Show HN: Thyme – A New AI-Based App Reverse Engineering Tool A developer released Thyme, an AI-based reverse engineering tool that integrates the Garlic Java/Dex decompiler in-process to decompile APKs, DEX/JAR files and IPA archives and disassemble ARM A64, A32 and T32 native code into a single DuckDB workspace with a SQL-queryable call graph. Thyme runs entirely on the local machine, exposes a Model Context Protocol server via `thyme --mcp` over a unix socket or named pipe rather than a network port, and is priced at $0 for the free tier or a one-time $49 payment for the Analysis pass, with a 30-day trial on first run and a one-time licence covering every 0.x release. Java decompilation, in-process Integrates the Garlic Java/Dex decompiler for rapid decompilation of JVM and Dalvik code, source code at github https://github.com/neocanable/garlic . Open an APK and get Java back, with the symbols the compiler left behind. Open a .so and get ARM disassembly — A64, A32 or T32 — with basic blocks and control-flow graphs. Both land in one DuckDB workspace, so the call graph is a table you can run SQL against rather than a picture you have to squint at. The decompiler is linked in-process — there is no subprocess, no scratch directory, and nothing leaves the machine. Supports static disassembly analysis for ARM A64, A32, and T32 instruction sets. Supports call graph queries across Java, Dalvik, and native libraries, enabling seamless call graph tracing between Java and native code within APKs. Basic blocks with the assembly inline, edges coloured by kind, jump-to-address from the entry point table, and export to Graphviz .dot . Drop to the byte level or to smali when the decompiler's output is not the truth you need. Pull every .so out of an APK and treat each as a project in its own right. A bare library is not a lesser project for having no Java in it. A bundled screen mirror with a GPU colour-conversion path, so a 1080×2400 device does not cost a core to watch. thyme --mcp speaks the Model Context Protocol over stdio, so an agent can drive the analysis. It reaches the running IDE over a unix socket or named pipe — not a network port. Keep the credentials for the AI CLIs you already use in one place, and launch one against the open project. Thyme with a real project open — an APK, its native libraries, and the call graph underneath. Use the arrows to page through them. | Format | What you get | Status | |---|---|---| | APK | Java decompilation, native libraries, manifest metadata | stable | | DEX / JAR | Java decompilation, call graph | stable | | IPA | Archive browsing, Mach-O payloads | stable | | ELF64 .so | A64 disassembly, CFG, cross-references | stable | | ELF32 .so | A32 / T32 disassembly, CFG | stable | | Mach-O .dylib | A64 disassembly, CFG, cross-references | stable | | Mach-O | Other Mach-O — executables, bundles | partial | The Analysis pass: the workspace database, the SQL-queryable call graph, and native library analysis. Everything else — opening APK, DEX, JAR and IPA files, Java decompilation, ARM disassembly A64, A32 and T32 , hex and smali views, control-flow graphs and the phone mirror — runs without one. When the licence server is reachable, yes: Thyme posts the licence to it and caches the answer locally. That is what lets a licence be revoked, and it is the only thing the app ever sends anywhere. The request contains the licence text and nothing else — no file names, no binary contents, no telemetry. Yes. The licence is a plain text file, and the app holds the matching public key. With no network it verifies the signature locally and starts. ~/.garlic/license is the file, and it is the same file the garlic command-line tool reads, so one licence covers both. No. Analysis runs entirely on your machine. The MCP server talks over a unix socket or a named pipe rather than a network port, and the only outbound request the app makes is the licence check above. A one-time licence covers every 0.x release and the features listed above. If a future major version changes what the licence unlocks, existing licences keep working for the version they were bought on. $0 Open APK, DEX, JAR and IPA. Java decompilation, ARM disassembly A64, A32, T32 , hex and smali views, call graph, CFG. No account, no key. 30-day trial of the Analysis pass on first run, no account needed. $49 Everything in Free, plus the Analysis pass: the workspace database, the SQL-queryable call graph, and native library analysis. One-time payment, handled by Stripe. Delivered on screen and by email. $490 The same licence as Pro, priced for organisations that need it on paper. One-time and perpetual, with the same terms. Free to download. The Analysis pass needs a licence, and there is a 30-day trial on first run.