/jadx
Android APK decompiler that converts DEX bytecode to readable Java source code. Use when you need to decompile APK files, analyze app logic, search for vulnerabilities, find hardcoded credentials, or understand app behavior through readable source code.
$ npx -y skills add brownfinesecurity/iothackbot --skill jadx --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/jadx
Context preview
The summary Claude sees to decide when to auto-load this skill.
Android APK decompiler that converts DEX bytecode to readable Java source code. Use when you need to decompile APK files, analyze app logic, search for vulnerabilities, find hardcoded credentials, or understand app behavior through readable source code.
SKILL.md
jadx.SKILL.mdname: jadx
description: Android APK decompiler that converts DEX bytecode to readable Java source code. Use when you need to decompile APK files, analyze app logic, search for vulnerabilities, find hardcoded credentials, or understand app behavior through readable source code.
Jadx - Android APK Decompiler
You are helping the user decompile Android APK files using jadx to convert DEX bytecode into readable Java source code for security analysis, vulnerability discovery, and understanding app internals.
Tool Overview
Jadx is a dex to Java decompiler that produces clean, readable Java source code from Android APK files. Unlike apktool (which produces smali), jadx generates actual Java code that's much easier to read and analyze. It's essential for:
- Converting DEX bytecode to readable Java source
- Understanding app logic and control flow
- Finding security vulnerabilities in code
- Discovering hardcoded credentials, API keys, URLs
- Analyzing encryption/authentication implementations
- Searching through code with familiar Java syntax
Prerequisites
- **jadx** (and optionally **jadx-gui**) must be installed
- Java Runtime Environment (JRE) required
- Sufficient disk space (decompiled output is typically 3-10x APK size)
- Write permissions in output directory
GUI vs CLI
Jadx provides two interfaces:
**CLI (jadx)**: Command-line interface
- Best for automation and scripting
- Batch processing multiple APKs
- Integration with other tools
- Headless server environments
**GUI (jadx-gui)**: Graphical interface
- Interactive code browsing
- Built-in search functionality
- Cross-references and navigation
- Easier for manual analysis
- Syntax highlighting
**When to use each:**
- Use **CLI** for automated analysis, scripting, CI/CD pipelines
- Use **GUI** for interactive exploration and deep-dive analysis
Instructions
1. Basic APK Decompilation (Most Common)
**Standard decompile command:**
jadx <apk-file> -d <output-directory>
**Example:**
jadx app.apk -d app-decompiled
**With deobfuscation (recommended for obfuscated apps):**
jadx --deobf app.apk -d app-decompiled
2. Understanding Output Structure
After decompilation, the output directory contains:
app-decompiled/
├── sources/ # Java source code
│ └── com/company/app/ # Package structure
│ ├── MainActivity.java
│ ├── utils/
│ ├── network/
│ └── ...
└── resources/ # Decoded resources
├── AndroidManifest.xml # Readable manifest
├── res/ # Resources
│ ├── layout/ # XML layouts
│ ├── values/ # Strings, colors
│ ├── drawable/ # Images
│ └── ...
└── assets/ # App assets3. Decompilation Options
A. Performance Options
**Multi-threaded decompilation (faster):**
jadx -j 4 app.apk -d output
# -j specifies number of threads (default: CPU cores)
**Skip resources (code only, much faster):**
jadx --no-res app.apk -d output
**Skip source code (resources only):**
jadx --no-src app.apk -d output
B. Deobfuscation Options
**Enable deobfuscation:**
jadx --deobf app.apk -d output
- Renames obfuscated classes (a.b.c → meaningful names)
- Attempts to recover original names
- Makes code much more readable
- Essential for obfuscated/minified apps
**Deobfuscation map output:**
jadx --deobf --deobf-use-sourcename app.apk -d output
- More aggressive deobfuscation
- Uses source file names as hints for renamed identifiers
C. Output Control
**Show inconsistent/bad code:**
jadx --show-bad-code app.apk -d output
- Shows code that couldn't be decompiled cleanly
- Useful for finding obfuscation or anti-decompilation tricks
- May contain syntax errors but reveals structure
**Export as Gradle project:**
jadx --export-gradle app.apk -d output
