Frida Mobile Security
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-frida -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-frida --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-frida .claude/skills/re-frida && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-frida" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida into .claude/skills/re-frida/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-fridaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-frida -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-frida --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-frida .agents/skills/re-frida && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-frida" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida into .agents/skills/re-frida/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-frida -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-frida --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-frida .cursor/skills/re-frida && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-frida" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida into .cursor/skills/re-frida/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-frida--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-frida -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-frida --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-frida .gemini/skills/re-frida && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-frida" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida into .gemini/skills/re-frida/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-fridaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-frida -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-frida .github/skills/re-frida && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-frida" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida into .github/skills/re-frida/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-frida -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-frida --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-frida .opencode/skills/re-frida && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-frida" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida into .opencode/skills/re-frida/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-fridaFrida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.
Re Frida is an agent skill from dslsdzc/rev-skills. Frida 动态插桩(桌面+移动统一)。 触发词:frida、hook、插桩、绕过、spawn
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/frida-scripts.md`).
It sits in Security, covering Mobile application security. It works with Frida, Python, Android and iOS. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
adbpippython3sshpythonFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.combuild.frida.reFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Frida loads about 2.8k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 14 tokens; SKILL.md has 736 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 736 words, ~2,793 tokens.
.claude/skills/re-frida/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.动态分析按 [[re-analyze/platform-tips]] 最高原则:移动端在受控设备 / 模拟器快照内执行,桌面端插桩前确认沙箱环境。所有工具先验证再使用。
