AI-powered Android project health analyzer built with LangGraph
Point it at any Android project. Get a full health report in 30 seconds.
pip install droiddoctor
droiddoctor ~/AndroidStudioProjects/MyAppAndroid projects rot silently. AGP falls behind, Compose BOM drifts, exported components leak, deprecated APIs linger, permissions creep.
You know you should audit. But it's scattered across lint, dependency checks, manual manifest review, and that one senior dev who "just knows."
DroidDoctor does the full audit in one command.
| Check | What It Does |
|---|---|
| Gradle Dependencies | Parses build.gradle(.kts) + libs.versions.toml, checks every dep against Google Maven and Maven Central for latest versions |
| Manifest Security | Exported components without permissions, dangerous permissions, cleartext traffic, hardcoded debuggable flag, missing backup rules |
| Deprecated APIs | Regex scan for AsyncTask, startActivityForResult, ViewModelProviders.of, android.support.*, kapt, findViewById, and 7 more patterns |
| Compose Adoption | Measures XML layout vs @Composable file split across all modules with adoption percentage |
| AI Analysis | LLM synthesizes all findings into a prioritized action plan: ๐จ FIX NOW / |
A 7-node LangGraph agent with conditional routing and shared state:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโบโ analyze_gradle_dependenciesโโโโโโโโโโ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ
โโโโโโโโโโดโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโ โผ
โ scan_project โโโบโ audit_manifest โโโโบ โโโโโโโโโโโโ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโ
โ _structure โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ collect โโโโโบโ llm_analyze โโโโโบโ generate โ
โโโโโโโโโโฌโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ _results โ โ โ โ _report โ
โ โ detect_deprecated_apis โโโโบ โโโโโโโโโโโโ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโ โฒ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โโโโโโโโโโบโ check_compose_adoption โโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Design philosophy: The LLM never scans files. Static analysis handles scanning โ it's deterministic and fast. The LLM only does what LLMs are good at: correlating findings, prioritizing by risk, and generating actionable explanations.
pip install droiddoctorOr from source:
git clone https://github.com/samuvelp/droiddoctor.git
cd droiddoctor
pip install -e .export ANTHROPIC_API_KEY=sk-ant-xxxxxOr create a .env file:
ANTHROPIC_API_KEY=sk-ant-xxxxx
droiddoctor /path/to/your/android/projectDroidDoctor supports 5 LLM providers. Use whatever key you already have:
# Claude (default)
export ANTHROPIC_API_KEY=sk-ant-...
droiddoctor /path/to/project
# OpenAI
pip install langchain-openai
export OPENAI_API_KEY=sk-...
droiddoctor /path/to/project --provider openai
# Google Gemini
pip install langchain-google-genai
export GOOGLE_API_KEY=...
droiddoctor /path/to/project --provider gemini
# Groq (free tier available)
pip install langchain-groq
export GROQ_API_KEY=gsk_...
droiddoctor /path/to/project --provider groq
# Ollama (fully local โ no API key needed)
pip install langchain-ollama
droiddoctor /path/to/project --provider ollama --model llama3.1Override the default model for any provider:
droiddoctor /path/to/project --provider openai --model gpt-4.1
droiddoctor /path/to/project --provider gemini --model gemini-2.5-flash# Full scan with AI analysis
droiddoctor /path/to/android/project
# Save markdown report to file
droiddoctor /path/to/project --save
# Custom output path
droiddoctor /path/to/project --save -o health-report.md
# Offline mode โ skip LLM, just raw data (no API key needed)
droiddoctor /path/to/project --no-llm
# Use a specific LLM provider
droiddoctor /path/to/project --provider openai
# Show version
droiddoctor --versionโญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ DroidDoctor v0.1.0 โ
โ AI-powered Android project health analyzerโ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โญโโโโโโโโโโโโโโ Health Score โ MyApp โโโโโโโโโโโโโโโฎ
โ 62/100 ๐ โ
โ 3 module(s) scanned โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
Outdated Dependencies
โโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโฌโโโโโโโโโฌโโโโโโโโโโโ
โ Dependency โ Current โ Latest โ Severity โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโผโโโโโโโโโผโโโโโโโโโโโค
