Android APK Pentester
ptn1411/skill
Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.
Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.
SKILL.md written in Chinese; this summary is our English description.
$ npx skills add dslsdzc/rev-skills --skill re-apk -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-apk --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-apk .claude/skills/re-apk && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-apk" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-apk into .claude/skills/re-apk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-apk", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-apkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-apk -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-apk --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-apk .agents/skills/re-apk && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-apk" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-apk into .agents/skills/re-apk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-apk", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-apk -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-apk --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-apk .cursor/skills/re-apk && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-apk" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-apk into .cursor/skills/re-apk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-apk", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-apk--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-apk -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-apk --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-apk .gemini/skills/re-apk && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-apk" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-apk into .gemini/skills/re-apk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-apk", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-apkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-apk -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-apk .github/skills/re-apk && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-apk" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-apk into .github/skills/re-apk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-apk", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-apk -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-apk --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-apk .opencode/skills/re-apk && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-apk" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-apk into .opencode/skills/re-apk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-apk", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-apkGuides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.
This skill covers the static side of reversing Android packages. It applies when you have an APK and need to see its manifest, decompiled Java, resources, permissions and component structure, or to recognize packing and resource obfuscation before unpacking or patching. It sends runtime hooking, native library logic and DEX extraction from memory to other skills in the same collection.
A long tool-preparation section gives sources, install routes and a version check for each tool: jadx for Java decompilation (needing Java 11 or newer), apktool for unpacking and rebuilding (with a note that its 3.x and 2.x lines differ in commands), aapt2 for resource dumps, optional dex2jar, apksigner and keytool for re-signing, and adb for device checks. Steps are to be done in order with each result recorded as an evidence path and sha256 hash. Two reference files hold commands and known pitfalls, and the excerpt is cut off before the steps. The skill text is in Chinese.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
brewadbaptdnfFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
APK Static Analysis loads about 2k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 21 tokens; SKILL.md has 599 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 599 words, ~1,952 tokens.
.claude/skills/re-apk/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.纯静态分析(解包 / 反编译)可免沙箱([[re-analyze/platform-tips]] 最高原则);涉及动态 / 脱壳转 [[re-frida]] / 脱壳域。所有工具先验证再使用。
