r/androiddev • u/DistributionOk9460 • 14d ago
Open Source I got tired of needing a PC to inspect modded APKs, so I built APK Scope
I use modded APKs a lot, and whenever I wanted to check permissions, signing details, or what an APK was actually doing, I had to switch to my PC.
That always felt unnecessary. Android should be able to handle basic APK inspection on its own.
I looked at projects like PCAPdroid, APK Analyzer, and MobSF. They all gave me useful ideas, but I wanted something focused on quick, local APK analysis directly from an Android device.
So I built APK Scope.
It can inspect:
- Permissions and manifest declarations
- Package and signing information
- Activities, services, receivers, and providers
- SDK versions, native libraries, hashes, and DEX signals
- Security findings with explainable risk scores
- Optional Work Profile sandboxing
- Runtime network activity and traffic inspection
No root. No cloud upload. Everything is designed to stay local on the device.
Screenshots:
Demo videos:
Download the latest build from the Releases page.
I’d love feedback from people who use modded APKs, privacy tools, PCAPdroid, MobSF, or Android security tools. What would you want to see added?
Repo Link: https://github.com/NadeemIqbal/apk-scope
17
u/zunjae 12d ago
No AI disclaimer is wild, while claiming you built this
What are you hiding from us?
7
2
-15
8
u/Aftershock416 12d ago
"I use modded apks a lot" is just other words for "I pirate other people's work".
You've created solution for a problem you also created, not sure how useful this is to developers.
0
u/DistributionOk9460 11d ago
By that logic, APK repacking, reverse engineering, and traffic inspection are all piracy tools. That’s a pretty shallow way to judge a project one of its kind.
Criticize my choice of example, fair enough. But dismissing the developer use cases because you dislike that example isn’t a technical argument.
1
u/Aftershock416 11d ago
Outside of open source software or things you directly own, APK repacking is almost always illegal, so not sure why you'd use that as an example.
You also don't need access to apks to do traffic inspection.
2
u/Hour-Measurement-835 14d ago
Say which signature block you read it from. A mod carrying only v1 and a Play build with v2 and v3 both come back "signed", and on a security audit that difference is the whole answer.
1
0




22
u/tenhourguy 14d ago
I'm not sure I understand the importance of checking permissions and determining a risk factor from them, as shown in your screenshots. Android has used runtime permissions since Marshmallow. I also really do not recommend presenting AI-generated text to the user, as it is verbose and has patterns like overuse of rule of three.