mobsf-mcp

mobsf-mcp

Enables AI agents to perform autonomous Android security analysis, including static analysis, dynamic analysis, and Frida instrumentation, powered by MobSF.

Category
访问服务器

README

mobsf-mcp

<p align="center"> <img src="assets/logo.png" alt="mobsf-mcp" width="400"> </p>

An MCP (Model Context Protocol) server that gives AI agents the ability to perform autonomous Android security analysis - static analysis, dynamic analysis, and Frida instrumentation - powered by MobSF.

Point your AI agent at an APK and let it autonomously discover vulnerabilities, inspect decompiled source, test exported activities, bypass SSL pinning with Frida, and generate security reports.

Architecture

┌─────────────────────┐         ┌──────────────┐         ┌─────────────┐
│   AI Agent          │  MCP    │  mobsf-mcp   │  REST   │   MobSF     │
│ (Claude/Ollama/etc) │◄───────►│  Server      │◄───────►│  (Docker)   │
└─────────────────────┘  stdio  └──────────────┘  HTTP   └──────┬──────┘
                                                                 │ ADB
                                                          ┌──────▼──────┐
                                                          │  Android    │
                                                          │  Emulator   │
                                                          │ (optional)  │
                                                          └─────────────┘

Static analysis (no emulator needed): Upload APK → decompile → analyze manifest, permissions, code, secrets, network config, crypto, certificates, trackers.

Dynamic analysis (emulator required): Install app on emulator → monitor runtime behavior → intercept API calls with Frida → test TLS → collect network traffic → exported activity testing.

Quick Start

One-command setup

bash scripts/setup.sh

Or step-by-step

# 1. Start MobSF
docker compose up -d

# 2. Get the API key
docker logs mobsf 2>&1 | grep "REST API Key"

# 3. Install the MCP server
pip install -e .

# 4. Configure
cp .env.example .env
# Edit .env with your API key

# 5. Use with your MCP client
mobsf-mcp

Connecting to Your LLM

Once MobSF is running and the MCP server is installed, configure your MCP client to load the tools.

Claude Desktop

Add to ~/.claude/claude_desktop_config.json:

{
  "mcpServers": {
    "mobsf": {
      "command": "mobsf-mcp",
      "env": {
        "MOBSF_URL": "http://localhost:8000",
        "MOBSF_API_KEY": "your_api_key_here"
      }
    }
  }
}

Restart Claude Desktop. The 23 tools appear automatically.

Open WebUI + Ollama

See docs/ollama-setup.md for connecting local LLMs via mcpo bridge.

Any MCP Client

The server speaks stdio MCP. Point any MCP-compatible client at the mobsf-mcp command with MOBSF_URL and MOBSF_API_KEY environment variables. No additional configuration needed.

# Test standalone
MOBSF_URL=http://localhost:8000 MOBSF_API_KEY=your_key mobsf-mcp

Available Tools (23)

Static Analysis (8)

Tool Description
upload_apk Upload an APK file for analysis
scan_apk Trigger static analysis (decompile, manifest, code, secrets)
get_report Get detailed security findings (filterable by section)
get_security_scorecard High-level security posture score
view_source_file Inspect specific decompiled source files
list_scans List all previous scans
search_scans Search scans by name/package/hash
delete_scan Remove a scan

Dynamic Analysis (9)

Tool Description
list_dynamic_apps List apps ready for dynamic testing
start_dynamic_analysis Install & launch app on emulator
stop_dynamic_analysis Stop analysis & collect results
get_dynamic_report Get runtime analysis findings
get_logcat Get filtered logcat output
run_adb_command Execute ADB commands on device
test_exported_activities Test for unauthorized activity access
launch_activity Launch a specific activity
run_tls_tests Test TLS/SSL security

Frida Instrumentation (6)

Tool Description
frida_instrument Run hooks (SSL bypass, root bypass, custom scripts)
frida_monitor_apis Monitor sensitive API calls at runtime
frida_get_logs Get Frida hook output
frida_list_scripts List available built-in scripts
frida_get_script_code View script source code
frida_get_dependencies Install Frida dependencies on device

Dynamic Analysis Setup

Dynamic analysis requires an Android emulator with root access (for writable /system) connected to MobSF.

