@xi0yu/android-reverse-tools
v3.0.6
Published
Android reverse-engineering MCP server — Frida, UIAutomator, JADX, JEB
Maintainers
Readme
ARev
ARev is an MCP server for Android reverse engineering. It gives Codex, Claude Code, and other MCP clients access to Frida, UIAutomator2, JADX, and JEB.
| Item | Name |
| --- | --- |
| npm package | @xi0yu/android-reverse-tools |
| command | arev |
| MCP server name | arev |
The npm package keeps its descriptive registry name. The installed command stays short: arev.
Quick start
Install ARev globally:
npm install -g @xi0yu/android-reverse-tools@latestPrepare its Python runtime:
arev initIf you use JEB, install the companion plugin separately:
arev pluginThen register ARev with your MCP client.
Codex:
codex mcp add arev -- arev
codex mcp get arevClaude Code:
claude mcp add --scope user --transport stdio arev -- arev
claude mcp get arevARev is now started automatically by the MCP client. You do not need to keep a separate terminal process running.
Requirements
- Node.js 18 or newer
uvforarev init- A matching
frida-serveron the device for live Frida operations - The companion desktop plugin for JADX or JEB integrations
The npm installation itself is non-interactive. It does not download Python, initialize the runtime, or change a JEB installation.
Install in mainland China
If npm downloads are slow, select the npmmirror registry before installing:
npm config set registry https://registry.npmmirror.com
npm install -g @xi0yu/android-reverse-tools@latestTo switch back to the official npm registry later:
npm config set registry https://registry.npmjs.org/Initialize ARev
Run this after the first installation and after updating ARev:
arev initThis command prepares the runtime used by the MCP server. It does not ask about JEB and does not install or update the JEB plugin.
Each ARev release uses its own managed runtime and its tested dependency set. Initializing an update does not modify the previous release's Python environment.
Normal arev startup never waits for setup questions. If the runtime has not been initialized for the installed version, ARev tells you to run arev init from a terminal.
Install or update the JEB plugin
The JEB tools require the compatible companion plugin bundled with ARev. The ARev package and JEB plugin have independent version numbers because they are updated separately.
- Close JEB.
- Run
arev pluginin a terminal. - At
[Y/n], press Enter to install or update the plugin, or enternto skip. - Enter the JEB installation directory or its
corepluginsdirectory. ARev asks every time and does not save the path. - Restart JEB after ARev prints the completed installation path.
arev pluginThe path prompt accepts standard Windows, macOS, and Linux paths.
Examples:
C:\Tools\JEB
C:\Tools\JEB\coreplugins
/Users/you/Tools/JEB/coreplugins
/opt/jeb/corepluginsFor scripts or an explicit installation path:
arev plugin install --jeb-home "/path/to/JEB"
arev plugin install --plugins-dir "/path/to/coreplugins"
arev plugin update --plugins-dir "/path/to/coreplugins"
arev plugin status --plugins-dir "/path/to/coreplugins"Other useful commands:
# Print the verified JAR bundled with ARev
arev plugin path
# Copy the JAR to the current user's Downloads directory
arev plugin exportarev plugin export prints the complete output path. It does not install the file into JEB.
For unattended setup, use AREV_JEB_HOME or AREV_JEB_PLUGINS_DIR. A command-line path takes priority over these variables.
If JEB runs on another computer, install the plugin on that computer. --jeb-host changes where ARev connects; it does not copy the JAR to the remote host.
Configure MCP clients
Codex
Global installation:
codex mcp add arev -- arevRemote JADX and JEB hosts:
codex mcp add arev -- arev --jadx-host 192.168.1.100 --jeb-host 192.168.1.100Codex CLI and the Codex IDE extension use the same MCP configuration.
