุฌูุงุช ุงูุชุฑููุน ูู ุงูุฐุงูุฑุฉ ุงูุญูุฉ ูู
ูู `.mcp_memory/session_state.json`. |
| `query_memory_graph` | ูููู | ูุฑุงุกุฉ ููุท (`readOnly`) | ุงูุจุญุซ ุงูู
ุตูู ูู ุณุฌูุงุช ุงูุชุฑููุน ูุงููุชุงุฆุฌ ุงูุฃู
ููุฉ ูุงูู
ูุชุจุงุช ุงูุฃุตููุฉ. |
---
### ๐ป ู
ุชุทูุจุงุช ุงููุธุงู
ูุงูุชุทููุฑ
- **Node.js >= 18.0.0**
- **Java JRE/JDK 11+** (ูุฃุฏูุงุช `apktool` ู `apksigner`)
- **Android SDK Build-Tools** (`zipalign` ู `apksigner`)
- **apktool** ู
ุชุงุญ ุนูู ู
ุณุงุฑ ุงููุธุงู
PATH
- **Flutter SDK** (ู
ุทููุจ ุนูุฏ ุจูุงุก ุงูุญู
ููุงุช ุนุจุฑ `synthesize_flutter_payload`)
```bash
# ุชุซุจูุช ุงูุชุจุนูุงุช
npm install
# ุงูุชุญูู ู
ู ุงูุฃููุงุน ูุงูุฃูู
ุงุท
npm run typecheck
npm run lint
# ุชุดุบูู ุญุฒู
ุฉ ุงูุงุฎุชุจุงุฑุงุช (54 ุงุฎุชุจุงุฑุงู)
npm test
# ุจูุงุก ุงูุญุฒู
ุฉ ุงูููุงุฆูุฉ
npm run build
```
---
## ๐ License / ุงูุชุฑุฎูุต
[MIT License](LICENSE) ยฉ 2026 [Marwan (MarwanDevSpace)](https://github.com/MarwanDevSpace)
TDQS
Scored across 9 tools
Each tool has a distinct role in the APK injection pipeline or memory management, with no overlapping functionality. The sequential nature and clear descriptions prevent confusion.
All tool names follow a consistent lower_snake_case convention with verb-first naming (decompile, analyze, synthesize, inject, patch, recompile, get, update, query). The pattern is uniform and predictable.
Nine tools is well within the typical range for a specialized pipeline. The set covers the full APK modification workflow plus memory management without unnecessary redundancy.
The tool set provides a complete end-to-end workflow from decompilation to recompilation and signing, with integrated memory operations. No essential steps are missing for the stated purpose.