# AndroJack MCP

**Category:** 📂 Browser Automation  
**Repository:** https://github.com/VIKAS9793/androjack-mcp  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/androjack-mcp

## Description
MCP server that validates AI-generated Android code against official SDK documentation.

## Claude Desktop Quick Installation
Heuristic fallback — verify the package name and runner against the repository README before running it. Uses `npx` (confidence: low):

```json
"mcpServers": {
  "androjack-mcp": {
    "command": "npx",
    "args": ["-y","androjack-mcp"]
  }
}
```

## Documentation & README

<div align="center">

![AndroJack Banner](https://raw.githubusercontent.com/VIKAS9793/AndroJack-mcp/main/assets/AndroJack%20banner.png)

# AndroJack — The Jack of All Android Trades

<img src="https://img.shields.io/badge/Android-3DDC84?style=for-the-badge&logo=android&logoColor=white" />
<img src="https://img.shields.io/badge/Kotlin-7F52FF?style=for-the-badge&logo=kotlin&logoColor=white" />
<img src="https://img.shields.io/badge/MCP-Protocol-blueviolet?style=for-the-badge" />

### *An MCP server that equips your AI coding assistant with live, verified Android knowledge — so it builds from official sources, not from memory.*

<br/>

[![npm version](https://img.shields.io/npm/v/androjack-mcp?color=0A7AFF&style=flat-square&logo=npm&label=npm)](https://www.npmjs.com/package/androjack-mcp)
[![VS Code Extension](https://img.shields.io/badge/VS%20Code-Extension-0A7AFF?style=flat-square&logo=visual-studio-code)](https://marketplace.visualstudio.com/items?itemName=VIKAS9793.androjack-vscode)
[![GitHub stars](https://img.shields.io/github/stars/VIKAS9793/AndroJack-mcp?style=flat-square&logo=github&color=0A7AFF)](https://github.com/VIKAS9793/AndroJack-mcp/stargazers)
[![npm downloads](https://img.shields.io/npm/dm/androjack-mcp?style=flat-square&logo=npm&color=0A7AFF)](https://www.npmjs.com/package/androjack-mcp)
[![Tools](https://img.shields.io/badge/tools-23-orange?style=flat-square)](#-what-androjack-covers--23-tools)
[![MCP Spec](https://img.shields.io/badge/MCP-2025--11--25-blueviolet?style=flat-square)](https://modelcontextprotocol.io)
[![TypeScript](https://img.shields.io/badge/TypeScript-5.5-3178C6?style=flat-square&logo=typescript)](https://typescriptlang.org)
[![Node.js](https://img.shields.io/badge/node-%3E%3D18.0.0-brightgreen?style=flat-square&logo=node.js)](https://nodejs.org)
[![Android API](https://img.shields.io/badge/Android-API%2021--37-34A853?style=flat-square&logo=android)](https://developer.android.com)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg?style=flat-square)](LICENSE)
[![Security Policy](https://img.shields.io/badge/security-policy-0A7AFF?style=flat-square&logo=github)](SECURITY.md)

<br/>

[![Install in VS Code](https://img.shields.io/badge/Install%20in-VS%20Code-007ACC?style=for-the-badge&logo=visual-studio-code&logoColor=white)](https://marketplace.visualstudio.com/items?itemName=VIKAS9793.androjack-vscode)
[![Install in Claude Desktop](https://img.shields.io/badge/Install%20in-Claude%20Desktop-D97706?style=for-the-badge&logo=anthropic&logoColor=white)](https://claude.ai/integrations/install-mcp?params=eyJuYW1lIjoiYW5kcm9qYWNrIiwiY29tbWFuZCI6Im5weCIsImFyZ3MiOlsiLXkiLCJhbmRyb2phY2stbWNwQDIuMC4wIl19)
[![Install in Cursor](https://img.shields.io/badge/Install%20in-Cursor-000000?style=for-the-badge&logo=cursor&logoColor=white)](https://cursor.com/install-mcp?name=androjack&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsImFuZHJvamFjay1tY3BAMi4wLjAiXX0=)
[![Add to Kiro](https://img.shields.io/badge/Add%20to-AWS%20Kiro-FF9900?style=for-the-badge&logoColor=white)](https://kiro.dev/launch/mcp/add?name=androjack&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22androjack-mcp%402.0.0%22%5D%2C%22disabled%22%3Afalse%2C%22autoApprove%22%3A%5B%5D%7D)
[![View on npm](https://img.shields.io/badge/View%20on-npm-CB3837?style=for-the-badge&logo=npm&logoColor=white)](https://www.npmjs.com/package/androjack-mcp)