pip install frida-tools(Python 3.8+;建议 venv: python3 -m venv venv && venv/bin/pip install frida-tools)frida --version(输出 frida 版本号);frida-ps -U / frida-trace -h 可用https://github.com/frida/frida/releases,选 frida-server-<版本>-android-<架构>(arm64 选 -arm64,32 位选 -arm,模拟器 x86_64 选 -x86_64)frida --version);为避免功能/API 差异,推荐使用完全相同且最新的版本。架构与设备匹配,否则连接报协议错误(见坑 1)adb push frida-server-xxx /data/local/tmp/frida-server
adb shell "chmod 755 /data/local/tmp/frida-server"
adb shell "su -c /data/local/tmp/frida-server" & # 或 adb root 后直接运行https://build.frida.re 安装 frida deb,或 ssh root@<设备IP> 后安装frida-ps -U 能列出设备进程(-U = USB 设备,-R = 远程 ip:port)>=3.7 下限不同,需单独满足): python -m pip install -U objection,建议另建 3.10+ 的 venv 或 pipx 隔离objection --versionobjection -n <应用或 Bundle ID> start,内置 android hooking / ios hooking 子命令(如 android hooking list activities、ios sslpinning disable)-g / explore 已弃用(在 CLI 中隐藏,仅出弃用告警,旧写法仍可跑);新写作用 -n + start按顺序执行,每步记下结果。
spawn vs attach 选择:
frida -U -f com.target.app # spawn:从零启动应用,能抓启动早期逻辑(解密 / 初始化)
frida -U com.target.app # attach:附加到已运行进程(不重启)
frida-trace -U -f com.target.app -i "Java!*" # 启动即跟踪 Java 方法调用规则:抓启动逻辑 / 绕过早期检测用 spawn;只是观察现状用 attach。attach 晚于启动,可能错过已执行完的早期逻辑(见坑 2)。
JS hook 编写(拦截 / 改参 / 返回值):
// hook.js —— 拦截、改参数、改返回值(Android Java 层)
Java.perform(function () {
var cls = Java.use("com.example.Target");
cls.doLogin.implementation = function (user, pass) {
console.log("doLogin(" + user + ", " + pass + ")");
return this.doLogin("hacked", "pass123"); // 改参
};
cls.isLicensed.implementation = function () {
return true; // 改返回值
};
});frida -U -f com.target.app -l hook.js原生函数用 Interceptor.attach(Process.getModuleByName("libfoo.so").findExportByName("func"), { onEnter: ..., onLeave: ... }) 拦截(onEnter 改参数、onLeave 用 retval.replace() 改返回值)。桌面端同样本:frida -p <pid> -l hook.js。
枚举与调用(enumerateModules / Java.perform):
Java.perform(function () {
Java.enumerateLoadedClasses({
onMatch: function (c) { if (c.indexOf("target") >= 0) console.log(c); },
onComplete: function () {}
});
});// 模块与导出枚举(原生层)
Process.enumerateModules().forEach(function (m) { console.log(m.name + " " + m.base); });
Process.getModuleByName("libfoo.so").enumerateExports().forEach(function (e) { console.log(e.name); });运行: frida -U -f com.target.app -l enum.js。定位到目标后直接主动调用:Java.use("com.x").method(...) / 原生导出函数。
绕过证书校验 / 检测(常见模板):
// Android SSL 绕过模板(配合抓包工具)
Java.perform(function () {
var X509TrustManager = Java.use("javax.net.ssl.X509TrustManager");
var TrustAll = Java.registerClass({
name: "com.bypass.TrustAll",
implements: [X509TrustManager],
methods: { checkClientTrusted: function () {}, checkServerTrusted: function () {},
getAcceptedIssuers: function () { return []; } }
});
var SSLContext = Java.use("javax.net.ssl.SSLContext");
SSLContext.init.implementation = function (km, tm, sr) {
this.init(km, [TrustAll.$new()], sr);
};
});// iOS 证书绕过:hook SecTrustEvaluateWithError 返回值
var SecTrust = Module.findGlobalExportByName("SecTrustEvaluateWithError"); // Frida 17+:全局符号静态查找
Interceptor.attach(SecTrust, { onLeave: function (r) { this.context.x0 = 0; } }); // arm64 返回寄存器 x0;x86_64 用 rdi 场景先验证现成命令:objection -n com.target.app start → android sslpinning disable / ios sslpinning disable。
反检测对抗(隐藏 frida-server、改名):
/data/local/tmp/frida-server 路径、gum-js-loop / gmain 线程名、/proc/self/maps 中的 frida 特征、frida 字符串# 1) 二进制改名后启动(避开路径检测)
cp frida-server-xxx /data/local/tmp/fridad
adb shell "su -c 'chmod 755 /data/local/tmp/fridad && /data/local/tmp/fridad' &"
