The APKPure direct endpoint (d.apkpure.com/b/APK/<pkg>) now returns an HTTP
403 Cloudflare bot challenge for every package, so downloads always failed —
which also blocked the entire reverse-engineering chain downstream (it never
ran because Phase 1 produced no APK).
- download-apk.sh: fetch the APKCombo download page with a browser UA, extract
the embedded /r2?u=<signed-url> link, and download that. No JS needed; the
URL slug is ignored so a literal 'app' works for any package. Verified
end-to-end against com.wonder (Elevate) -> 126MB xapk -> RE fingerprint.
- test-download-apk.sh: model the two-step flow and the page-without-link case.
- resolve-re-scripts.sh: warn (stderr) when bash < 4, since the upstream RE
scripts use ${VAR,,} and fail with 'bad substitution' on macOS bash 3.2.
- SKILL.md / README.md / CLAUDE.md: document the APKCombo source and bash 4+ req.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
||
|---|---|---|
| .. | ||
| .claude-plugin | ||
| commands | ||
| skills/clone-app | ||
| tests | ||
| README.md | ||
README.md
clone-app — Clone Feasibility Analyzer (Claude Code skill)
Give it a Google Play URL. It downloads the APK, reverse engineers the tech
stack and APIs (via the sibling android-reverse-engineering plugin), analyzes
the app's store presence, estimates AI-assisted build effort (in AI Sprints)
and monthly infrastructure cost, judges market viability (GO / CONDITIONAL GO /
NO GO), and — if you approve — generates a full implementation plan.
Requirements
- The
android-reverse-engineeringplugin (ships in this same repo). - Java JDK 17+ and jadx (the RE plugin auto-installs jadx if missing).
curl, Python 3 (stdlib only),unzip.- bash 4+. macOS ships bash 3.2, but the RE scripts use bash-4 syntax
(
${VAR,,}) and fail with "bad substitution" on 3.2. Install a modern bash withbrew install bash—#!/usr/bin/env bashthen picks it up.
APK source
APKs/XAPKs are fetched from APKCombo. The previous APKPure direct endpoint
(d.apkpure.com/b/APK/<pkg>) now returns an HTTP 403 Cloudflare bot challenge
for every package, so it is no longer usable from a plain curl. If an app is
not on APKCombo, pass a local .apk/.xapk path instead.
Install
/plugin marketplace add https://github.com/masa2146/clone-app-skill
/plugin install android-reverse-engineering@clone-app-skill
/plugin install clone-app@clone-app-skill
Usage
/clone-app https://play.google.com/store/apps/details?id=com.example.app
Or natural language: "Analyze this Play Store app for cloning: ".
The skill pauses twice for your input: choosing the clone stack, and deciding whether to generate the implementation plan.
Output
./work/<package>/
├── app.apk | app.xapk
├── output/ # decompiled sources + Kotlin name maps
├── play.json # store metrics
├── appstore.json # iOS presence
└── clone-report-YYYY-MM-DD.md
Keeping the RE plugin up to date
This repo is a fork. To pull upstream improvements:
git remote add upstream https://github.com/SimoneAvogadro/android-reverse-engineering-skill.git
git pull upstream master
The clone-app plugin lives in its own directory, so upstream updates to
android-reverse-engineering merge cleanly.
Legal
For lawful use only — your own apps, authorized interoperability, security research, or education. You are responsible for compliance.