<br/>

[![Official Product Page](https://img.shields.io/badge/Product-Landing%20Page-00C7B7?style=for-the-badge)](https://androjack-web.netlify.app/)
[![Watch AndroJack in Action on YouTube](https://img.shields.io/badge/YouTube-Watch%20Demo-FF0000?style=for-the-badge&logo=youtube&logoColor=white)](https://youtu.be/O2aFyObV-B0)

<br/>

**Also works with:** Windsurf · VS Code Copilot · Google Antigravity · JetBrains AI — see [Manual Config](#-manual-config--copy--paste) below ↓

**VS Code distribution:** Also live on the VS Code Marketplace as [AndroJack MCP for VS Code](https://marketplace.visualstudio.com/items?itemName=VIKAS9793.androjack-vscode).

**PM / APM docs:** Product strategy, JTBD, personas, roadmap, user stories, competitive analysis, and GTM materials live under [product-management/README.md](product-management/README.md).

</div>

---

## Table of Contents

- [The Crisis That Created This Tool](#-the-crisis-that-created-this-tool)
- [What Actually Breaks In Practice](#-what-actually-breaks-in-practice--documented-evidence)
- [What AndroJack Does](#-what-androjack-does)
- [Honest Activation Model](#️-honest-activation-model--two-levels)
- [What Can Still Break — Even at Level 3](#-what-can-still-break--even-at-level-3)
- [Defence-in-Depth](#️-defence-in-depth-the-right-tool-for-each-bug-class)
- [The Killer Argument](#-the-killer-argument)
- [The 23 Tools](#-what-androjack-covers--23-tools)
- [Quick Start](#-quick-start--zero-install-required)
- [Manual Config](#-manual-config--copy--paste)
- [Ecosystem Comparison](#-the-ecosystem-androjack-vs-other-mcps)
- [Security & Privacy](#-security--privacy)
- [Changelog](#-changelog)

---

## 🔥 The Crisis That Created This Tool

In 2025, the **Stack Overflow Developer Survey** asked 49,000 developers about their experience with AI coding tools. The results should alarm every Android engineer:

- **84% of developers** now use AI coding tools — up from 76% the year before.
- **Trust in AI accuracy collapsed** from 40% to just **29%** in a single year.
- **35% of all Stack Overflow visits in 2025** are now triggered by developers debugging and fixing AI-generated code.

The gap between usage and trust is not a coincidence. It is the product of a structural problem: **AI models predict tokens, not APIs.** They were trained on a snapshot of the world and have no mechanism to know what changed at API 30, what shipped at Google I/O 2025, or what Google Play now rejects at review time.

For Android developers, this failure mode is uniquely dangerous. Android has the fastest-moving ecosystem in mobile development — a new Compose BOM every month, Navigation 3 going stable after seven years of Nav2, Android 16 rewriting the rules on screen orientation locking — and most AI tools have training data that is six months to two years stale by the time you use them.

The result is not just bad code. It is **confidently bad code.**

---

## ⚡ What Actually Breaks In Practice — Documented Evidence

> These are not hypothetical risks. They are documented failure modes from real developer projects.

<details>
<summary><strong>The Navigation 3 Hallucination (January 2026)</strong></summary>

A published case study from **Atomic Robot** documented a live Navigation 2 → Navigation 3 migration using both Gemini and Claude — with internet access enabled on both. The conclusion, verbatim:

> *"LLMs still hallucinate versions. Even with internet access, both agents wanted to use an outdated release candidate instead of the stable 1.0.0 release."*

Navigation 3 went stable in November 2025 after seven years of the same library. It is a complete architectural rethink: back stacks are now plain Kotlin lists, the monolithic nav graph is gone, and `NavDisplay` replaces `NavController`. Google's own migration guide is so aware that AI tools get this wrong that it now contains special **"AI Agent:" annotations** — instructions embedded directly in the official docs for AI tools to follow. An AI tool that generates Nav2 code for a new Compose project in 2026 is not making a small mistake. It is creating an architectural incoherence that requires a full rewrite to fix.