https://github.com/skylot/jadx/releases 下载 jadx-<版本>.zip,解压后运行 bin/jadx(Linux/macOS)或 bin\jadx.bat(Windows);GUI 是 bin/jadx-guibrew install jadx;Arch: pacman -S jadxapt install openjdk-17-jre / dnf install java-17-openjdk / pacman -S jre17-openjdk;macOS brew install openjdkjadx --version;版本注——release zip 与 brew/pacman 包同步更新,以实测版本为准https://github.com/iBotPeaches/Apktool/releases 下载 apktool_<版本>.jar 与 wrapper 脚本(Linux/macOS apktool、Windows apktool.bat),脚本与 jar 放同目录apktool --version 确认 major version;2.x 时代的命令与教程直接拿到 3.x 上会报 Unrecognized option(变化清单见 [[gotchas]] 版本差异)apt install apktool(仓库版较旧,命令行为兼容即可)brew install apktoolapktool --versionsdkmanager "build-tools;34.0.0",路径 $ANDROID_HOME/build-tools/34.0.0/aapt2brew install --cask android-commandlinetools 后 sdkmanager "build-tools;34.0.0"aapt2 version;版本注——build-tools 版本随 SDK 更新(示例 34.0.0,新版 SDK 自带更高版本),命令接口稳定,按已装版本使用即可https://github.com/pxb1988/dex2jar/releases 下载 zip,解压后 d2j-dex2jar.sh classes.dex 得 jar,再用 jd-gui 浏览d2j-dex2jar.sh --versionapksigner --version;keytool -helpsdkmanager "platform-tools")apt install adb(Debian/Ubuntu);macOS: brew install --cask android-platform-tools;Arch: pacman -S android-toolsadb version按顺序执行,每步记下结果(证据路径 + sha256,见 [[re-triage]])。
解包(apktool d):
apktool d app.apk -o out/解出 AndroidManifest.xml、smali/(可回编译的字节码)、res/、assets/、lib/。-s(--no-src)不解码源码(只出资源)、-r(--no-res)不解码资源(只出 smali),补丁时按需组合。产物比 jadx 更适合改后回编译。
AndroidManifest 入口/权限/组件:
grep -E 'application|activity|service|receiver|provider' out/AndroidManifest.xml | head -40记录:主入口(application / 首个 activity 的 android:name)、uses-permission(短信 / 通话记录 / 设备管理权限是恶意或敏感信号)、exported 组件、android:debuggable="true"(可调试应用可直接 [[re-frida]] attach)。加固后入口常被替换成壳类(见坑 1)。
jadx 反编译 Java:
jadx -d java-out app.apk # 批量反编译全部 dex 类
jadx app.apk # 或 GUI 模式逐类浏览先看入口类(Application / MainActivity)与算法 / 校验类;敏感串(密钥、URL、校验逻辑)按 grep -rE 'key|secret|sign|license' java-out/ 定位。dex2jar 等价替代:d2j-dex2jar.sh app.apk 得 jar 后用 jd-gui,jar 也可转 [[re-java]] 流程(CFR/JD-GUI 浏览、Java 加固识别)。反编译不出业务代码 → 加固识别(步骤 5)。
smali 补丁思路:
# 改 smali 后回编译、对齐、签名、安装(用 apksigner 时 zipalign 必须在签名之前,签名后不得再改包)
apktool b out/ -o patched.apk
keytool -genkey -v -keystore ks.jks -alias r -keyalg RSA -validity 3650 -storepass 123456
zipalign -P 16 -f -v 4 patched.apk aligned.apk
apksigner sign --ks ks.jks --out signed.apk aligned.apk
adb install signed.apk常用改法:条件跳转取反(if-eqz ↔ if-nez)、把 const/4 v0, 0x0 改成返回常量、把校验方法直接 return-void。先 jadx 定位逻辑再在对应 smali 里改。目标含签名自校验时补丁可能被拦(见坑 2)。
加固/混淆识别:
com.stub.StubApp=爱加密、com.secneo.apkwrapper / com.bangcle.*=梆梆,乐固等);lib/ 多一个壳 so(libjiagu.so=360 加固、libDexHelper.so=爱加密…);classes.dex 体积异常小(真 dex 运行时解密)res/ 资源路径被随机改名、resources.arsc 结构异常aapt2 dump badging app.apk # 包名 / 入口 / 权限速览
aapt2 dump resources app.apk # 混淆后的资源映射AAB 与 split APK(分发形态边界):
.aab(Android App Bundle):本质是 zip,内含 dex 与资源——jadx 可直接打开读代码;真机安装需经 bundletool 生成 APKS,拿到 .aab 按步骤 1-3 走即可base.apk + config.*.apk):主 dex 与代码在 base,语言/密度等配置在 split——静态分析以 base 为主,资源差异在 split 中比对;apktool 对 base 与 split 分别解包加固样本 jadx 只看到壳壳:现象——反编译出来只有 StubApp 之类壳类,业务代码全无;原因——真 dex 加密存放在 assets/ 或运行时才解密;对策——按步骤 5 识别壳,转 [[re-anti-analysis]] 脱壳,或 [[re-frida]] / [[re-memdump]] 运行时取内存 DEX
签名校验拦补丁:现象——重打包安装后闪退或报"签名不一致 / 未签名";原因——应用内自校验签名(对比 PackageManager 的签名信息);对策——定位校验点打补丁绕过(smali 改返回值 / 跳转),或 [[re-frida]] hook PackageManager.getPackageInfo 调用链
资源混淆后无法直接看资源:现象——res/ 路径与资源 ID 对不上、strings 定位不到目标资源;原因——资源被混淆随机改名;对策——aapt2 dump 还原映射(步骤 5),必要时结合动态分析对照
原生 .so 被当 Java 分析:现象——Java 层找不到核心逻辑(算法 / 反调试);原因——敏感逻辑写在 JNI 的 .so 里;对策——lib/ 下 so 转 [[re-format-elf]] + [[re-ghidra]]([[re-binary-core]]),用导出表 / Java_<包名>_<类名>_<方法名> 风格符号对 JNI 函数
apktool 回编译失败:现象——apktool b 报资源编译错误;原因——解包时资源被解码、部分资源格式不兼容回编译;对策——apktool d -r 保留原资源不解码,只改 smali 后回编译
split APK 只分析 base 会缺资源:现象——目标字符串/资源在 base 里找不到;原因——语言/密度配置拆在 config.*.apk split 里;对策——apktool 对 base 与各 split 分别解包,资源差异按 split 比对(步骤 6)
自写 dex 解析四细节:opcode 是 u16 低字节(高字节是寄存器位,读完整 u16 当 opcode 全错位);fill-array-data 是 0x26(31t)、goto 是 0x28(0x24 是 filled-new-array,凭记忆必错);string_data_item 有 uleb128 长度前缀(不跳过会把长度当字符);code_item 的 insns_size 在 +12(+4 是 outs_size)——手写解析器前先对照 dex 规范核对布局
jadx 目录只剩启动脚本:现象——jadx 报 ClassNotFound;原因——安装不完整(jar 缺失/被清理);对策——从 GitHub release 重下完整 zip(codeload.github.com 比 github.com 稳),或直接用 baksmali 等单一工具
