cd /news/ai-tools/show-hn-thyme-a-new-ai-based-app-rev… · home › topics › ai-tools › article
[ARTICLE · art-145892] src=apppipeline.online ↗ pub= topic=ai-tools verified=true sentiment=· neutral

Show HN: Thyme – A New AI-Based App Reverse Engineering Tool

A developer released Thyme, an AI-based reverse engineering tool that integrates the Garlic Java/Dex decompiler in-process to decompile APKs, DEX/JAR files and IPA archives and disassemble ARM A64, A32 and T32 native code into a single DuckDB workspace with a SQL-queryable call graph. Thyme runs entirely on the local machine, exposes a Model Context Protocol server via `thyme --mcp` over a unix socket or named pipe rather than a network port, and is priced at $0 for the free tier or a one-time $49 payment for the Analysis pass, with a 30-day trial on first run and a one-time licence covering every 0.x release.

read4 min views1 publishedOct 6, 2026
Show HN: Thyme – A New AI-Based App Reverse Engineering Tool
Image: source

Java decompilation, in-process

Integrates the Garlic Java/Dex decompiler for rapid decompilation of JVM and Dalvik code, source code at github.

  Open an APK and get Java back, with the symbols the compiler left behind.
  Open a `.so` and get ARM disassembly — A64, A32 or T32 — with basic
  blocks and control-flow graphs. Both land in one DuckDB workspace, so the call graph is a table you can
  run SQL against rather than a picture you have to squint at. The decompiler is
  linked in-process — there is no subprocess, no scratch directory, and nothing
  leaves the machine.

Supports static disassembly analysis for ARM A64, A32, and T32 instruction sets.

Supports call graph queries across Java, Dalvik, and native libraries, enabling seamless call graph tracing between Java and native code within APKs.

Basic blocks with the assembly inline, edges coloured by kind, jump-to-address from the entry point table, and export to Graphviz .dot.

Drop to the byte level or to smali when the decompiler's output is not the truth you need.

Pull every .so out of an APK and treat each as a project in its own right. A bare library is not a lesser project for having no Java in it.

A bundled screen mirror with a GPU colour-conversion path, so a 1080×2400 device does not cost a core to watch.

thyme --mcp speaks the Model Context Protocol over stdio, so an agent can drive the analysis. It reaches the running IDE over a unix socket or named pipe — not a network port.

Keep the credentials for the AI CLIs you already use in one place, and launch one against the open project.

Thyme with a real project open — an APK, its native libraries, and the call graph underneath. Use the arrows to page through them.

Format What you get Status
APK Java decompilation, native libraries, manifest metadata stable
DEX / JAR Java decompilation, call graph stable
IPA Archive browsing, Mach-O payloads stable
ELF64 .so A64 disassembly, CFG, cross-references stable
ELF32 .so A32 / T32 disassembly, CFG stable
Mach-O .dylib A64 disassembly, CFG, cross-references stable
Mach-O Other Mach-O — executables, bundles partial

The Analysis pass: the workspace database, the SQL-queryable call graph, and native library analysis. Everything else — opening APK, DEX, JAR and IPA files, Java decompilation, ARM disassembly (A64, A32 and T32), hex and smali views, control-flow graphs and the phone mirror — runs without one.

When the licence server is reachable, yes: Thyme posts the licence to it and caches the answer locally. That is what lets a licence be revoked, and it is the only thing the app ever sends anywhere. The request contains the licence text and nothing else — no file names, no binary contents, no telemetry.

  Yes. The licence is a plain text file, and the app holds
  the matching public key. With no network it verifies the signature locally and
  starts. `~/.garlic/license` is the file, and it is the same file the
  `garlic` command-line tool reads, so one licence covers both.

No. Analysis runs entirely on your machine. The MCP server talks over a unix socket or a named pipe rather than a network port, and the only outbound request the app makes is the licence check above.

A one-time licence covers every 0.x release and the features listed above. If a future major version changes what the licence unlocks, existing licences keep working for the version they were bought on.

$0

Open APK, DEX, JAR and IPA. Java decompilation, ARM disassembly (A64, A32, T32), hex and smali views, call graph, CFG. No account, no key.

30-day trial of the Analysis pass on first run, no account needed.

$49

Everything in Free, plus the Analysis pass: the workspace database, the SQL-queryable call graph, and native library analysis.

One-time payment, handled by Stripe. Delivered on screen and by email.

$490

The same licence as Pro, priced for organisations that need it on paper. One-time and perpetual, with the same terms.

Free to download. The Analysis pass needs a licence, and there is a 30-day trial on first run.

── more in #ai-tools 4 stories · sorted by recency
── more on @thyme 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/show-hn-thyme-a-new-…] indexed:0 read:4min 2026-10-06 · —