</details>

<details>
<summary><strong>The Compose Deprecation Treadmill</strong></summary>

Jetpack Compose ships a new BOM every month. Since most models' training cutoffs, these APIs changed:

| API | Status | What goes wrong |
|:----|:-------|:----------------|
| `ContextualFlowRow` / `ContextualFlowColumn` | Deprecated in Compose 1.8 | AI still generates them — compile warning today, removal tomorrow |
| `TestCoroutineDispatcher` | Removed from coroutines-test 1.8+ | AI still generates it — non-deterministic test failures in CI |
| `FlowRow` overflow parameter | Deprecated in 1.8 | Subtle behavioral regression at runtime, silent in most linting setups |
| `AnchoredDraggableState.confirmValueChange` | Deprecated | Incorrect drag behavior at anchor boundaries |
| Navigation 2 in new projects | Superseded by Nav3 stable Nov 2025 | Architectural dead-end that requires a rewrite to fix |

Every one of these compiles. Most run without errors. The bugs surface later in CI flakiness, UI regressions, or Play Store review failures.

</details>

<details>
<summary><strong>The Android 16 / API 36 Mandate (August 2026 deadline)</strong></summary>

Android 16 made a platform-level change affecting every published app: on devices ≥600dp — tablets, foldables, ChromeOS — apps can **no longer lock screen orientation** or restrict resizability. Google Play requires API 36 targeting by August 2026.

An AI tool generating `android:screenOrientation="portrait"` or `android:resizeableActivity="false"` today is generating code that will trigger App Compatibility warnings in Play Console, fail large-screen quality checks, and get apps demoted in Play Store search results.

The business impact is not theoretical: **Foldable users spend 14× more on apps** than phone-only users. Tablet + phone users spend 9× more. FlipaClip saw 54% growth in tablet users within four months of going adaptive.

</details>

<details>
<summary><strong>The KMP Silent Failure</strong></summary>

Kotlin Multiplatform went mainstream in 2025 — over 900 new KMP libraries published, Room added KMP support, companies now hire specifically for KMP skills. When a developer on a KMP project asks an AI tool to add database support, the AI generates Android-only Room code. It compiles. It runs perfectly on Android. **The iOS build fails.** The developer spends hours debugging before realizing the root cause: their AI tool does not know KMP exists.

</details>

---

## 🧩 What AndroJack Does

AndroJack is a **documentation-grounded Android engineering MCP server**. It gives your AI coding assistant **23 specialized tools** that fetch live, verified answers from official Android and Kotlin sources — instead of predicting from stale training data.

It does not make the AI smarter. It makes the AI **accountable to evidence.**

Think of it as a pre-build linter for LLMs. While other tools retrieve documentation, AndroJack acts as a strict architectural gatekeeper.

```
Without AndroJack:  You ask → AI predicts from stale weights → Code (possibly wrong)

With AndroJack:     You ask → AI calls tool → Tool fetches official source live
                             → AI reads verified answer → Code (grounded)
```

---

## ⚠️ Honest Activation Model — Two Levels

> [!IMPORTANT]
> This is the most important thing to understand before you install AndroJack.

| Level | What's Active | What the AI Does |
|:------|:--------------|:-----------------|
| **Level 1 — Tools only** | 23 tools registered in IDE | AI *may* call the right tool. Depends on the IDE and the AI's judgment. |
| **Level 2 — Tools + Grounding Gate** | 23 tools + mandatory pre-generation rulebook | AI *must* call the correct tool for every decision before writing code. |
| **Level 3 — Full loop-back** | Level 2 + `android_code_validator` | AI validates every code block against 28 rules. Errors must be fixed before the user sees the code. |

**Level 1 is passive.** The tools are available but the AI decides when to use them. An AI building a Compose screen may call `architecture_reference` but skip `material3_expressive` — and ship M3E violations silently.

**Level 2 is active.** The `androjack_grounding_gate` system prompt maps every task type to the correct tool. Building Compose UI? The AI is mandated to call `material3_expressive` first. Adding a dependency? It must call `gradle_dependency_checker`. No exceptions.

**Level 3 is the loop-back.** `android_code_validator` runs on every code block the AI generates before returning it to the user. 28 rules covering removed APIs, deprecated patterns, Android 16/17 compliance, and Compose-First migration signals. Verdict **FAIL** means the AI must fix and re-validate — the user never sees the broken code.