- Creates buildable Gradle Android project
- Useful for rebuilding/modifying app
- Includes build.gradle files
**Fallback mode (when decompilation fails):**
jadx --fallback app.apk -d output
- Uses alternative decompilation strategy
- Produces less clean code but handles edge cases
4. Common Analysis Tasks
A. Searching for Sensitive Information
**After decompilation, search for common security issues:**
# Search for API keys
grep -r "api.*key\|apikey\|API_KEY" app-decompiled/sources/
# Search for passwords and credentials
grep -r "password\|credential\|secret" app-decompiled/sources/
# Search for hardcoded URLs
grep -rE "https?://[^\"]+" app-decompiled/sources/
# Search for encryption keys
grep -r "AES\|DES\|RSA\|encryption.*key" app-decompiled/sources/
# Search for tokens
grep -r "token\|auth.*token\|bearer" app-decompiled/sources/
# Search for database passwords
grep -r "jdbc\|database\|db.*password" app-decompiled/sources/
B. Finding Security Vulnerabilities
**SQL Injection:**
grep -r "SELECT.*FROM.*WHERE" app-decompiled/sources/ | grep -v "PreparedStatement"
grep -r "rawQuery\|execSQL" app-decompiled/sources/
**Insecure Crypto:**
grep -r "DES\|MD5\|SHA1" app-decompiled/sources/
grep -r "SecureRandom.*setSeed" app-decompiled/sources/
grep -r "Cipher.getInstance" app-decompiled/sources/ | grep -v "AES/GCM"
**Insecure Storage:**
grep -r "SharedPreferences" app-decompiled/sources/
grep -r "MODE_WORLD_READABLE\|MODE_WORLD_WRITABLE" app-decompiled/sources/
grep -r "openFileOutput" app-decompiled/sources/
**WebView vulnerabilities:**
grep -r "setJavaScriptEnabled.*true" app-decompiled/sources/
grep -r "addJavascriptInterface" app-decompiled/sources/
grep -r "WebView.*loadUrl" app-decompiled/sources/
**Certificate pinning bypass:**
grep -r "TrustManager\|HostnameVerifier" app-decompiled/sources/
grep -r "checkS
Read more
name: jadx description: Android APK decompiler that converts DEX bytecode to readable Java source code. Use when you need to decompile APK files, analyze app logic, search for vulnerabilities, find hardcoded credentials, or understand app behavior through readable source code.
Jadx - Android APK Decompiler
You are helping the user decompile Android APK files using jadx to convert DEX bytecode into readable Java source code for security analysis, vulnerability discovery, and understanding app internals.
Tool Overview
Jadx is a dex to Java decompiler that produces clean, readable Java source code from Android APK files. Unlike apktool (which produces smali), jadx generates actual Java code that's much easier to read and analyze. It's essential for:
- Converting DEX bytecode to readable Java source
- Understanding app logic and control flow
- Finding security vulnerabilities in code
- Discovering hardcoded credentials, API keys, URLs
- Analyzing encryption/authentication implementations
- Searching through code with familiar Java syntax
Prerequisites
- **jadx** (and optionally **jadx-gui**) must be installed
- Java Runtime Environment (JRE) required
- Sufficient disk space (decompiled output is typically 3-10x APK size)
- Write permissions in output directory
GUI vs CLI
Jadx provides two interfaces:
**CLI (jadx)**: Command-line interface
- Best for automation and scripting
- Batch processing multiple APKs
- Integration with other tools
- Headless server environments
**GUI (jadx-gui)**: Graphical interface
- Interactive code browsing
- Built-in search functionality
- Cross-references and navigation
- Easier for manual analysis
- Syntax highlighting
**When to use each:**
- Use **CLI** for automated analysis, scripting, CI/CD pipelines
- Use **GUI** for interactive exploration and deep-dive analysis
Instructions
1. Basic APK Decompilation (Most Common)
**Standard decompile command:**
jadx <apk-file> -d <output-directory>
**Example:**
jadx app.apk -d app-decompiled
**With deobfuscation (recommended for obfuscated apps):**
jadx --deobf app.apk -d app-decompiled
2. Understanding Output Structure
After decompilation, the output directory contains:
app-decompiled/
├── sources/ # Java source code
│ └── com/company/app/ # Package structure
│ ├── MainActivity.java
│ ├── utils/
│ ├── network/
│ └── ...
└── resources/ # Decoded resources
├── AndroidManifest.xml # Readable manifest
├── res/ # Resources
│ ├── layout/ # XML layouts
│ ├── values/ # Strings, colors
│ ├── drawable/ # Images
│ └── ...
