Agent skill

Re Frida Script Author

by dslsdzc in dslsdzc/rev-skills

Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Frida Script Author

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-frida-script-author --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-frida-script-author .claude/skills/re-frida-script-author && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-frida-script-author
GitHub stars
117
Token cost
~1.2k tokens
SKILL.md length
321 words
Files
3 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.

  • Works in 2 steps: 目标侦察 → 模板选择:按特征清单对照 [[re-frida/frida-scripts]]…
  • Tasks that involve Mobile application security
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls python and brew

What it does

Re Frida Script Author is an agent skill from dslsdzc/rev-skills. Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida)。 触发词:生成Frida脚本、写hook脚本、frida脚本怎么写、写个hook、脚本生成。

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/decision-tree.md` and `references/gotchas.md`).

It sits in Security, covering Mobile application security. It works with Frida, Python, Java and Ghidra. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Mobile application security

Example prompts

  • “/re-frida-script-author”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. 目标侦察
  2. 模板选择:按特征清单对照 [[re-frida/frida-scripts]] 模板表

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Frida Script Author loads about 1.2k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 31 tokens; SKILL.md has 321 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 321 words, ~1,236 tokens.

Download SKILL.mdSave it as .claude/skills/re-frida-script-author/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-frida-script-author
description
Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida)。 触发词:生成Frida脚本、写hook脚本、frida脚本怎么写、写个hook、脚本生成。
type
atomic
capabilities
frida-instrumentation

Frida 脚本生成

何时使用 / 何时不用

  • 用:需要新脚本时——拦截(加密/网络/文件)、绕过(检测/固定)、追踪(JNI/方法调用)
  • 用:现成模板没有的变体——按 [[re-frida/frida-scripts]] 模板改写出目标专用脚本
  • 不用:执行现成脚本 → 转 [[re-frida]](本技能只产出脚本,运行与进程管理在 re-frida)
  • 不用:反检测对抗面整体分析 → [[re-analyze/anti-dynamic-workflow]]
  • 不用:纯静态可解的问题——先走 [[re-apk]] / [[re-ghidra]] 静态路径,动态是最后手段
  • 不用:目标不可达(无设备/无 root/无越狱、加固拦注入)——先解决环境([[re-frida]] 工具准备),不硬写脚本

工具准备

frida-tools(脚本编写与运行验证)
  • 推荐(upstream 路径): python -m pip install -U frida-tools,建议用 venv 或 pipx 隔离环境
  • 第三方渠道: brew install frida 等非 upstream 渠道,安装前核验版本与维护状态,不与 pip 路径等同看待
  • 验证: frida --version、frida-ps -U(连设备后)
  • 注意: frida(运行时)与 frida-tools(CLI)版本需配套;跨大版本升级(16 → 17)有 API 移除,写法差异见 [[gotchas]] 版本组
python3(配合脚本调试)
  • 各平台同 [[re-python]] 工具准备
反编译辅助(侦察用)
  • jadx([[re-apk]])静态出类/方法清单;Ghidra/IDA([[re-ghidra]] / [[re-ida]])native 侧符号与调用点定位
  • 验证: 能按包名列出目标类与方法签名
目标设备/模拟器
  • Android 真机/模拟器 + frida-server(至少与主机 frida 同 major,安装见 [[re-frida]] 工具准备);桌面目标直接本机
  • iOS 越狱环境 frida-server 见 [[re-ios-jb]]

操作步骤

按「探 → 选 → 改 → 验」四步,先探后写,不猜。每步产物(特征清单/脚本/验证输出)记录路径 + sha256(见 [[re-triage]]),供报告引用。

  1. 目标侦察:

