Android Security Analyzer MCP Server
MCP server for static security analysis of Android application source code.
About
Analyzes Android project source files — without building the project — and returns a structured security report. The analysis covers: * Manifest analysis — exported components, dangerous permissions, cleartext traffic, debug flags, backup settings, SDK versions * Gradle/build config — release build misconfigurations, outdated SDKs, suspicious dependencies, hardcoded secrets * Source code (Java/Kotlin) — insecure WebView, SSL/TLS bypass, weak crypto, SQL injection patterns, process execution, insecure file storage, PendingIntent issues * XML configuration — network security config weaknesses, overly broad file provider paths * Secret scanning — API keys, tokens, passwords, private keys, cloud credentials, high-entropy strings
All analysis is regex/pattern-based and runs natively in the Workers runtime with no external tools, Java, or Android SDK required.
Security Report
This is a well-architected Android security analyzer MCP server with proper input validation, clean code structure, and appropriate permissions for its purpose. A few minor code quality issues were identified but do not pose security risks. Supply chain analysis found 3 known vulnerabilities in dependencies (1 critical, 1 high severity).
6 files analyzed · 5 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Getting Started
Once installed, try these example prompts and explore these capabilities:
- 1The server is hosted; no install or API keys are required.
- 21. Add the server to your MCP client
- 3Use this URL in your MCP configuration (Cursor, Cline, or any Streamable HTTP client):
- 4https://android-security-analyzer.ako-labs.workers.dev/mcp
- 52. Example config (JSON)
- 6{
- 7"mcpServers": {
- 8"android-security-analyzer": {
- 9"url": "https://android-security-analyzer.ako-labs.workers.dev/mcp"
- 10}
- 11}
- 12}
- 133. Use the tools
- 14After the client connects, you can:
- 15* analyze_android_project — run a full security scan by passing project files (manifest, Gradle, Java/Kotlin, XML). No build or Android SDK needed.
- 16* list_android_security_checks — list all security rules.
- 17* explain_finding — get a detailed explanation for a rule ID.
- 18Ask your AI assistant to analyze an Android project or explain a finding; it will call these tools as needed.
Reviews
No reviews yet
Be the first to review this server!
More Security MCP Servers
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
mcp-creator-typescript
Freeby mcp-marketplace · Developer Tools
Scaffold, build, and publish TypeScript MCP servers to npm — conversationally