→ *For full grounding, always activate Level 2 + Level 3. See Getting the Full Guarantee below.*

---

## 🪲 What Can Still Break — Even at Level 3

> [!IMPORTANT]
> AndroJack is a documentation-grounding and API-validation tool. It is not a Compose layout engine, a design system enforcer, or a runtime renderer. Level 3 catches removed APIs and deprecated patterns. It cannot catch every class of Android bug. This is not a limitation of AndroJack — it is a fundamental property of static text analysis applied to a visual, runtime-rendered UI framework.

The following bugs were encountered in a real Android app built with AndroJack at Level 2 (v1.4.0). They are documented here honestly so you know exactly what to watch for — and where to reach for different tools.

### ✅ What Level 3 Catches

```kotlin
// ❌ REMOVED — android_code_validator fires: REMOVED_ASYNCTASK
class MyTask : AsyncTask<Void, Void, String>()

// ❌ REMOVED — fires: REMOVED_TEST_COROUTINE_DISPATCHER
val dispatcher = TestCoroutineDispatcher()

// ❌ DEPRECATED — fires: DEPRECATED_CONTEXTUAL_FLOW_ROW
ContextualFlowRow { Text("hello") }

// ❌ LEAK — fires: GLOBALSCOPE_LAUNCH
GlobalScope.launch { fetchData() }
```

### ⚠️ What Level 3 Cannot Catch

> [!WARNING]
> The following bugs were found in a real project. They are valid, API-current Compose code that violates design system constraints, accessibility minimums, or architectural boundaries. Static text scanning cannot detect them.

<details>
<summary><strong>Bug PH-UI-001 — Segmented button text truncation</strong></summary>

```kotlin
// Compiles and runs. Level 3 sees no violation.
// The bug: Text inside MultiChoiceSegmentedButtonRow truncates because a
// fixed height modifier prevents the Roboto Flex variable font from expanding.
MultiChoiceSegmentedButtonRow {
    SegmentedButton(/* fixed height modifier */) {
        Text("Light")
    }
}
```

> [!NOTE]
> This is an **absence** bug. The correct modifier is missing — no wrong one is present. Use visual testing or runtime inspection.

</details>

<details>
<summary><strong>Bug PH-UI-003 — Disabled button contrast failure</strong></summary>

```kotlin
// Correct Material 3 API. Level 3 sees no violation.
// The bug: disabled state colours fail WCAG AA 4.5:1 contrast against surface.
Button(enabled = false, onClick = {}) {
    Text("INITIALIZE VAULT")
}
```

> [!NOTE]
> This is a **runtime visual property** bug. Use paparazzi screenshot tests or Google's Accessibility Scanner.

</details>

<details>
<summary><strong>Bug PH-AR-004 — Raw stack trace rendered to end user</strong></summary>

```kotlin
// A missing try/catch produces no pattern match.
class VaultViewModel : ViewModel() {
    fun initializeVault() {
        viewModelScope.launch {
            val result = repository.initialize() // Missing try/catch
            _uiState.value = UiState.Success(result)
        }
    }
}
```

> [!WARNING]
> **UDF architecture violations** require Detekt with custom rules or unit tests verifying exception mapping.

</details>

---

## 🗂️ Defence-in-Depth: The Right Tool for Each Bug Class

| Bug Class | Real Example | Right Tool |
|:----------|:-------------|:-----------|
| Removed / deprecated API | `AsyncTask`, `TestCoroutineDispatcher` | ✅ AndroJack Level 3 |
| Android 16 violations | `screenOrientation`, `resizeableActivity=false` | ✅ AndroJack Level 3 |
| Android 17 violations | `static final` reflection, LAN without permission | ✅ AndroJack Level 3 |
| Architecture (flagged root) | `GlobalScope` leaking to UI | ✅ AndroJack Level 3 |
| Absent modifier / missing constraint | `PH-UI-009` (innerPadding) | 🔧 Android Lint / IDE inspector |
| Runtime contrast / colour failures | `PH-UI-003` (WCAG) | 🔧 paparazzi + Accessibility Scanner |
| Touch target violations | `PH-UX-008` | 🔧 Accessibility Scanner |
| Architecture boundary (missing catch) | `PH-AR-004` (stack trace to UI) | 🔧 Detekt + ViewModel unit tests |

---

## 🎯 The Killer Argument

> *"Can your `agents.md` file tell me the Gradle version that shipped last Tuesday?"*

No markdown file can. No rules in `.cursorrules` can. No `SKILL.md` can.