容器/双开(VirtualApp 类)样本分析:现象——样本跑在双开容器里行为异常、hook 不到目标进程,或要分析容器本身;原因——VA/Blackbox 容器通过"代理桩 + 动态注册"模拟系统:启动 Activity 走容器内假 AMS(Binder 动态代理拦截,把 VAPP 请求参数还原后再转发真实系统);IO 重定向把写死的绝对路径转向容器内安装路径;ContentProvider 的 onCreate 作为容器初始化入口(handleBindApplication 主动调用);原理同老版 Android(VA 只支持老版本,Blackbox 为现代参考实现);对策——分析容器内应用时注意进程真实归属(容器进程 vs 宿主进程)、hook 点选在容器框架层(假 AMS/IO 重定向函数)而非应用层;识别双开环境(双开检测)看 /proc/self/maps 容器 so、假包名路径特征;这类原理对免安装运行/插件化分析也通用
重打包后 install -r 不生效(重打包陷阱):现象——重打包签名安装后行为毫无变化,误判「patch 无效」;原因——同包名同签名时 -r 会替换既有应用并保留数据,versionCode 未递增不阻止内容更新(它主要影响降级安装规则),「patch 未生效」应排查:签名校验链(见下条)、split APK 不一致、多用户/profile 的安装目标、构建产物缓存(apktool 回编译 build 缓存未清理)、目标进程未重启;对策——装机后做闭环验证:adb shell pm path <包名> 取回已装 APK,对 patch 地址做字节级比对,字节确认在位后再排查逻辑层(消费点错误等)(来源:reverse-skills(inliver233),MIT)
签名校验跨层链与系统版本漂移:现象——重打包后仍弹「签名不一致」类提示,或复用旧式签名适配 hook 后在新系统上反而误报篡改;原因——签名校验常是跨层链(Java 层取签名信息 → 摘要计算 → 原生层与硬编码基线比对,任一层不匹配即判失败),只中和单点不够;应用自带 PackageManager 签名适配 hook 可复用(拦截 getPackageInfo 系列、同时替换 signatures 与 signingInfo、只作用于自身包),但其反射构造的内部签名对象(如 SigningDetails)构造器签名随系统版本变化,抛异常返回 null 后触发误判;对策——优先复用应用自带的签名适配 hook,版本漂移时用 Frida 探测活构造器、改走公开构造器重建;带壳目标优先免重打包(运行时签名适配),无壳再考虑重打包;静态侧找原生比对函数中和失败分支(来源:reverse-skills(inliver233),MIT)
© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/re-apk of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
APK Static Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| APK Static Analysis this skilldslsdzc/rev-skills | 125 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Android APK Pentesterptn1411/skill | 219 | — | ~917 | Automated safety check: Pass | None | |
| Performing Dynamic Analysis Of Android Appmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | |
| Performing Android App Static Analysis With Mobsfmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Mobile Reversesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 |
ptn1411/skill
Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.
mukul975/Anthropic-Cybersecurity-Skills
Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…
mukul975/Anthropic-Cybersecurity-Skills
Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and…
sickn33/agentic-awesome-skills
Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…
mukul975/Anthropic-Cybersecurity-Skills
Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…
mukul975/Anthropic-Cybersecurity-Skills
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination…
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation. This skill covers the static side of reversing Android packages. It applies when you have an APK and need to see its manifest, decompiled Java, resources, permissions and component structure, or to recognize packing and resource obfuscation before unpacking or patching.
APK Static Analysis fits situations like: opening an unfamiliar APK to review its manifest, permissions and exported components; decompiling an Android app to read its Java code and resources; telling whether an APK is packed or obfuscated before deeper analysis.
Run `npx skills add dslsdzc/rev-skills --skill re-apk -a claude-code`. Or copy the skill folder (.claude/skills/re-apk in dslsdzc/rev-skills) into .claude/skills/re-apk in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-apk -a codex`. Or copy the skill folder (.claude/skills/re-apk in dslsdzc/rev-skills) into .agents/skills/re-apk in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-apk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-apk, .gemini/skills/re-apk, .github/skills/re-apk and .opencode/skills/re-apk in your project.
Going by SKILL.md and its folder, APK Static Analysis needs the command-line tools its instructions call (brew, adb, apt and dnf). Our summary lists: Java 11 or newer for jadx; jadx and apktool installed; Android SDK build-tools for aapt2 and apksigner.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
APK Static Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with APK Static Analysis: Android APK Pentester (ptn1411/skill, 219 stars), Performing Dynamic Analysis Of Android App (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Android App Static Analysis With Mobsf (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.