
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
maven-decoder-mcp
Advanced tools
MCP server for reading and decompiling Maven jar files, with online Maven Central search and comprehensive Java project analysis
Your agent guesses at library APIs it has never read. This makes it read them.
Lets AI agents read the actual source of any Maven dependency — decompiles jars from
~/.m2 or Maven Central, and diffs versions for breaking changes.

Ask an agent "I'm upgrading org.jsoup:jsoup from 1.17.2 to 1.23.2 — what breaks?" and
without a way to read the jars it will answer from memory. With this server,
compare_versions reads both jars and reports what actually changed:
| 1.17.2 → 1.23.2 | |
|---|---|
| Breaking changes | 45 |
| Members removed | 31 |
| Members added | 150 |
| Classes with API changes | 47 of 115 compared |
Members are compared as declared, so one that moved to a supertype is reported as removed even though it may still be callable. The tool states this in its own output.
It works on artifacts that have no sources jar too: extract_class_info falls back
to javap and returns parsed fields, methods, and bytecode version — which is exactly
the case for the internal artifacts in a corporate Nexus.
npx skills add https://github.com/salitaba/maven-decoder-mcp --skill maven-code-search
That installs the maven-code-search agent skill, which tells your agent when to reach
for these tools. For a raw MCP server setup instead, see Installation.
~/.m2/repository)curl -fsSL https://raw.githubusercontent.com/salitaba/maven-decoder-mcp/main/install.sh | bash
# Install uv (if not installed)
curl -Ls https://astral.sh/uv/install.sh | sh
# Ensure your shell PATH is updated (restart shell or eval as printed by installer)
# Run the server via uvx (isolated, fast, no venv needed)
uvx maven-decoder-mcp
# Optional: pick a specific Python
# uvx --python 3.12 maven-decoder-mcp
# Install globally
npm install -g maven-decoder-mcp
# Or install locally
npm install maven-decoder-mcp
# Run the server
maven-decoder-mcp
# or if installed locally: npx maven-decoder-mcp
# Pull and run
docker run --rm -it \
-v ~/.m2:/home/mcpuser/.m2 \
-v $(pwd):/workspace \
ali79taba/maven-decoder-mcp:latest
# Clone repository
git clone https://github.com/salitaba/maven-decoder-mcp.git
cd maven-decoder-mcp
# Option A: Using Virtual Environment
python3 -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\activate
pip install -r requirements.txt
pip install "git+https://github.com/modelcontextprotocol/python-sdk.git"
./setup_decompilers.sh
# Option B: System-wide Installation (not recommended)
./setup_decompilers.sh
Add to your ~/.cursor/mcp_servers.json:
{
"maven-decoder": {
"command": "uvx",
"args": ["maven-decoder-mcp"]
}
}
The server runs as a standard MCP server and can be integrated with any MCP-compatible client.
This repository includes a maven-code-search agent skill that tells AI coding agents when and how to use this MCP for searching installed Maven package code.
npx skills add https://github.com/salitaba/maven-decoder-mcp --skill maven-code-search
The skill is located at skills/maven-code-search and is ready for skills.sh indexing after the repository is pushed.
| Tool | Description |
|---|---|
list_artifacts | List artifacts in Maven repository with filtering |
analyze_jar | Analyze jar file structure and contents |
extract_class_info | Get detailed information about Java classes |
get_dependencies | Retrieve Maven dependencies from POM files |
search_classes | Search for classes across all jars, optionally filtered by annotation |
extract_source_code | Decompile and extract Java source code |
extract_jar_resource | Extract text resources such as .proto files, services, and metadata |
compare_versions | Compare two versions, including a public API diff and breaking changes |
find_usage_examples | Find classes that reference a given class or method |
get_dependency_tree | Get complete dependency tree |
find_dependents | Find artifacts that depend on a specific artifact |
get_version_info | Get installed versions of an artifact (set include_remote to add published ones) |
analyze_jar_structure | Analyze overall jar structure and metadata |
extract_method_info | Extract specific method information from Java classes |
| Tool | Description |
|---|---|
search_maven_central | Search Maven Central for artifacts by name, coordinates, or contained class |
get_remote_versions | List every version published remotely, flagging which are installed |
download_artifact | Download an artifact (jar/sources/POM) into the local cache; accepts latest |
"Show me all dependencies of org.springframework:spring-core:5.3.21"
"Decompile the class com.example.MyService from my Maven repository"
"Find all version conflicts in my Maven repository"
"Compare org.jsoup:jsoup 1.17.2 with 1.23.2 and tell me what would break"
compare_versions diffs the public and protected members of every class the
two versions share, and reports removals separately from additions. Removed
members and removed classes are counted as breaking changes. Members are
compared as declared, so one that moved to a supertype is reported as
removed even though it may still be callable.
"Show me all public methods in the Jackson ObjectMapper class"
"The sources jar is missing. Use extract_class_info for bytecode-backed fields and methods."
"Find and read .proto resources from com.example:protobuf-lib:1.0.0"
When a dependency has no sources jar, extract_class_info uses javap internally and returns parsed fields, methods, bytecode version, and optional verbose bytecode output. Agents should use analyze_jar, extract_class_info, extract_source_code, and extract_jar_resource through this MCP instead of running jar or javap directly.
"List all Spring classes with pagination (page 2, 10 items per page)"
"Extract source code for a large class with summarization"
"Get method information for specific patterns in a class"
"Which Maven artifact contains the class HikariDataSource?"
"Search Maven Central for retrofit"
"What is the newest published version of org.apache.commons:commons-lang3?"
"Download com.google.code.gson:gson:latest and show me the JsonParser class"
The server works against the local repository and remote repositories. Online access is enabled by default.