**✅ Only a live tool call can.**

That's the job AndroJack exists to do — and nothing else in the current ecosystem does it for Android specifically.

| What you need | agents.md / SKILL.md | AndroJack MCP |
|:--------------|:---------------------|:--------------|
| Format output a specific way | ✅ Perfect | Works too |
| Follow team conventions | ✅ Perfect | Works too |
| Latest Gradle version right now | ❌ Guesses from memory | ✅ Fetches live |
| Is AsyncTask removed? | ❌ May be wrong | ✅ Verified against SDK |
| Android 16 Play Store rules | ❌ Unknown | ✅ Official source |

**Prompt engineering controls how the AI responds. MCP controls what the AI knows.**

---

## ✨ What AndroJack Covers — 23 Tools

| # | Tool | What It Does | What Breaks Without It |
|:----|:-----|:-------------|:-----------------------|
| 1 | `🔍 search` | Live search across official Android/Kotlin docs | AI reasons from memory — possibly wrong today |
| 2 | `⚠️ component` | Deprecated/removed check on 40+ APIs | Compiles fine, breaks at runtime/review |
| 3 | `📐 architecture` | Guides for 40+ topics — MVVM, Nav3, MVI... | AI gives 2022 advice; misses Nav3 |
| 4 | `🐛 debugger` | Parses stacktraces → searches Issue Tracker | AI hallucinates fixes for known bugs |
| 5 | `📦 gradle` | Live lookup from Google Maven + BOM resolution | Stale Compose BOM, KAPT instead of KSP |
| 6 | `📊 api-level` | API 21–36 table, minSdk warnings | API 26+ calls in minSdk 21 apps |
| 7 | `🎯 kotlin` | 10 patterns — coroutines, MVI, Compose state | `GlobalScope.launch`, `runBlocking` in UI |
| 8 | `🎨 m3e` | Material 3 Expressive components & Motion | M2 MaterialTheme in M3E app |
| 9 | `🔐 permissions` | 40+ permissions rules & contracts | `deprecated requestPermissions()` |
| 10 | `🧪 testing` | Unit/Compose UI testing official patterns | `Thread.sleep()` in tests; missing Hilt |
| 11 | `🏗️ build` | R8, libs.versions.toml, signing, AAB | `implementation` instead of `ksp` |
| 12 | `📱 large-screen` | WindowSizeClass (5 breakpoints incl. Large/XL), Adaptive Scaffolds | Phone-only layouts on foldables and desktops |
| 13 | `🚀 scalability` | Paging 3, WorkManager, modularization | Naive `loadAll()`; unstable keys in lists |
| 14 | `🧭 nav3` | Nav3 (Nov 2025) — Scenes, migration | AI generates Nav2 dead-ends |
| 15 | `✅ compliance` | API 36 / Android 16 / 16 KB page size | Apps fail Play Store August 2026 mandate |
| 16 | `🌐 kmp` | Room KMP, Ktor, source sets, Room 3.0 alpha | Android-only code in KMP projects |
| 17 | `🤖 ondevice-ai` | AICore, ML Kit Gen AI, Gemini Nano | Cloud-only AI when offline is required |
| 18 | `📋 policy` | Play Store age-gating, billing openness, data safety | Apps rejected for unknown policy changes |
| 19 | `🥽 xr` | Android XR SDK, SpatialPanel, Orbiter | Works as 2D panel, misses spatial value |
| 20 | `⌚ wear` | Tiles, Health, M3 Expressive for Wear OS | Handheld patterns on round displays |
| 21 | `🛡️ validator` | Level 3 loop-back validation gate — 28 rules | AI ships broken code without checking |
| 22 | `🆕 api17` | Android 17 / API 37 — static final, LAN, OTP, Handoff | Apps crash or fail Play Store on API 37 |
| 23 | `🪪 dev-verification` | Developer Verification Program — timeline, registration, CI/CD | Apps blocked from install on certified devices from Sept 30, 2026 |

