MCP server for static security analysis of Android source code
MCP server for static security analysis of Android application source code. Runs on Cloudflare Workers as a remote MCP server over Streamable HTTP. Analyzes Android project source files — without building the project — and returns a structured security report. The analysis covers: Manifest analysis — exported components, dangerous permissions, cleartext traffic, debug flags, backup settings, SDK…
Dedotto dai trasporti dichiarati da questo annuncio (streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Forge non ha completato alcun handshake tools/list verso questo endpoint, quindi non ha alcuna osservazione di ciò che il server espone. Nulla di tutto ciò dice che non esponga nulla.
MCP server for static security analysis of Android application source code. Runs on Cloudflare Workers as a remote MCP server over Streamable HTTP. Analyzes Android project source files — without building the project — and returns a structured security report. The analysis covers: Manifest analysis — exported components, dangerous permissions, cleartext traffic, debug flags, backup settings, SDK versions Gradle/build config — release build misconfigurations, outdated SDKs, suspicious…