# 2) 换端口 + adb 端口转发,主机用 -H 连接
adb shell "su -c '/data/local/tmp/fridad -l 0.0.0.0:27142' &"
adb forward tcp:27142 tcp:27142
frida -H 127.0.0.1:27142 -f com.target.appJava.use("com.target.rootcheck").isRooted.implementation = function () { return false; };脚本模板与对抗方法论:常用脚本骨架见 [[frida-scripts]](TLS keylog / DEX/SO dump / JNI 注册还原 / 加密拦截 / 检测绕过表);崩溃迭代法与检测面对照表见 [[re-analyze/anti-dynamic-workflow]]——先基线跑看裸崩,再定点 hook,不预置绕过全家桶。
[[re-address-space]]:运行时基址换算(Process.getModuleByName(...).base 与链接地址对齐)
[[re-mobile]]:工作流第 3 步动态插桩固定调用本技能
[[re-apk]] / [[re-ios]]:静态分析后需要运行时行为(解密 / hook / 绕过 / 脱壳执行)时调用本技能
系统调用级跟踪互补 → [[re-tracing]];运行时内存提取 → [[re-memdump]]
本技能被 [[re-analyze]] 的 triage「移动 App 分析」路径调用(re-mobile → re-frida)
脚本生成:目标特征 → 模板选择 → 改写验证 → [[re-frida-script-author]](模板素材 [[frida-scripts]])
frida-ps -U 报 unable to communicate with the frida server / 协议错误;原因——客户端与 frida-server major 不一致,或所用的功能在目标版本上不存在;对策——先查 major 是否匹配(frida --version 对照 frida-server 版本,见工具准备),再确认该功能是否被对应版本支持;升级侧用 pip install -U frida-toolsTypeError: Module.findExportByName is not a function(或 getExportByName / enumerateExports / findBaseAddress 同类);原因——17.0.0 起静态查找与枚举 API 全部移除,静态只余 Module.load / Module.findGlobalExportByName / Module.getGlobalExportByName,其余改为模块实例方法;对策——先取实例再查:Process.getModuleByName("libfoo.so").findExportByName("func")(find 返 null,get 抛异常)、基址用 .base、枚举用 .enumerateExports();全局符号(原 null 模块参数)改用 Module.findGlobalExportByName(...);注意 Process.getModuleByName 在模块未加载时抛异常(旧 Module.findExportByName 返 null)——不确定时先用 Process.findModuleByName 判空再查;动笔前 frida --version 确认版本再选写法(迁移清单见 [[re-frida-script-author]] 版本相关组)-f spawn 模式起步即插桩;仍错过则 hook dlopen / ClassLoader.loadClass 这类更早的执行点frida 线程名或 maps 特征;对策——步骤 5 改名 + 换端口;仍检测用 frida-gadget 注入(隐藏于进程内)Java.perform 外调用 Java API、模块名大小写不符;对策——用步骤 3 的枚举先核对名称,脚本内 console.log 打桩定位IsDebuggerPresent/NtQueryInformationProcess 等导出,反调试照样触发、进程退出;原因——加壳/加固目标不走导入表:自实现 GetProcAddress、API 名存哈希,或直接 syscall(内联 Nt* 直调),hook 点根本没经过;对策——hook 更深一层(ntdll 的 syscall 包装点)、跟踪 GetProcAddress/哈希解析处反推真实调用点,反调试与反 VM(RegOpenKeyExA/GetSystemFirmwareTable)API 一并 hook(Arkana 项目实战模板),先用 Process.enumerateModules()/enumerateExports 确认实际调用目标再插桩/proc/self/fd 的 memfd 名称、JIT 缓存池(pool-frida)、frida_agent.so/frida_rpc 等内存字符串与导出符号、管道/linjector 名称,甚至非标准端口也会被扫(Promon 式扫描);对策——用 undetected-frida 补丁集(字符串/符号/线程/协议/memfd/JIT 池全量混淆,Magisk/KSU 模块形态),或 frida-gadget + 自编译隐藏版,缩小指纹面/proc/self/maps+/proc/self/status 进程监控 + 非标准端口扫描,整体防线而非单点;对策——先处理完整性校验与进程监控(hook 校验函数返回、patch 监控点)再过反调试,hook 落到自定义导入解析处而非导出 API,必要时结合 [[re-apk]] 静态改 smali + Native 层插桩配合SocketOutputStream 无结果,抓包却看到流量;原因——应用多进程(发流量的逻辑在子进程)或使用 Netty 的 SocketChannelImpl(不走 OutputStream 路径);对策——排查顺序:hook 最外层出口 → 无果 ps -e 查子进程分别 hook → 再试 SocketChannelImpl 等替代实现;hook 成功后打印堆栈(Netty 的 MessageToByteEncoder 链)定位组装/加密代码;从"编解码器链"逐层向上追明文对象与加密产物bArr 类)拿当前密钥,再向上追踪密钥来源与传输路径,配合抓包对照(首包固定头如 89 04 01 01 可作协议锚点)Process.arch==x64 且找不到目标原生 so),运行时从未执行你的字节;部分目标在模拟器上校验宽松,「模拟器能跑」可能是降级假象;对策——按阶段选环境:静态 patch 与渲染回归可用任意模拟器(含 x86 翻译层),动态插桩必须原生 ARM,交付验证必须与目标匹配的真机;翻译层假象可证伪:把已知必需函数首指令 patch 成裸 ret,UI 照常渲染即运行时没执行你的字节,立即停掉该环境的 live 工作(盘上静态 patch 下次启动重新翻译仍可用);真机采集前 svc power stayon true 并唤醒,防睡眠屏造成「空白」假截图