---

## 🚀 Quick Start — Zero Install Required

### Option 1 — Interactive CLI (v2.0.0) ✨ Recommended

```bash
npx -y androjack-mcp@2.0.0 install
```

Launches a full animated terminal wizard with auto-detection for **VS Code, Cursor, Claude, Windsurf, JetBrains, Kiro, and Antigravity.**

### Option 2 — Targeted Installs

```bash
# Preview detected IDEs and config paths
npx -y androjack-mcp@2.0.0 install --list

# Auto-detect all
npx -y androjack-mcp@2.0.0 install --auto

# Install to a specific IDE
npx -y androjack-mcp@2.0.0 install --ide=cursor
npx -y androjack-mcp@2.0.0 install --ide=claude
npx -y androjack-mcp@2.0.0 install --ide=vscode
npx -y androjack-mcp@2.0.0 install --ide=windsurf
npx -y androjack-mcp@2.0.0 install --ide=jetbrains
npx -y androjack-mcp@2.0.0 install --ide=kiro
npx -y androjack-mcp@2.0.0 install --ide=antigravity
```

### Option 3 — Test Without an IDE

```bash
npx -y @modelcontextprotocol/inspector npx -y androjack-mcp@2.0.0
```

---

## 🧩 Manual Config / Copy / Paste

If you prefer to wire the server manually, or want to inspect the exact JSON before writing anything:

- Run `npx -y androjack-mcp@2.0.0 install --list` to preview detected IDEs and target config paths.
- Ready-to-paste examples live in [`config/`](config/).

| IDE / Client | Config file |
|:-------------|:------------|
| Claude Desktop | [`config/claude_desktop_config.json`](config/claude_desktop_config.json) |
| Cursor | [`config/cursor_mcp.json`](config/cursor_mcp.json) |
| VS Code / GitHub Copilot | [`config/vscode_mcp.json`](config/vscode_mcp.json) |
| Windsurf | [`config/windsurf_mcp.json`](config/windsurf_mcp.json) |
| Android Studio / IntelliJ | [`config/jetbrains_mcp.json`](config/jetbrains_mcp.json) |
| AWS Kiro | [`config/kiro_mcp.json`](config/kiro_mcp.json) |
| Google Antigravity | [`config/antigravity_mcp.json`](config/antigravity_mcp.json) |

Every example keeps AndroJack local by default and runs the published package via `npx -y androjack-mcp@2.0.0`.

---

## 📍 The Ecosystem: AndroJack vs. Other MCPs

| Feature | Google Developer Knowledge MCP | Google Android Skills (Apr 2026) | AndroJack MCP |
|:--------|:-------------------------------|:----------------------------------|:--------------|
| **Identity** | The Librarian (Information) | The Instructor (Pre-generation context) | The Gatekeeper (Enforcement) |
| **Mechanism** | Context Retrieval | Skill files read before code generation | Context Enforcement + post-generation validation |
| **Scope** | Generalist — Firebase, Cloud, Maps | Android-specific, first-party | Android engineering specialist |
| **Tools** | 3 retrieval tools | Skill-file based, growing | 23 specialized tools |
| **Setup** | Google Cloud project + API key required | `android skills add` — first-party CLI | `npx androjack-mcp@2.0.0` — zero auth |
| **Enforcement** | Passive — AI decides when to retrieve | Passive — instructional context only | Active — mandating calls by task type + `android_code_validator` loop-back gate |
| **Relationship to AndroJack** | Overlapping retrieval scope | **Complementary, not competing** — Skills inform generation; AndroJack's validator checks the result before it reaches you | — |

> Android Skills and AndroJack solve different halves of the same problem. Skills give an agent context *before* it writes code. AndroJack's `android_code_validator` is the gate that runs *after* — checking the generated code against 28 rules before you ever see it. Use both if your agent supports Agent Skills.

---

## 🔒 Security & Privacy

| Property | Implementation |
|:---------|:---------------|
| **Domain allowlist** | Requests only to Google/Android/Kotlin official domains |
| **HTTPS only** | Outbound documentation fetches refuse non-HTTPS URLs, cap body size, and redact query strings in retry logs |
| **Local by default** | `serve` binds to loopback only unless you explicitly pass `--allow-remote` |
| **HTTP hardening** | Streamable HTTP validates `Origin` and `Host` headers and caps request bodies and active sessions |
| **Transparent agent** | `User-Agent: AndroJack-MCP/2.0.0` |
| **Read-only** | All 23 tools annotated `readOnlyHint: true` |
| **Zero credentials** | No API keys or tokens required for documentation fetching |
| **Security policy** | Disclosure process and supported versions in [SECURITY.md](SECURITY.md) |

