ShizuStore

AppSlim Analyzer

Horizen5

0.6.3 · GitHub

Download APK
Software management Android 10+ 2 months ago Proprietary
96 ShizuStore
239 GitHub
7 Stars
2 MB Size

More about this app

Android runtime analyzer profiling launch behavior, CPU/memory and Dex calls, then slimming apps through hooks, rules and Shizuku or root actions.

AppSlim Analyzer

Android App Runtime Analysis & Smart Slimming Platform

Languages: 简体中文 · English


Instead of blindly deleting APKs, AppSlim Analyzer inspects an app's real behavior at runtime, identifies low-value components, and slims it down through hooks, rules, and dynamic strategies.

✨ Features

  • 🚀 One-tap Detection (launch behavior analysis): A single tap auto-opens the target app, keeps it in the foreground for 10 seconds sampling every 500ms, records which Activities were started and each process's CPU / memory usage, then auto-returns to this app and shows the results (grant "Display over other apps" so it can return automatically; otherwise tap the notification). Results highlight the highest-usage Activity / process, with a one-tap "back to detail & manage" entry.
  • 📋 Activity Enumeration: Statically enumerate all Activities of the target app (with exported / launcher flags).
  • 🔍 Dex Behavior Scan: Scan the target APK's Dex to spot system-capability calls and SDK fingerprints.
  • 📊 Runtime Monitoring: A foreground service samples process CPU / memory / network / WakeLock (via UsageStats).
  • 🪝 LSPosed Module: This app is itself an Xposed module and can block specific Activities / Services / Providers by rule.
  • 🔐 Tiered Permission Support: Normal mode (UsageStats) / ADB / Root (Magisk, KernelSU), with automatic downgrade.
  • 💥 Crash Logging: Globally captures uncaught exceptions to disk for fast diagnosis.
  • 🔋 Background Auto-Throttle (v0.5.8): When the app moves to the background, all sampling coroutines pause (except the foreground detection service); foreground refresh interval is lowered from 500ms to 2s, so it no longer pins a CPU core.

🛠 Tech Stack

Layer Choice
UI Kotlin + Jetpack Compose (Material3)
Architecture ViewModel + StateFlow + Navigation
Persistence Room
Async Kotlin Coroutines
Root Magisk / KernelSU (RootShell)
Non-root Shizuku
Hook LSPosed (this app is an Xposed module)

🔬 How It Works (which code does the detection use)

The One-tap Detection (launch behavior analysis) is ported directly from the author's other project APPLENS (ActivitySampler + SamplingService), and lands as these modules:

  • Foreground Activity detection: reads the most-recently-foregrounded Activity via UsageStatsManager.queryEvents (works in normal mode with only the "Usage Access" permission granted), falling back to dumpsys activity activities when unavailable; it does not rely on cross-UID-restricted dumpsys.
  • Sampling cadence: one sample every 500ms for 10s (20 sampling points in total).
  • CPU / memory: top -b -n 1 and dumpsys meminfo (routed through su when root is available).
  • Staying alive: detection runs inside a foreground Service (ProfileService) + PARTIAL_WAKE_LOCK, so our app is not killed after launching the target and moving to the background.
  • HyperOS compatibility: it does not scan /proc nor force-launch its own Activity from the background (avoiding background-launch restrictions that cause crashes).

Key source locations:

File Role
app/.../lens/launcher/ProfileService.kt Foreground detection service (ported from APPLENS SamplingService)
app/.../lens/launcher/ApplensSampler.kt Sampler (ported from APPLENS ActivitySampler)
app/.../lens/launcher/ApplensShell.kt Shell execution (ported from APPLENS ShellUtils, prefers su)
app/.../lens/launcher/ProfileSession.kt State bridge: Service → ViewModel → UI
app/.../util/CrashLogger.kt Global exception capture, written to files/crash/crash.log
app/.../monitor/MonitorService.kt Runtime component monitoring (Activity / Service / CPU / network)
app/.../hook/HookEntry.kt LSPosed hook entry (this app is an Xposed module)

📦 Build & Install

How to build

This project uses Gradle (AGP 8.5.2 / Kotlin 2.0.20 / Compose BOM 2024.09.00). No separate Gradle install is needed — the Gradle Wrapper is committed at the repo root.

# 1) Clone
git clone https://github.com/Horizen5/Appslim.git
cd Appslim

# 2) Build the Release APK (output: app/build/outputs/apk/release/app-release.apk)
./gradlew assembleRelease

# Or build the Debug APK
./gradlew assembleDebug

Note: assembleRelease signs with the bundled keystore.jks, which is excluded from this repository. To sign with your own key, place your keystore at keystore.jks in the repo root, or edit the path/password in signingConfigs inside app/build.gradle.kts.

Requirements

  • Android Studio Hedgehog or newer
  • JDK 17
  • Android SDK (compileSdk / targetSdk = 34, minSdk = 29 → Android 10+)

Build

git clone https://github.com/Horizen5/Appslim.git
cd Appslim
./gradlew assembleRelease

Note: assembleRelease signs with the bundled keystore.jks, which is excluded from this repository. Provide your own signing key.