Note on API level: MobSF v4.5.1 uses Frida 17.15.3 which has a known compatibility issue with Android 13 (API 33) - frida.attach() crashes with a TypeError. For full DAST including Frida instrumentation, use an Android 11 (API 30) emulator. ADB commands, exported activity testing, TLS tests, and logcat all work fine on API 33. This will be resolved when MobSF updates its Frida dependency.

Emulator Setup

Two options:

Option A: Docker Android Emulator (simplest)

Use docker-android - a pre-built Docker image with Android emulator, SDK, and ADB ready to go. No local SDK install needed.

docker run -d --privileged -p 6080:6080 -p 5554:5554 -p 5555:5555 \
  -e DEVICE="pixel_6" -e EMULATOR_ARGS="-writable-system" \
  budtmo/docker-android:emulator_13.0

# Wait for boot, then root it
adb connect localhost:5555
adb root && adb remount

Then set ANALYZER_IDENTIFIER=localhost:5555 in docker-compose.yml (instead of emulator-5554).

Option B: Manual AVD (more control)

# Install Android SDK command-line tools, then:
sdkmanager "system-images;android-33;google_apis;x86_64" "platforms;android-33" "platform-tools"
avdmanager create avd -n mobsf -k "system-images;android-33;google_apis;x86_64" -d pixel_6 -f

# Start with writable system
emulator -avd mobsf -no-window -no-audio -no-snapshot \
    -writable-system -gpu swiftshader_indirect -memory 2048 &

# Wait for boot
adb wait-for-device
adb root && adb remount
adb shell 'while [[ -z $(getprop sys.boot_completed) ]]; do sleep 5; done'

Docker ↔ Emulator Wiring

This project's docker-compose.yml is pre-configured:

  • network_mode: host - Docker shares the host network, so ADB just works
  • MOBSF_PLATFORM=host - disables Docker Desktop hostname translation
  • ANALYZER_IDENTIFIER=emulator-5554 - points MobSF to the emulator
  • ./mobsf-data/.android/ - ADB keys mounted for authorization
  • Entrypoint wrapper patches MobSF to support API 33+

Important: Kill the host ADB server before starting MobSF Docker to avoid ADB conflicts:

adb kill-server && docker compose up -d

Example Agent Interaction

User: Analyze the security of ./target.apk

Agent: I'll upload and scan this APK for you.
       [calls upload_apk("./target.apk")]
       [calls scan_apk("a1b2c3d4...")]
       [calls get_security_scorecard("a1b2c3d4...")]

       The app has a security score of 28/100 (High Risk):
       - 6 high-severity manifest issues (StrandHogg 2.0, debuggable)
       - 7 exported components without permission checks
       - Janus vulnerability (v1 signature only)
       - 23 hardcoded secrets found
       - 3 privacy trackers
       - Debug enabled, backup allowed

       Want me to start dynamic analysis and test the exported activities?

File Structure

/home/kali/labs/MCP/
├── src/
│   ├── server.py          ← MCP server (23 tools)
│   └── mobsf_client.py    ← MobSF REST API client
├── scripts/
│   ├── setup.sh           ← One-command setup
│   └── test_pipeline.py   ← End-to-end test suite
├── docs/
│   └── ollama-setup.md    ← LLM integration guide
├── mobsf-data/            ← Docker volume (persistent)
│   ├── .android/adbkey    ← ADB authorization keys
│   ├── entrypoint-wrapper.sh ← API cap patch
│   ├── config.py / db.sqlite3 / secret
│   └── downloads/         ← Scan artifacts
├── tests/
│   └── test.apk           ← InsecureBankv2 (test target)
├── docker-compose.yml     ← MobSF container config
├── pyproject.toml         ← Python package config
├── .env.example           ← Environment template
└── README.md

Development

pip install -e .
python3 scripts/test_pipeline.py

License

MIT © plur1bu5


<p align="center"> <sub>Built with ❤️ by <a href="https://github.com/plur1bu5">plur1bu5</a> - if this helps you hack smarter, drop a ⭐</sub> </p>

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选