---

## 📋 Changelog

### v2.0.0 — Security Hardening, Compose-First, Developer Verification

- **Content sanitizer for indirect prompt injection** — `src/content-sanitizer.ts` neutralizes structural injection patterns (fake role markers, instruction-reset framing) in any externally-fetched text before it reaches the calling agent's context. `android_debugger` results from `issuetracker.google.com` — the only allowlisted domain indexing free-text, user-submitted content — are wrapped in an explicit untrusted-data boundary.
- **Dependency vulnerabilities patched** — resolved 7 vulnerabilities (3 high) in transitive `undici`/`qs` via a `cheerio` update. Zero breaking changes, 0 vulnerabilities in the shipped tree.
- **Tool 23: `android_developer_verification`** — Google's developer verification program enforces from September 30, 2026 (Brazil, Indonesia, Singapore, Thailand first; global 2027). Covers registration paths, timeline, enterprise exemptions, and CI/CD bulk-registration APIs.
- **Compose-First platform shift reflected** — as of May 19, 2026, Android UI development is officially Compose First; View-based patterns (Fragments, RecyclerView, ViewPager) are flagged as maintenance-mode wherever queried, sourced directly from Google's own announcement rather than left silently outdated.
- **Compose 1.11 v2 Testing Framework** — full migration guide for the new default `StandardTestDispatcher` behavior, plus a validator rule (`UNCONFINED_DISPATCHER_COMPOSE_TEST`) that flags the old assumption.
- **Navigation 3 Scene Decorators (1.1)** — persistent chrome (bottom bars, rails, dialogs) without per-screen awareness.
- **Android Studio codename corrected** — was two full codenames stale ("Panda 2"). Now correctly reflects **Quail (2026.1.x)** as current stable, AGP 9.2.0.
- **Android Skills positioning** — documents Google's first-party Android Skills/CLI (April 2026) and positions AndroJack's validator as the complementary post-generation enforcement gate, not a competing retrieval layer.
- **28 validator rules** (was 26) — added `UNCONFINED_DISPATCHER_COMPOSE_TEST` and `NEW_FRAGMENT_CLASS_COMPOSE_FIRST`.
- **Fabricated version numbers removed** — a prior session's dependency version catalog example asserted several unverified version numbers. Replaced with only-confirmed values plus explicit `CHECK_LIVE_VIA_gradle_dependency_checker` placeholders.
- **Full version sync** — closed a gap where `src/version.ts` had been bumped without propagating to `package.json`, all IDE config files, and manifest files — now enforced as a release checklist item.

### v1.7.1 — Engineering Hardening & Community Parity

- **54-Test Coverage** — Implemented comprehensive unit and contract tests for validator rules, HTML parser, LRU cache, and HTTP security layer.
- **Discovery Parity** — Fixed `/.well-known/mcp` endpoint to correctly report `tools: 22`.
- **Dependency Sanitization** — Removed `node-fetch` (migrated to native `fetch`) and pruned stale overrides for a cleaner supply chain.
- **Rule Hardening** — Improved Compose component detection for `NavHost` and `BottomAppBar`.
- **URL Remediation** — Fixed broken documentation anchors for Android 17 `ACCESS_LOCAL_NETWORK` and `handoff`.

### v1.7.0 — Android 17 / API 37 Support

- **Tool 22: `android_api17_compliance`** — Full reference for Android 17 platform stability (March 26, 2026).
- **31 validator rules** — Expanded from 24 to 31 with dedicated Android 17 and Room 3.0 removal checks.
- **WindowManager 1.5.0** — Added Large (1200dp) and Extra-large (1600dp) breakpoints and layout patterns.
- **Room 3.0 alpha** — Support for modern SQLiteDriver migration paths.


---

## 👥 Authorship & Ownership

**Vikas Sahani** — Product Lead (vikassahani17@gmail.com)  
**Claude AI** — AI Engineering Lead

---

<div align="center">

MIT License © 2026 Vikas Sahani | [SECURITY.md](SECURITY.md)

*Built because 35% of Stack Overflow visits in 2025 are developers debugging AI-generated code.*  
*AndroJack exists so none of those visits are yours.*

</div>

