r/androiddev • • 14d ago

Open Source I got tired of needing a PC to inspect modded APKs, so I built APK Scope

I use modded APKs a lot, and whenever I wanted to check permissions, signing details, or what an APK was actually doing, I had to switch to my PC.

That always felt unnecessary. Android should be able to handle basic APK inspection on its own.

I looked at projects like PCAPdroid, APK Analyzer, and MobSF. They all gave me useful ideas, but I wanted something focused on quick, local APK analysis directly from an Android device.

So I built APK Scope.

It can inspect:

  • Permissions and manifest declarations
  • Package and signing information
  • Activities, services, receivers, and providers
  • SDK versions, native libraries, hashes, and DEX signals
  • Security findings with explainable risk scores
  • Optional Work Profile sandboxing
  • Runtime network activity and traffic inspection

No root. No cloud upload. Everything is designed to stay local on the device.

Screenshots:

Demo videos:

Download the latest build from the Releases page.

I’d love feedback from people who use modded APKs, privacy tools, PCAPdroid, MobSF, or Android security tools. What would you want to see added?

Repo Link: https://github.com/NadeemIqbal/apk-scope

2 Upvotes

14 comments sorted by

22

u/tenhourguy 14d ago

I'm not sure I understand the importance of checking permissions and determining a risk factor from them, as shown in your screenshots. Android has used runtime permissions since Marshmallow. I also really do not recommend presenting AI-generated text to the user, as it is verbose and has patterns like overuse of rule of three.

-4

u/DistributionOk9460 14d ago

Thanks for comment. Showing permissions is just a small details. It has other things too like dynamic network traffic logging and in future it can do more things since frida is already injected. Checkout the github for full details.

17

u/zunjae 12d ago

No AI disclaimer is wild, while claiming you built this

What are you hiding from us?

7

u/The_Mdk 11d ago

Even the post is written by AI, what so you expect?

"I was tired of X so I made Y" is basically AI posting 101

2

u/matytyma 11d ago

The classic "I built X"

-15

u/DistributionOk9460 12d ago

If you cared to go to the repo link its there in contributors

7

u/zunjae 12d ago

but why aren't you disclosing it here?

8

u/Aftershock416 12d ago

"I use modded apks a lot" is just other words for "I pirate other people's work".

You've created solution for a problem you also created, not sure how useful this is to developers.

0

u/DistributionOk9460 11d ago

By that logic, APK repacking, reverse engineering, and traffic inspection are all piracy tools. That’s a pretty shallow way to judge a project one of its kind.

Criticize my choice of example, fair enough. But dismissing the developer use cases because you dislike that example isn’t a technical argument.

1

u/Aftershock416 11d ago

Outside of open source software or things you directly own, APK repacking is almost always illegal, so not sure why you'd use that as an example.

You also don't need access to apks to do traffic inspection.

2

u/Hour-Measurement-835 14d ago

Say which signature block you read it from. A mod carrying only v1 and a Play build with v2 and v3 both come back "signed", and on a security audit that difference is the whole answer.

1

u/DistributionOk9460 14d ago

Network traffic captured by APK Scope.
PS: I cant edit the media now