Agent skill

Re Android Crypto

by dslsdzc in dslsdzc/rev-skills

Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。

Apache-2.0Auto-check passedSecurity

Install Re Android Crypto

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-android-crypto -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-android-crypto --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-android-crypto .claude/skills/re-android-crypto && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-android-crypto
GitHub stars
117
Token cost
~1.1k tokens
SKILL.md length
234 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。

  • Works in 4 steps: Keystore 审计(AndroidKeyStore 密钥体系) → crypto hook(加密调用点拦截) → 第三方加密库分析(BoringSSL / OpenSSL / Tink /… → …
  • Tasks that involve Mobile application security
  • SKILL.md covers 任务分类器(intent → 路径), 何时使用 / 何时不用, 工具准备 and 操作步骤, plus 2 more sections
  • Calls adb

What it does

Re Android Crypto is an agent skill from dslsdzc/rev-skills. Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。 触发词:Keystore、AndroidKeyStore、Cipher、KeyInfo、StrongBox、加密审计、crypto hook、密钥别名。

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security. It works with Android, Frida and Python. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Mobile application security

Example prompts

  • “/re-android-crypto”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Keystore 审计(AndroidKeyStore 密钥体系)
  2. crypto hook(加密调用点拦截)
  3. 第三方加密库分析(BoringSSL / OpenSSL / Tink / libsodium 等)
  4. 产出与存证:密钥体系图(别名/算法/用途/背书来源)+ 加密调用点清单 + hook 脚本,sha256 存档供 [[re-ioc]] 引用

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Android Crypto loads about 1.1k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 234 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 234 words, ~1,135 tokens.

Download SKILL.mdSave it as .claude/skills/re-android-crypto/SKILL.md (or your agent's skills folder).
name
re-android-crypto
description
Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。 触发词:Keystore、AndroidKeyStore、Cipher、KeyInfo、StrongBox、加密审计、crypto hook、密钥别名。
type
atomic
capabilities
crypto-identification, key-extraction

Android 加密体系审计(crypto audit)

任务分类器(intent → 路径)

用户目的路径
密钥来自 AndroidKeyStore / 硬件背书密钥→ Keystore 审计(步骤 1)
定位加密调用点 / 拦截密文与明文→ crypto hook(步骤 2)
分析第三方加密库(BoringSSL / OpenSSL / Tink / libsodium 等)→ 库分析(步骤 3)

何时使用 / 何时不用

  • 用:Android 应用加密体系审计——密钥体系(Keystore)、加解密调用链、库选型还原
  • 用:getEncoded() 不可用的硬件背书密钥(须走审计而非提取密钥字节)
  • 用:加密拦截时需记录密钥别名与用途(不记录密钥字节——安全边界)
  • 不用:JNI/so 原生逻辑逆向(走 [[re-android-native]]);通用加密算法识别(走 [[re-crypto-id]]);通用密钥提取([[re-crypto-keys]],Keystore 硬件密钥除外)
  • 不用:非 Android 平台(走通用 crypto 域 [[re-protocol]] 分支)
  • 边界:本技能承接 Android crypto audit 全谱——Keystore/Cipher/KeyInfo/hook 为起点,BoringSSL/OpenSSL/Tink/libsodium 等第三方库分析归入本技能(步骤 3),不塞入 re-android-native

工具准备

所有工具先验证再使用。动态 hook 默认沙箱([[re-analyze/platform-tips]] 最高原则);静态审计可免沙箱。

frida([[re-frida]])—— crypto hook 主力
  • 安装与验证见 [[re-frida]] 工具准备;脚本模板见 [[re-frida/frida-scripts]]
  • 验证: frida --version
python3 / jadx —— 静态定位加密调用点
  • python3 安装与验证见 [[re-python]] 工具准备
  • jadx 安装与验证见 [[re-apk]] 工具准备
设备侧命令([[re-apk]] adb 章节)
  • adb shell 取应用运行态(KeyStore 枚举需应用进程内执行)

