Apk Reversing
zhaji2333/CkSKILLS
当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…
Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-frida-script-author --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-frida-script-author .claude/skills/re-frida-script-author && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-frida-script-author" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida-script-author into .claude/skills/re-frida-script-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida-script-author", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida-script-authorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-frida-script-author --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-frida-script-author .agents/skills/re-frida-script-author && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-frida-script-author" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida-script-author into .agents/skills/re-frida-script-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida-script-author", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-frida-script-author --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-frida-script-author .cursor/skills/re-frida-script-author && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-frida-script-author" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida-script-author into .cursor/skills/re-frida-script-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida-script-author", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-frida-script-author--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-frida-script-author --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-frida-script-author .gemini/skills/re-frida-script-author && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-frida-script-author" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida-script-author into .gemini/skills/re-frida-script-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida-script-author", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-frida-script-authorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-frida-script-author .github/skills/re-frida-script-author && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-frida-script-author" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida-script-author into .github/skills/re-frida-script-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida-script-author", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-frida-script-author --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-frida-script-author .opencode/skills/re-frida-script-author && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-frida-script-author" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-frida-script-author into .opencode/skills/re-frida-script-author/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-frida-script-author", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-frida-script-authorFrida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.
Re Frida Script Author is an agent skill from dslsdzc/rev-skills. Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida)。 触发词:生成Frida脚本、写hook脚本、frida脚本怎么写、写个hook、脚本生成。
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/decision-tree.md` and `references/gotchas.md`).
It sits in Security, covering Mobile application security. It works with Frida, Python, Java and Ghidra. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pythonbrewFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Frida Script Author loads about 1.2k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 31 tokens; SKILL.md has 321 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 321 words, ~1,236 tokens.
.claude/skills/re-frida-script-author/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.python -m pip install -U frida-tools,建议用 venv 或 pipx 隔离环境brew install frida 等非 upstream 渠道,安装前核验版本与维护状态,不与 pip 路径等同看待frida --version、frida-ps -U(连设备后)frida(运行时)与 frida-tools(CLI)版本需配套;跨大版本升级(16 → 17)有 API 移除,写法差异见 [[gotchas]] 版本组按「探 → 选 → 改 → 验」四步,先探后写,不猜。每步产物(特征清单/脚本/验证输出)记录路径 + sha256(见 [[re-triage]]),供报告引用。
目标侦察:
Java.enumerateLoadedClasses / Java.use(...).overloads),不猜名字模板选择:按特征清单对照 [[re-frida/frida-scripts]] 模板表:
| 目标特征 | 模板 |
|---|---|
| HTTPS 抓包被 TLS 加密(BoringSSL) | TLS 密钥日志(SSLKEYLOGFILE) |
| 证书固定挡抓包 | SSL 固定绕过(TrustManager/CertificatePinner) |
| 加密算法/密钥要提取 | 加密拦截(Cipher/SecretKeySpec 全 overload) |
| 加固/运行时解密 | DEX dump(类加载点)/ SO dump |
| 双向 TLS 客户端证书 | keystore p12 导出 |
| JNI 动态注册要还原 | RegisterNatives + 汇聚点双 hook |
| 反调试/检测拦截 | 检测绕过表(root/属性/文件/命令) |
改写:
overloads 枚举再逐个定义或按参数类型选(见坑 1)Java.perform;保存 original 引用、带原 this 调用;Interceptor.attach 里 onEnter 用 this.context 读寄存器,改返回值只能在 onLeave 用参数 retval.replace(...)——this 上只有 returnAddress/context/errno/lastError/threadId/depth,没有 this.returnValue;且 retval 跨调用复用,需留存时先 ptr(retval.toString()) 复制send() 传出;每个 hook 主体 try/catch,错误发消息不静默.implementation(缓存静默覆盖,见坑 2)Java.perform(function () {
var Cls = Java.use("com.target.Cls");
Cls.method.overload("java.lang.String").implementation = function (s) {
try { send({ type: "call", arg: s ? s.toString() : null }); }
catch (e) { send({ type: "error", msg: String(e) }); }
return this.method(s); // 调原实现(保留原 this)
};
});
Interceptor.attach(
Process.getModuleByName("libtarget.so").getExportByName("func"),
{ onEnter: function (args) { send({ type: "native", arg0: args[0].toInt32() }); } }
);Process.getModuleByName(...).getExportByName;旧写法 Module.getExportByName 见 [[gotchas]] 版本组);非导出函数用调用点 hook 或内存特征定位验证:
frida -U -f <pkg> -l script.js --pause # spawn + 停在早期代码前
frida -U -f <pkg> -l script.js -o out.json # 输出存文件(大流量/批量时)Java.use(...).<method>.overloads 列出全部重载再选.implementation 赋值静默覆盖;对策——合并进一个 hookJava.choose 或对类加载点下 hook([[re-analyze/anti-dynamic-workflow]])Module.getExportByName is not a function;原因——Frida 17 移除静态 Module 查找 API;对策——按 [[gotchas]] 版本组迁移写法© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/re-frida-script-author of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Frida Script Author next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Frida Script Author this skilldslsdzc/rev-skills | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Apk Reversingzhaji2333/CkSKILLS | 112 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Rev Unicorn Debugindex-login/MobileRE-Skill | 111 | — | ~1.9k | Automated safety check: Pass | MIT | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Skylosduriantaco/skylos | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | |
| Skylos Securityduriantaco/skylos | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 |
zhaji2333/CkSKILLS
当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…
index-login/MobileRE-Skill
Debug and emulate specific code fragments or functions using the Unicorn engine.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
duriantaco/skylos
Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.
duriantaco/skylos
Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.
OrbitCurve/firmware-reverse-engineering
Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Categories
Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills. Re Frida Script Author is an agent skill from dslsdzc/rev-skills.
Re Frida Script Author fits situations like: tasks that involve Mobile application security.
Run `npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a claude-code`. Or copy the skill folder (.claude/skills/re-frida-script-author in dslsdzc/rev-skills) into .claude/skills/re-frida-script-author in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a codex`. Or copy the skill folder (.claude/skills/re-frida-script-author in dslsdzc/rev-skills) into .agents/skills/re-frida-script-author in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-frida-script-author, .gemini/skills/re-frida-script-author, .github/skills/re-frida-script-author and .opencode/skills/re-frida-script-author in your project.
Going by SKILL.md and its folder, Re Frida Script Author needs the command-line tools its instructions call (python and brew). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Frida Script Author is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Re Frida Script Author: Apk Reversing (zhaji2333/CkSKILLS, 112 stars), Rev Unicorn Debug (index-login/MobileRE-Skill, 111 stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars) and Skylos (duriantaco/skylos, 843 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.