~/.m2/repository).~/.cache/maven-decoder-mcp/repository) that uses the standard Maven layout.The cache is deliberately separate from ~/.m2 so downloads never interfere
with your Maven or Gradle builds. Responses include an origin field
(local-repository or remote-cache) so you always know where a result came from.
MAVEN_OFFLINE=true # no network access at all; original local-only behavior
MAVEN_AUTO_DOWNLOAD=false # keep online search, but never auto-download
MAVEN_REMOTE_REPOS="https://nexus.corp/repository/maven-public"
MAVEN_REMOTE_USERNAME=builder
MAVEN_REMOTE_PASSWORD=secret
Artifact downloads use repo1.maven.org, which is fast and reliable.
Artifact search uses search.maven.org, the only public index that answers
class-level (c: / fc:) queries correctly. That index rate-limits bursts, so
requests are retried with backoff; a busy period can still surface as a timeout.
Downloads and version listing are unaffected, because they read
maven-metadata.xml directly from the repository.
The server automatically handles large responses through intelligent pagination:
list_artifacts, extract_class_info, search_classes, get_dependencies, find_dependents, get_version_infoLarge text content is automatically summarized to improve readability:
New tool for targeted access to specific methods:
The server is built with a modular architecture:
MavenDecoderServer: Main MCP server implementationResponseManager: Handles pagination and summarizationJavaDecompiler: Handles multiple decompilation strategiesMavenDependencyAnalyzer: Analyzes Maven dependencies and metadataMavenCentralClient: Remote search, version listing, and artifact downloads# Install development dependencies
pip install -e ".[dev]"
# Run tests
pytest
# Run specific test
python test_startup.py
# Build distribution
python setup.py sdist bdist_wheel
# Install locally
pip install dist/maven_decoder_mcp-*.whl
# Build Docker image
docker build -t maven-decoder-mcp .
# Run container
docker run --rm -it maven-decoder-mcp
MAVEN_REPOSITORY / MAVEN_REPO: direct path to local Maven repository (e.g. F:\data\repository). Highest precedence.MAVEN_HOME / M2_HOME: Maven install dir or repository dir. A nested repository/ subdir wins when it exists; conf/settings.xml <localRepository> honored.~/.m2/settings.xml <localRepository> honored when no env var set. Fallback: ~/.m2/repository.MAVEN_OFFLINE: set to true to disable all network access (default: false)MAVEN_AUTO_DOWNLOAD: auto-fetch artifacts missing locally (default: true)MAVEN_REMOTE_REPOS / MAVEN_REMOTE_REPO: comma/space separated repository base URLs (default: https://repo1.maven.org/maven2)MAVEN_SEARCH_URL: comma/space separated Solr search endpoints (default: https://search.maven.org/solrsearch/select)MAVEN_DECODER_CACHE_DIR: where downloaded artifacts are cached (default: ~/.cache/maven-decoder-mcp/repository)MAVEN_REMOTE_USERNAME / MAVEN_REMOTE_PASSWORD: basic-auth credentials for a private mirrorMAVEN_HTTP_TIMEOUT: per-request timeout in seconds (default: 30)MAVEN_HTTP_RETRIES: retries for transient network failures (default: 3)MAVEN_MAX_DOWNLOAD_SIZE: maximum download size in bytes (default: 104857600)MAVEN_VERIFY_CHECKSUM: verify downloads against published SHA-1 (default: true)MCP_LOG_LEVEL: Logging level (DEBUG, INFO, WARNING, ERROR)MCP_MAX_RESPONSE_SIZE: Maximum response size in bytes (default: 50000)MCP_MAX_ITEMS_PER_PAGE: Default items per page (default: 20)MCP_MAX_TEXT_LENGTH: Maximum text length before summarization (default: 10000)MCP_MAX_LINES: Maximum lines before summarization (default: 500)MCP_USAGE_SCAN_LIMIT: Max classes scanned by find_usage_examples (default: 200000)MCP_API_DIFF_LIMIT: Max classes compared by compare_versions (default: 2000)MAVEN_DECODER_DECOMPILER_DIR: Directory holding cfr.jar / procyon-decompiler.jarThe server automatically detects and configures:
Server won't start
# Check Python installation
python --version
# Check Maven repository
ls ~/.m2/repository
# Check logs
maven-decoder-mcp --debug
Decompilation fails
# Check the environment: Java, repository, cache and available decompilers
maven-decoder-setup status
# Install the optional CFR and Procyon decompilers
maven-decoder-setup decompilers
Without CFR or Procyon the server still works, falling back to javap from
the JDK for signatures, fields and methods.
No artifacts found
# Verify Maven repository location
ls ~/.m2/repository
# Run a Maven build to populate repository
mvn dependency:resolve
Maven Central search times out
The public search index rate-limits bursts of requests. Retries with backoff are built in, but during heavy throttling a search can still fail. Workarounds:
# Wait a moment and retry, or raise the retry budget
MAVEN_HTTP_RETRIES=5
# Downloads and version listing do not use the search index, so these keep
# working even while search is throttled:
# get_remote_versions, download_artifact
Downloads fail behind a proxy or firewall
# requests honors the standard proxy variables
export HTTPS_PROXY=http://proxy.corp:8080
# Or point at an internal mirror
export MAVEN_REMOTE_REPOS="https://nexus.corp/repository/maven-public"
# Or turn the network off entirely
export MAVEN_OFFLINE=true
git checkout -b feature/amazing-feature)git commit -m 'Add amazing feature')git push origin feature/amazing-feature)This project is licensed under the MIT License - see the LICENSE file for details.
Made with ❤️ for the Java development community
FAQs
MCP server for reading and decompiling Maven jar files, with online Maven Central search and comprehensive Java project analysis
We found that maven-decoder-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.