โ com.android.tools.build โ 8.2.0 โ 8.7.0 โ CRITICAL โ
โ org.jetbrains.kotlin โ 1.9.22 โ 2.1.0 โ MAJOR โ
โ androidx.core:core-ktx โ 1.10.0 โ 1.15.0 โ MINOR โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโดโโโโโโโโโดโโโโโโโโโโโ
Manifest Issues
โโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Severity โ Issue โ
โโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ CRITICAL โ Cleartext (HTTP) traffic enabled โ
โ CRITICAL โ android:debuggable="true" hardcoded โ
โ WARNING โ Dangerous permission: CAMERA โ
โ WARNING โ Exported activity without permission โ
โโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Deprecated APIs
โโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ API โ Replacement โ
โโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ AsyncTask โ Kotlin Coroutines โ
โ startActivityForResult โ Activity Result API โ
โ ViewModelProviders.of โ by viewModels() delegate โ
โ kapt โ Migrate to KSP โ
โโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โญโโโ Compose Adoption โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ XML Layouts: 42 | Composable Files: 12 | 22.2% โ
โ โโโโโโโโโโโโโโโโโโโโ 22.2% โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โญโโโ AI-Powered Analysis โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ โ
โ ๐จ FIX NOW โ
โ โข Remove android:debuggable="true" โ this makes โ
โ your release APK debuggable in production โ
โ โข Disable cleartext traffic โ user data is being โ
โ sent over unencrypted HTTP โ
โ โ
โ โ ๏ธ FIX THIS SPRINT โ
โ โข Update AGP 8.2.0 โ 8.7.0 โ you're missing โ
โ build performance improvements and R8 fixes โ
โ โข Replace AsyncTask with viewModelScope.launch โ โ
โ deprecated since API 30 โ
โ โ
โ ๐ PLAN FOR NEXT QUARTER โ
โ โข Compose is at 22% โ create a migration tracker โ
โ and convert one screen per sprint โ
โ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
- Single or multi-module โ reads
settings.gradle(.kts)to discover all modules - Groovy or Kotlin DSL โ parses both
build.gradleandbuild.gradle.kts - Version catalogs โ full
gradle/libs.versions.tomlsupport with version ref resolution - Network failures โ if Maven version checks fail, skips gracefully and continues
- No Compose projects โ works fine on 100% XML projects, reports without judgment
- Large projects โ automatically skips
.gradle/,build/,.idea/,node_modules/
droiddoctor/
โโโ droiddoctor/
โ โโโ cli.py # CLI entry point โ rich terminal UI
โ โโโ graph.py # LangGraph definition โ 7 nodes, conditional routing
โ โโโ state.py # AgentState TypedDict + data models
โ โโโ nodes/
โ โ โโโ scanner.py # Node 1: Discover project layout and modules
โ โ โโโ gradle.py # Node 2: Parse deps, check versions via HTTP
โ โ โโโ manifest.py # Node 3: Security audit of AndroidManifest.xml
โ โ โโโ deprecated.py # Node 4: Regex scan for 13 deprecated patterns
โ โ โโโ compose.py # Node 5: XML vs Composable adoption metrics
โ โ โโโ analyzer.py # Node 6: LLM synthesis + health score
โ โ โโโ reporter.py # Node 7: Final markdown report generation
โ โโโ parsers/
โ โโโ gradle_parser.py # build.gradle(.kts) + libs.versions.toml parser
โ โโโ manifest_parser.py # AndroidManifest.xml parser (xml.etree)
โโโ tests/
โ โโโ fixtures/ # Sample Android project files for testing
โ โโโ test_nodes.py # 22 tests covering all parsers and nodes
โโโ pyproject.toml
โโโ requirements.txt
โโโ .env.example
โโโ LICENSE
Each node is a pure function: (AgentState) -> dict. To add a new check:
- Create a new node in
droiddoctor/nodes/ - Read what you need from
AgentState, return only the keys you update - Wire it into the graph in
graph.pywithadd_node()+add_edge() - Add a table for it in
reporter.py
Ideas for new nodes:
- ProGuard/R8 rules audit โ missing keep rules
- Room migration checker โ detect missing migration paths
- API level compatibility โ flag APIs unavailable on minSdk
- Test coverage estimator โ test files vs source files ratio
- CI config checker โ missing lint/test steps in GitHub Actions
Contributions welcome! Good first issues:
- Groovy
build.gradletest fixtures -
buildSrcand convention plugin support - JSON output format (
--format json) - True parallel fan-out for analysis nodes
- GitHub Actions integration
- HTML report output
- Diff mode โ compare two scans
MIT โ see LICENSE