操作步骤

  1. Keystore 审计(AndroidKeyStore 密钥体系):

    java
    // 应用进程内枚举(frida 注入或 jadx 反编译定位调用点)
    KeyStore ks = KeyStore.getInstance("AndroidKeyStore");
    ks.load(null);
    java.util.Enumeration<String> aliases = ks.aliases();
    • 遍历:aliases() 枚举全部条目(密钥别名 = 应用内引用键)
    • 条目属性:算法(AES/RSA/EC)、用途(encrypt/decrypt/sign/verify)、来源——KeyInfo.getSecurityLevel()(API 31+,返回 SOFTWARE / TRUSTED_ENVIRONMENT(TEE) / STRONGBOX 三档);API 23–30 只有 isInsideSecureHardware()(布尔,TEE 与 StrongBox 同为 true,分不开)
    • 生物绑定:setUserAuthenticationRequired 的密钥在认证失败时不可用(绕过与检测见 [[re-analyze/anti-dynamic-workflow]])
    • 产出:别名 → 算法/用途/硬件背书 清单(不记录密钥字节)
  2. crypto hook(加密调用点拦截):

    js
    // frida:拦截加密调用点,记录算法/模式/密钥别名
    // 别名来源:Key 对象本身不携带别名(KeyStore 无 getKeyAlias),须在 getKey 处记录
    const KeyStore = Java.use('java.security.KeyStore');
    KeyStore.getKey.overload('java.lang.String', '[C').implementation = function (alias, password) {
      console.log('KeyStore.getKey', alias);
      return this.getKey(alias, password);
    };
    const Cipher = Java.use('javax.crypto.Cipher');
    Cipher.init.overload('int', 'java.security.Key', 'java.security.spec.AlgorithmParameterSpec').implementation =
      function (opmode, key, params) {
        console.log('Cipher.init', opmode, key.getClass().getName(), params);  // 对应别名见上方 getKey 输出
        return this.init(opmode, key, params);
      };
    // 另路取回别名:SecretKeyFactory.getInstance(key.getAlgorithm(), 'AndroidKeyStore')
    //   .getKeySpec(key, KeyInfo.class) → KeyInfo.getKeystoreAlias()
    • hook 目标:Cipher.init 系列(算法/模式/IV 来源)、KeyStore.getKey / getEntry(别名与用途)、Signature/Mac 初始化(验签/校验链)
    • 记录:别名与用途,不记录密钥字节(安全边界,见坑 2)
    • 静态定位辅助:jadx 搜 AndroidKeyStore / KeyStore.getInstance / Cipher.getInstance 调用点,与 hook 结果互证
  3. 第三方加密库分析(BoringSSL / OpenSSL / Tink / libsodium 等):

    • 识别:导入表/符号(SSL_*/EVP_*/crypto_*/sodium_* 前缀)+ jadx 依赖声明
    • 定位调用点:库 API 的 xref(静态)或 hook 库导出函数(动态)
    • 与 [[re-android-native]] 衔接:库以 .so 形态存在 → 其 JNI/内部逻辑走 [[re-android-native]],本技能管加密语义(算法/密钥来源/用途)
  4. 产出与存证:密钥体系图(别名/算法/用途/背书来源)+ 加密调用点清单 + hook 脚本,sha256 存档供 [[re-ioc]] 引用

跨域联合

  • [[re-android-native]]:JNI/so 原生逻辑逆向(本技能的 .so 库内部逻辑承接方;Keystore 审计自其转出)
  • [[re-frida]]:hook 执行层([[re-frida/frida-scripts]] 模板)
  • [[re-crypto-id]] / [[re-crypto-keys]]:算法识别与通用密钥提取(Keystore 硬件密钥除外——走本技能审计)
  • [[re-apk]]:应用静态定位(jadx 调用点)
  • [[re-mobile]]:工作流移动分支(加密审计子路径)