Claude Code
Global installation:
claude mcp add --scope user --transport stdio arev -- arevRemote JADX and JEB hosts:
claude mcp add --scope user --transport stdio arev -- arev --jadx-host 192.168.1.100 --jeb-host 192.168.1.100Other MCP clients
Use arev as a stdio MCP server:
{
"mcpServers": {
"arev": {
"command": "arev",
"args": []
}
}
}To connect to desktop plugins on another host, add arguments:
{
"mcpServers": {
"arev": {
"command": "arev",
"args": [
"--jadx-host", "192.168.1.100",
"--jeb-host", "192.168.1.100"
]
}
}
}Use npx without a global installation
Initialize the selected release once:
npx -y @xi0yu/android-reverse-tools@latest initInstall the JEB plugin only if you use JEB:
npx -y @xi0yu/android-reverse-tools@latest pluginCodex:
codex mcp add arev -- npx -y @xi0yu/android-reverse-tools@latestClaude Code:
claude mcp add --scope user --transport stdio arev -- npx -y @xi0yu/android-reverse-tools@latestWhen @latest changes, run the npx initialization command again before restarting the MCP client.
Connect to JADX and JEB
The default desktop plugin endpoints are:
| Backend | Host | Port |
| --- | --- | --- |
| JADX | 127.0.0.1 | 8650 |
| JEB | 127.0.0.1 | 16161 |
Override them when starting ARev:
arev --jadx-host 192.168.1.100 --jadx-port 8650 --jeb-host 192.168.1.100 --jeb-port 16161The same options can be placed after arev in a Codex, Claude Code, or JSON MCP configuration.
For JEB operations, call jeb_list_apps first and pass the returned session to later jeb_* calls. The same package name and version produce the same session. Do not load two APKs with the same package name and version at the same time.
If JEB was restarted or an APK changed, call jeb_list_apps again before retrying an operation.
Run ARev manually
Start the default stdio MCP server:
arevShow all command-line options:
arev --helpConnect only the modules you need:
arev --disable-jadx --disable-jeb --disable-uiautomatorStart an HTTP MCP server:
arev --transport http --host 127.0.0.1 --port 8765Available tools
frida_*: processes, applications, sessions, injection, messages, and script generationui_*: screen hierarchy, taps, text input, waits, scrolling, and screenshotsjadx_*: source, manifest, references, debugger state, search, and renamingjeb_*: loaded applications, decompilation, references, renaming, background tasks, and protobuf recoveryserver_*: server status and live JADX or JEB endpoint changes
Your MCP client displays the complete tool list for the modules enabled at startup.
Update ARev
Update the npm package, then initialize the new runtime:
npm install -g @xi0yu/android-reverse-tools@latest
arev initIf you use JEB, update its plugin separately:
arev pluginUpdating the ARev runtime and updating the JEB plugin are independent. A problem with one does not block the other.
Troubleshooting
uv is not in PATH
Install uv, open a new terminal, and run:
arev initAfter initialization, normal MCP startup and JEB plugin management do not require uv.
ARev says the runtime is not initialized
Run arev init in a terminal, then restart Codex, Claude Code, or the MCP client. Repeat this after installing a newer ARev release.
ARev uses its own versioned Python environment. Do not repair it with the
system pip; rerun arev init so the package is installed into the correct
environment.
Windows reports failed to rename file or os error 5
Close other ARev, Python, and uv processes, then retry arev init. Antivirus or enterprise endpoint protection can temporarily lock files under %LOCALAPPDATA%\arev; allow that directory or ask the system administrator to review the blocked operation.
The runtime error is unrelated to JEB plugin installation. You can run arev plugin separately.
The JEB plugin cannot be replaced
Close JEB completely and run arev plugin again. On Windows, a running JEB process can keep the old JAR locked.
Do not keep multiple xi0yu-jebplugin*.jar files in the same plugins directory.
jeb_* reports INCOMPATIBLE_JEB_BACKEND
Run arev plugin on the computer that runs JEB, restart JEB, then call jeb_list_apps again.
JADX or JEB cannot be reached
Confirm that the desktop plugin is running. Then verify the host and port passed to ARev. For a remote computer, also confirm that its firewall permits the connection.
From source
uv sync
uv run arevInstalled npm users should use the global arev command or the documented npx form.
License
The Node.js and Python code is licensed under MIT. The bundled JEB plugin is licensed under Apache-2.0; its license and notice are included in the npm package.