(来源:reverse-skills(inliver233),MIT)/dev/binder,不能用 --device 或 binderfs)、新内核无 ashmem 时未加 androidboot.use_memfd=1、设了 ro.secure=1 ro.debuggable=0 杀掉 root adb、停掉的容器 binder 已消失无法 docker restart、adbd 高负载下崩溃;对策——binder 用 bind-mount、新内核强制 use_memfd、保留 root adb(防篡改用保持签名有效而非藏 root)、重建容器后重注入 adb 公钥(echo $PUBKEY > /data/misc/adb/adb_keys)、大文件用 docker cp 而非 adb push、动态分析用 spawn 模式(frida -U -f,attach 在防篡改下常 0 命中);定位认知——它是数据采集工具而非迭代环境,采完动态数据回稳定环境做静态 patch 回归
(来源:reverse-skills(inliver233),MIT)findModuleByName 的 waitForLibapp 包装器,起步优先 spawn 模式;破 cid 墙:目标函数 onEnter 记 lr(returnAddress)+ Thread.backtrace(Backtracer.ACCURATE) 前 20 帧,一次回溯定位分派点;guard 定位三件套:Stalker.follow transform 里对 ldr 类指令放 putCallout(首个命中 PC = guard)、MemoryAccessMonitor.enable 等重建触发(arm64 支持不一需回退)、候选 hook 扫射;运行时翻转验证前置:live writePointer 翻转候选门字段 → 触发重建 → 组件消失即确认门字段,确认后再投静态 patch,省掉反复重打包;frida 17 起 Java bridge 不再内置于底层 GumJS runtime,但 frida CLI/REPL 与 frida-trace 仍自带三个 bridge,普通 frida -l 脚本无需改动;仅自建 agent / 走 bindings 注入脚本时需显式安装 frida-java-bridge(必要时用 frida-compile 打包)
(来源:reverse-skills(inliver233),MIT)© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .claude/skills/re-frida of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Frida next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Frida this skilldslsdzc/rev-skills | 125 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Frida Mobile Securityindex-login/MobileRE-Skill | 123 | — | ~3k | Automated safety check: Pass | MIT | |
| Mira Risk Collectvw2x/Mira | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | |
| R0crawl Skillsmanyuegong33/r0crawl_skills | 306 | — | ~1.2k | Automated safety check: Pass | None | |
| Mobile Reversesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Offensive MobileSnailSploit/Claude-Red | 7.3k | — | ~3.5k | Automated safety check: Pass | MIT |
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
manyuegong33/r0crawl_skills
面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。
sickn33/agentic-awesome-skills
Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
transilienceai/communitytools
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Categories
Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills. Re Frida is an agent skill from dslsdzc/rev-skills.
Re Frida fits situations like: tasks that involve Mobile application security.
Run `npx skills add dslsdzc/rev-skills --skill re-frida -a claude-code`. Or copy the skill folder (.claude/skills/re-frida in dslsdzc/rev-skills) into .claude/skills/re-frida in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-frida -a codex`. Or copy the skill folder (.claude/skills/re-frida in dslsdzc/rev-skills) into .agents/skills/re-frida in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-frida -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-frida, .gemini/skills/re-frida, .github/skills/re-frida and .opencode/skills/re-frida in your project.
Going by SKILL.md and its folder, Re Frida needs the command-line tools its instructions call (adb, pip, python3, ssh and python). Our summary lists: Python 3.
SKILL.md names 2 domains. In commands or code: github.com and build.frida.re; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Frida is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Re Frida: Frida Mobile Security (index-login/MobileRE-Skill, 123 stars), Mira Risk Collect (vw2x/Mira, 105 stars), R0crawl Skills (manyuegong33/r0crawl_skills, 306 stars) and Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.