常见坑与陷阱

  • 把 Keystore 当普通密钥提取:现象——getEncoded() 拿不到密钥字节,误判「密钥不存在」;原因——AndroidKeyStore 硬件背书密钥不可导出,这是设计而非缺失;对策——改走审计(步骤 1:别名/算法/用途/背书),不追求密钥字节
  • TEE 与 StrongBox 混为一谈:现象——isInsideSecureHardware 为 true 就断言 StrongBox;原因——Secure Hardware 含 TEE 与 StrongBox 两级,该接口是布尔、分不开(isStrongBoxBacked 在 KeyGenParameterSpec 上,只管生成侧,KeyInfo 没有);对策——API 31+ 用 KeyInfo.getSecurityLevel() 取 SOFTWARE / TEE / STRONGBOX 三档;API 23–30 无法细分,结论按「secure hardware(TEE 或 StrongBox)」标注层级
  • 记录密钥字节:现象——hook 脚本把 Keystore 密钥内容打印/落盘;原因——把审计当提取,越过安全边界;对策——只记录别名与用途,密钥字节不落盘(见步骤 2 注)
  • 库语义当 JNI 逻辑分析:现象——第三方加密库的 .so 被按 native 逻辑深挖而忽略加密语义;原因——域不清;对策——库 API 的加密语义(算法/密钥来源/用途)归本技能,内部实现细节才走 [[re-android-native]]

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/re-android-crypto of dslsdzc/rev-skills.

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Android Crypto next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Android Crypto compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Android Crypto this skilldslsdzc/rev-skills117—~1.1kAutomated safety check: PassApache-2.0
Frida Mobile Securityindex-login/MobileRE-Skill111—~3kAutomated safety check: PassMIT
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
Rev Unicorn Debugindex-login/MobileRE-Skill111—~1.9kAutomated safety check: PassMIT
Rev Dex Dumperindex-login/MobileRE-Skill111—~1.9kAutomated safety check: PassMIT
R0crawl Skillsmanyuegong33/r0crawl_skills305—~1.2kAutomated safety check: PassNone

Similar skills

  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    111 GitHub stars~3k tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    111 GitHub stars~1.9k tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Rev Dex Dumper

    index-login/MobileRE-Skill

    Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

    111 GitHub stars~1.9k tokensUpdated 8 days ago
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    305 GitHub stars~1.2k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    117 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    117 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Categories

Questions about Re Android Crypto

What does Re Android Crypto do?

Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。. Re Android Crypto is an agent skill from dslsdzc/rev-skills.

When should I use Re Android Crypto?

Re Android Crypto fits situations like: tasks that involve Mobile application security.

How do I install Re Android Crypto in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-android-crypto -a claude-code`. Or copy the skill folder (.claude/skills/re-android-crypto in dslsdzc/rev-skills) into .claude/skills/re-android-crypto in your project. Claude Code loads it when a task matches its description.

How do I install Re Android Crypto in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-android-crypto -a codex`. Or copy the skill folder (.claude/skills/re-android-crypto in dslsdzc/rev-skills) into .agents/skills/re-android-crypto in your project. Codex loads it when a task matches its description.

Can I use Re Android Crypto in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-android-crypto -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-android-crypto, .gemini/skills/re-android-crypto, .github/skills/re-android-crypto and .opencode/skills/re-android-crypto in your project.

What does Re Android Crypto need to run?

Going by SKILL.md and its folder, Re Android Crypto needs the command-line tools its instructions call (adb). Our summary lists: Python 3.

Does Re Android Crypto access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Android Crypto safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Android Crypto use?

Re Android Crypto is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Android Crypto use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Re Android Crypto?

Skills that share tags, products or a category with Re Android Crypto: Frida Mobile Security (index-login/MobileRE-Skill, 111 stars), Mira Risk Collect (vw2x/Mira, 105 stars), Rev Unicorn Debug (index-login/MobileRE-Skill, 111 stars) and Rev Dex Dumper (index-login/MobileRE-Skill, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Android Crypto?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.