Well a quick web search on "decompile apk" would reveal a number of options. As long as you can read the code that results it might help you, though if someone wanted to beat such a check there would surely be ways (trivial ones would include the app having to download other resources after installation, with those containing the malware rather than the apk itself, or providing a "clean" app for install and then putting malware into an "update" at a later date).
But by and large the best bet is to be careful where you get stuff from. You can avoid the worst risks by applying some simple rules, e.g. sites that provide "cracked" apps for download, and sites where anyone can upload stuff, are very high risk. Also any app suggested by spam, by an unsolicited pop-up of any sort (the OS never recommends downloading boosters, antivirus, etc), and anything that is downloaded in the background while you are browsing something else, should be avoided at all costs.