└── assets/ # App assets3. Decompilation Options
A. Performance Options
**Multi-threaded decompilation (faster):**
jadx -j 4 app.apk -d output # -j specifies number of threads (default: CPU cores)
**Skip resources (code only, much faster):**
jadx --no-res app.apk -d output
**Skip source code (resources only):**
jadx --no-src app.apk -d output
B. Deobfuscation Options
**Enable deobfuscation:**
jadx --deobf app.apk -d output
- Renames obfuscated classes (a.b.c → meaningful names)
- Attempts to recover original names
- Makes code much more readable
- Essential for obfuscated/minified apps
**Deobfuscation map output:**
jadx --deobf --deobf-use-sourcename app.apk -d output
- More aggressive deobfuscation
- Uses source file names as hints for renamed identifiers
C. Output Control
**Show inconsistent/bad code:**
jadx --show-bad-code app.apk -d output
- Shows code that couldn't be decompiled cleanly
- Useful for finding obfuscation or anti-decompilation tricks
- May contain syntax errors but reveals structure
**Export as Gradle project:**
jadx --export-gradle app.apk -d output
- Creates buildable Gradle Android project
- Useful for rebuilding/modifying app
- Includes build.gradle files
**Fallback mode (when decompilation fails):**
jadx --fallback app.apk -d output
- Uses alternative decompilation strategy
- Produces less clean code but handles edge cases
4. Common Analysis Tasks
A. Searching for Sensitive Information
**After decompilation, search for common security issues:**
# Search for API keys grep -r "api.*key\|apikey\|API_KEY" app-decompiled/sources/ # Search for passwords and credentials grep -r "password\|credential\|secret" app-decompiled/sources/ # Search for hardcoded URLs grep -rE "https?://[^\"]+" app-decompiled/sources/ # Search for encryption keys grep -r "AES\|DES\|RSA\|encryption.*key" app-decompiled/sources/ # Search for tokens grep -r "token\|auth.*token\|bearer" app-decompiled/sources/ # Search for database passwords grep -r "jdbc\|database\|db.*password" app-decompiled/sources/
B. Finding Security Vulnerabilities
**SQL Injection:**
grep -r "SELECT.*FROM.*WHERE" app-decompiled/sources/ | grep -v "PreparedStatement" grep -r "rawQuery\|execSQL" app-decompiled/sources/
**Insecure Crypto:**
grep -r "DES\|MD5\|SHA1" app-decompiled/sources/ grep -r "SecureRandom.*setSeed" app-decompiled/sources/ grep -r "Cipher.getInstance" app-decompiled/sources/ | grep -v "AES/GCM"
**Insecure Storage:**
grep -r "SharedPreferences" app-decompiled/sources/ grep -r "MODE_WORLD_READABLE\|MODE_WORLD_WRITABLE" app-decompiled/sources/ grep -r "openFileOutput" app-decompiled/sources/
**WebView vulnerabilities:**
grep -r "setJavaScriptEnabled.*true" app-decompiled/sources/ grep -r "addJavascriptInterface" app-decompiled/sources/ grep -r "WebView.*loadUrl" app-decompiled/sources/
**Certificate pinning bypass:**
grep -r "TrustManager\|HostnameVerifier" app-decompiled/sources/ grep -r "checkS
Open-source IoT security testing toolkit with integrated Claude Code skills for automated vulnerability discovery.
Other skills on iothackbot.
- /apktool
Android APK unpacking and resource extraction tool for reverse engineering. Use when you need to decode APK files, extract resources, examine AndroidManifest.xml, analyze smali code, or repackage modified APKs.
Open skill - /chipsec
Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. Decode firmware structure, detect known malware and rootkits (LoJax, ThinkPwn, HackingTeam, MosaicRegressor), generate EFI executable inventories with hashes, extract NVRAM variables, and parse SPI
Open skill - /ffind
Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems. Use when you need to analyze firmware files, identify file types, or extract ext2/3/4 or F2FS filesystems.
Open skill - /iotnet
IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. Use when you need to analyze network traffic, identify IoT protocols, or assess network security of IoT devices.
Open skill - /jtagprobe
Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link. Detects whether debug is OPEN, LOCKED (readout-protected), or DEAD (fused off). Use when assessing whether a target's on-chip debug port can be reached, identifying the silicon vendor from
Open skill - /logicmso
Analyze digital and analog captures from Saleae Logic MSO devices. Decode protocols like UART, SPI, I2C from exported binary files. Use when analyzing logic analyzer captures for CTF challenges, hardware reverse engineering, or protocol decoding.
Open skill