Install

  1. Enable "Install unknown apps" on your device.
  2. Install app/build/outputs/apk/release/app-release.apk (or download a prebuilt APK from Releases).
  3. Open the app, go to any app's detail page, and tap 一键检测 (One-tap Detection).

Permission note

  • Usage Access: Before the first detection, tap "去开启使用情况访问 (open usage access)" inside the app and grant the permission in system settings; otherwise the target app's foreground Activity cannot be read (CPU / memory still work in normal mode).

📂 Project Structure (excerpt)

app/src/main/java/com/appslim/analyzer/
├── monitor/        # Runtime data collection (MonitorService, etc.)
├── analysis/       # Risk scoring / SDK identification / dependency analysis
├── lens/           # One-tap detection: Activity enumeration + Dex scan + launch sampling
│   ├── launcher/   # ProfileService (foreground service) / ApplensSampler / Shell
│   ├── collector/  # CPU / memory / process collectors
│   └── scanner/    # Activity enumeration / Dex analysis / package scan
├── hook/           # LSPosed hook entry
├── root/           # RootShell / Shizuku bridge
├── rules/          # rules.json generation
└── ui/             # Compose UI & ViewModel

⚠️ Disclaimer

This project is for learning and researching Android runtime behavior analysis only. Do not use it to violate others' privacy or any vendor's terms of service.

📄 License

For learning and research purposes only. All rights reserved.

Close

How Shizuku is used

Can freeze and restore app components via `IPackageManager.setComponentEnabledSetting` through Shizuku

This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.

How this app uses Shizuku

Shizuku is used to freeze and restore other apps components directly.

  • Freeze app components: selected activities, services, receivers and providers for a chosen app are disabled in bulk through the system package service via Shizuku, so they stop running in the background.
  • Restore app components: previously frozen components are re-enabled the same way, either selectively or by resetting a whole package to its original state.

Android APIs or commands used

  • IPackageManager.setComponentEnabledSetting
Close

Changelog

What's new for version 0.6.3

Android 应用运行时分析与智能精简平台。

这一版重写了应用列表模块,从「扫一遍再显示」改成 MT 管理器式的四级架构, 并解决了纯缓存方案最大的隐患——缓存一致性。

⚡ 列表秒开:慢在哪,就绕开哪

原来的做法是启动时把所有应用的 APK 都解析一遍(Activity/Service 数量、图标全解), 应用一多就要等好几秒。问题不在「扫描慢」,而在一开始就不该扫这么多。

层 做什么 为什么
① 快速列表 getInstalledApplications(0) flag 传 0,不解析任何组件信息,几十毫秒返回
② Room 缓存 组件数量等重信息落库 二次启动直接读表,不碰 APK
③ 安装广播 PACKAGE_ADDED/REMOVED/REPLACED 补上「App 开着时装了新应用」的缺口
④ 懒加载 点进详情才做深度解析 用不到的信息一律不算

图标只解可见项 —— LruCache 缓存 400 张,卡片进入可视区才异步解码。 原来一次性解几百张 Bitmap,既慢又占内存。

排序放在组合层 —— 名称/可瘦身/最近更新/最近使用四种排序走 combine, 切换排序不触发任何重新扫描。

🔄 v0.6.3:缓存一致性

纯缓存方案有个隐患:刚装完的新 App 不在缓存里,列表就看不到它。

分两种情况:

  • 重新打开 App — 每次 refreshAppList() 都会重新调 getInstalledApplications, 不是纯读缓存,所以新应用会出现(v0.6.2 已经是这个行为)
  • App 正开着的时候装了新应用 — 这就是 v0.6.3 补的洞

做法是在 Application context 上动态注册广播监听:

IntentFilter().apply {
    addAction(Intent.ACTION_PACKAGE_ADDED)
    addAction(Intent.ACTION_PACKAGE_REMOVED)
    addAction(Intent.ACTION_PACKAGE_REPLACED)
    addDataScheme("package")   // ← 少了这行收不到任何广播
}

两个细节:

  • 必须 addDataScheme("package") —— 这三个广播都带 package: 这个 data scheme, 不声明的话过滤器不匹配,一条都收不到
  • 动态注册 + 挂在 Application 上 —— 静态注册在 Android 8+ 会被后台广播限制拦掉; 挂在 Activity 上则会随页面销毁而失效

📊 增量更新,不做全量重扫

第二阶段的深度信息只对「缓存里没有」或「APK 路径变了」的应用重新解析, 而且每 25 个批量提交一次,避免频繁触发重组。


方法笔记:这套架构抽象成了可复用的方法,写在 dev-craft / 让 Android 应用列表秒开

大小:2.9 MB · 要求:Android 10+

Close

Permissions

11 permissions requested

  • android.permission.QUERY_ALL_PACKAGES
  • android.permission.PACKAGE_USAGE_STATS
  • android.permission.KILL_BACKGROUND_PROCESSES
  • android.permission.FOREGROUND_SERVICE
  • android.permission.FOREGROUND_SERVICE_SPECIAL_USE
  • android.permission.RECEIVE_BOOT_COMPLETED
  • android.permission.INTERNET
  • android.permission.POST_NOTIFICATIONS
  • android.permission.SYSTEM_ALERT_WINDOW
  • com.appslim.analyzer.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
  • moe.shizuku.manager.permission.API_V23
Close