7.8 KiB
Clone App Skill — Design Spec
Date: 2026-06-21
Status: Approved
Repo: fork of masa2146/android-reverse-engineering-skill
Overview
A Claude Code skill (/clone-app) that takes a Google Play URL, downloads the APK, reverse engineers it, analyzes the app store presence, estimates clone effort with AI-assisted tooling, evaluates market viability, and optionally generates a full implementation plan.
Trigger:
/clone-app https://play.google.com/store/apps/details?id=com.example.app
Repository Structure
The skill lives inside the fork of android-reverse-engineering-skill as a separate plugin — upstream files are never modified.
masa2146/android-reverse-engineering-skill/
├── plugins/
│ ├── android-reverse-engineering/ ← upstream, untouched
│ │ └── skills/android-reverse-engineering/
│ │ ├── SKILL.md
│ │ └── scripts/ ← called directly by clone-app
│ └── clone-app/ ← new skill
│ ├── .claude-plugin/
│ │ └── plugin.json
│ ├── skills/
│ │ └── clone-app/
│ │ └── SKILL.md
│ └── commands/
│ └── clone-app.md
Upstream sync:
git remote add upstream https://github.com/SimoneAvogadro/android-reverse-engineering-skill.git
git pull upstream master
Conflict risk is low — upstream only modifies plugins/android-reverse-engineering/ and root files (README, LICENSE).
Architecture
Approach: Orchestrator Skill (Option B)
clone-app SKILL.md orchestrates all phases sequentially. RE bash scripts are called directly via relative path from within the same repo — no cross-plugin tool invocation needed.
RE script path pattern:
RE_SCRIPTS="$(dirname "$CLAUDE_PLUGIN_ROOT")/../android-reverse-engineering/skills/android-reverse-engineering/scripts"
bash "$RE_SCRIPTS/fingerprint.sh" app.xapk
bash "$RE_SCRIPTS/decompile.sh" app.xapk
bash "$RE_SCRIPTS/find-api-calls.sh" output/sources/
Phase Workflow
Phase 0: Input Validation
- Extract package name from URL via regex:
id=([a-zA-Z0-9._]+) - If extraction fails → ask user to provide package name directly
- Create working directory:
./work/{package}/
Phase 1: APK Download
curl -L "https://d.apkpure.com/b/APK/{PACKAGE}?version=latest" --output work/{package}/app.xapk
- 3 retries on failure
- Detect file type (APK vs XAPK) from magic bytes
- If download fails after retries → ask user for local APK path
Phase 2: Reverse Engineering
Calls RE skill scripts in order:
fingerprint.sh— framework detection (Flutter/RN/Kotlin/etc.), HTTP stack, obfuscation levelcheck-deps.sh— verify jadx, Java 17+ present; auto-install if missing viainstall-dep.shdecompile.sh— full decompile towork/{package}/output/sources/recover-kotlin-names.sh— R8 deobfuscation (if Kotlin app)find-api-calls.sh— extract all API endpoints (Retrofit, OkHttp, Ktor, Apollo, etc.)
Output: tech stack JSON, API endpoint list, AndroidManifest summary, detected features.
Flutter/RN/Cordova fallback: fingerprint detects framework → warn user "Java decompile limited for this framework" → proceed with what's available (manifest, hardcoded URLs, SDK list).
Phase 3: Store Analysis
- Scrape Google Play store page for: rating, review count, install range, category, last update, developer
- Search App Store for same package → note if iOS version exists
- If App Store not found → continue with Google Play data only
Output: store metrics JSON.
Phase 4: Stack Recommendation
AI analyzes RE results + store data and proposes 2-3 clone stack options:
- Considers detected original stack
- Considers AI-assisted development efficiency (Flutter and React Native favored for speed)
- Presents tradeoffs for each option
Present to user:
"Detected: Native Kotlin. Recommended for AI-assisted clone: Flutter (fastest) or React Native (JS ecosystem). Original stack also viable. Which do you prefer?"
User selects stack → locked for Phase 5+.
Phase 5: Effort & Cost Estimation
Based on selected stack:
Feature list extracted from APK:
- Screens (Activity/Fragment count)
- Permissions used
- API endpoints count
- Third-party SDKs (payment, auth, analytics, etc.)
- Detected backend patterns (REST/GraphQL/WebSocket)
AI-assisted effort table:
| Category | Complexity | AI Sprints |
|---|---|---|
| Auth flow | Medium | 1 |
| Core screens | High | 3-5 |
| API integration | Medium | 2 |
| Backend (if needed) | High | 3-8 |
| ... | ... | ... |
"AI Sprint" = one focused Claude Code session (~2-4 hours of human review time).
Infrastructure cost estimate:
- Backend hosting (Railway/Render/AWS estimate)
- Database
- CDN / storage
- Third-party API costs (maps, payments, etc.)
Phase 6: Market Viability Report
Synthesizes all data into work/{package}/clone-report-YYYY-MM-DD.md:
## App Overview
## Tech Stack (Detected)
## Recommended Clone Stack
## Feature List (from APK)
## Effort Estimate (AI-assisted)
## Infrastructure Cost Estimate (monthly)
## Market Analysis
- Current app metrics
- Competitor landscape
- Target market size estimate
## Viability Verdict
- GO / CONDITIONAL GO / NO GO
- Key risks
- Key opportunities
Phase 7: Decision Gate
Present report summary to user:
"Report saved to work/{package}/clone-report-YYYY-MM-DD.md. Want to proceed with building the implementation plan?"
- Yes → invoke
writing-plansskill with report as context - No → save report, end skill
Error Handling
| Scenario | Behavior |
|---|---|
| APKPure download fails (3x) | Ask user for local APK path |
| XAPK (split bundle) | RE skill handles automatically |
| Flutter/RN/Cordova app | Warn, continue with available data |
| App Store not found | Continue with Google Play only |
| RE skill not installed | Run check-deps.sh, auto-install missing tools |
| Package name not in URL | Ask user to input package name |
writing-plans skill unavailable |
Write plan as Markdown manually |
| Heavy obfuscation | Note in report, feature list may be incomplete |
Known Limitations
- iOS API extraction not possible (store scrape only, no IPA download)
- Effort estimates are AI-sprint based, not calendar time — depends on developer review speed
- Play Store download counts are ranges (not exact) — viability estimate uses midpoint
- APKPure availability not guaranteed for all apps
- Heavy R8 obfuscation may limit feature detection accuracy
Working Directory Layout
./work/{package}/
├── app.xapk ← downloaded APK
├── output/
│ ├── sources/ ← decompiled Java/Kotlin
│ └── names/ ← Kotlin name recovery maps
├── clone-report-YYYY-MM-DD.md ← final report
└── implementation-plan.md ← generated by writing-plans
Dependencies
Skill dependencies:
android-reverse-engineeringplugin (same repo)- Java JDK 17+
- jadx (auto-installed if missing)
- curl
Optional:
- Vineflower/Fernflower (better decompile quality)
- dex2jar
Installation
# 1. Clone fork
git clone https://github.com/masa2146/android-reverse-engineering-skill.git
cd android-reverse-engineering-skill
# 2. Install both plugins
/plugin marketplace add .
/plugin install android-reverse-engineering@android-reverse-engineering-skill
/plugin install clone-app@android-reverse-engineering-skill
Out of Scope
- Automated code generation of the clone (that's writing-plans → executing-plans)
- iOS IPA download/reverse engineering
- Real-time market data (uses scraped/estimated data)
- Legal review of clone viability