droidasc-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DROIDASC_MCP_MAX_PARALLEL | No | Maximum concurrent ASC subprocesses. | 2 |
| DROIDASC_MCP_ALLOWED_ROOTS | No | Allowed roots, separated by os.pathsep (':' on Unix, ';' on Windows). Default is current directory. | current directory |
| DROIDASC_MCP_MAX_APK_BYTES | No | Maximum accepted APK size. | 2147483648 |
| DROIDASC_MCP_MAX_PAGE_SIZE | No | Maximum lines returned by one call. | 1000 |
| DROIDASC_MCP_TIMEOUT_SECONDS | No | Per-operation timeout. | 180 |
| DROIDASC_MCP_MAX_OUTPUT_BYTES | No | Captured stdout limit and aggregate decoded snapshot budget. | 67108864 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| asc_pingA | Report server, engine, path-scope, and pagination configuration. |
| asc_apk_infoA | Inspect APK size, SHA-256, manifest presence, and top-level DEX entries. |
| asc_get_manifestA | Decode AndroidManifest.xml and return a bounded page of XML lines. |
| asc_list_classesB | List class descriptors, optionally filtered by package or class prefix. |
| asc_get_class_sourceA | Locate and decompile one class, returning a bounded page of source lines. |
| asc_find_refsC | Find cross-DEX references to a string, type, method, or field. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 6 tools
Each tool targets a distinct concern: configuration, APK metadata, manifest decoding, class listing, source decompilation, and cross-DEX reference searching. There is no meaningful overlap between tool purposes, so an agent can reliably select the right tool.
The tools share a clear asc_ prefix and mostly follow a verb_noun pattern (ping, get_manifest, list_classes, get_class_source, find_refs). The single exception is asc_apk_info, which uses a noun phrase rather than a verb, creating a minor inconsistency.
Six tools is well-scoped for an APK static analysis server. Each tool covers a distinct capability without redundancy or bloat, making the surface easy for an agent to navigate.
The tool set covers the core APK inspection workflow: metadata, manifest, class enumeration, source decompilation, and reference lookup. Minor gaps exist such as resource decoding or raw DEX dumping, but the provided surface supports common reverse-engineering tasks end to end.