An agent that reverse-engineers apps while you get coffee
Seep Reverse Lab wraps Radare2, JADX, Apktool and Frida behind 23 MCP tools so an AI agent can autonomously audit client-side authorization (CWE-602) end to end.

What it does You give it a plain-language goal — say, “find the premium check in this APK and bypass it” — and the agent triages the binary, picks the right toolchain, decompiles, generates a Frida hook, runs it in a sandbox, and self-heals when the PoC throws errors. The end product is a three-part security report with evidence, including an “airplane-mode” test to prove whether a feature gate is a local boolean or actually server-authoritative. It targets Windows PE, Android APK, Linux ELF and web targets.
The interesting bit
The whole thing is written in Lua and behaves like a state machine for agents: a softseep orchestrator classifies platform × 9 task types through a 7-gate decision tree, and a “lab mode” layer translates colloquial requests into compliance-friendly terminology so security models don’t refuse mid-audit. There’s also aggressive context budgeting — decompiler output can be folded to roughly 60% fewer tokens or summarized to 90% fewer, which is a genuinely practical answer to agents choking on disassembly dumps.
Key highlights
- 23 MCP tools wrapping Radare2, JADX, Apktool and Frida behind one API
- 289 field journals in a searchable knowledge base, consulted before execution (“Zero-Waste Recon”)
- PoC self-healing loop: Frida errors get root-caused and auto-fixed, up to 3 attempts before structured handoff
- Fully offline after setup — all toolchains pre-bundled (251 MB), no network dependencies
- Works with Pi Agent, Claude Code, DeepSeek Harness, Codex and OpenCode
Caveats
- The README is heavy on capability claims and light on verifiable detail — the “8–20 minutes fully unattended” figure is presented without benchmark context
- One MCP runtime path is hardcoded relative and explicitly marked “do not rename,” so the directory layout is fragile
- It’s a 251 MB bundle largely assembled from three referenced upstream projects (apk-reverse, Open-tgtylab, open-reverselab) — substantial glue, and the glue is the point, but worth knowing
Verdict Worth a look if you do client-side authorization audits or want a reference architecture for agent-driven reversing. If you were hoping for a lean library, this is a full workbench with strong opinions — and a legal gray zone, so read the disclaimer first.
Frequently asked
- What is angusdevgo/Seep-Reverse-Lab?
- Seep Reverse Lab wraps Radare2, JADX, Apktool and Frida behind 23 MCP tools so an AI agent can autonomously audit client-side authorization (CWE-602) end to end.
- Is Seep-Reverse-Lab open source?
- Yes — angusdevgo/Seep-Reverse-Lab is open source, released under the GPL-3.0 license.
- What language is Seep-Reverse-Lab written in?
- angusdevgo/Seep-Reverse-Lab is primarily written in Lua.
- How popular is Seep-Reverse-Lab?
- angusdevgo/Seep-Reverse-Lab has 1k stars on GitHub.
- Where can I find Seep-Reverse-Lab?
- angusdevgo/Seep-Reverse-Lab is on GitHub at https://github.com/angusdevgo/Seep-Reverse-Lab.