    • 静态:目标包名/类名/关键 API([[re-apk]] jadx 输出)、加固商特征([[re-mobile-pack]])、Flutter/RN 混合结构([[re-hybrid-app]])
    • 动态基线:原样跑一次抓崩溃与日志(崩溃特征 → 保护机制对照,见 [[re-analyze/anti-dynamic-workflow]])
    • 产出:目标特征清单——检测点/目标 API 全限定名/输入输出形态/方法 overload 数
    • 不确定的类名/方法名先小脚本枚举(Java.enumerateLoadedClasses / Java.use(...).overloads),不猜名字
    • 侦察结论记入 [[re-analyze/analysis-contract]] 契约字段(包名/类名/API 清单),供脚本与报告复用
  2. 模板选择:按特征清单对照 [[re-frida/frida-scripts]] 模板表:

目标特征模板
HTTPS 抓包被 TLS 加密(BoringSSL)TLS 密钥日志(SSLKEYLOGFILE)
证书固定挡抓包SSL 固定绕过(TrustManager/CertificatePinner)
加密算法/密钥要提取加密拦截(Cipher/SecretKeySpec 全 overload)
加固/运行时解密DEX dump(类加载点)/ SO dump
双向 TLS 客户端证书keystore p12 导出
JNI 动态注册要还原RegisterNatives + 汇聚点双 hook
反调试/检测拦截检测绕过表(root/属性/文件/命令)
  • 特征不匹配任何模板 → 组合改写(多个模板拼装)而非从零写
  • 选完模板先读模板内已知边界注释([[re-frida/frida-scripts]]),避免重复踩坑
  1. 改写:

    • 替换占位符:包名/类名/方法名(精确匹配,Java 全限定名)
    • overload 精确匹配:先 overloads 枚举再逐个定义或按参数类型选(见坑 1)
    • 结构规范:Java 操作包在 Java.perform;保存 original 引用、带原 this 调用;Interceptor.attach 里 onEnter 用 this.context 读寄存器,改返回值只能在 onLeave 用参数 retval.replace(...)——this 上只有 returnAddress/context/errno/lastError/threadId/depth,没有 this.returnValue;且 retval 跨调用复用,需留存时先 ptr(retval.toString()) 复制
    • 输出统一 JSON(可打印 ASCII + hex 双格式)经 send() 传出;每个 hook 主体 try/catch,错误发消息不静默
    • 同一类多 hook 合并进一个 .implementation(缓存静默覆盖,见坑 2)
    • 骨架参考(Java + native 双面最小结构,按目标裁剪):
      js
      Java.perform(function () {
        var Cls = Java.use("com.target.Cls");
        Cls.method.overload("java.lang.String").implementation = function (s) {
          try { send({ type: "call", arg: s ? s.toString() : null }); }
          catch (e) { send({ type: "error", msg: String(e) }); }
          return this.method(s);          // 调原实现(保留原 this)
        };
      });
      Interceptor.attach(
        Process.getModuleByName("libtarget.so").getExportByName("func"),
        { onEnter: function (args) { send({ type: "native", arg0: args[0].toInt32() }); } }
      );
    • native 侧:导出符号优先(Process.getModuleByName(...).getExportByName;旧写法 Module.getExportByName 见 [[gotchas]] 版本组);非导出函数用调用点 hook 或内存特征定位
  2. 验证:

    sh
    frida -U -f <pkg> -l script.js --pause   # spawn + 停在早期代码前
    frida -U -f <pkg> -l script.js -o out.json  # 输出存文件(大流量/批量时)
    • 验证清单:hook 挂载成功(无报错输出)→ 触发目标路径(操作 app 或复现调用)→ 输出与静态分析一致 → 重复触发输出稳定
    • 输出 JSON 可解析、目标行为符合预期(拦截到目标调用/绕过生效)
    • 失败 → 回步骤 2 重选模板或细化特征;崩溃 → 按 [[re-analyze/anti-dynamic-workflow]] 崩溃对照表定位;输出为空 → 见 [[decision-tree]] 排查分支

跨域联合

  • [[re-frida]]:脚本执行(本技能产出 → re-frida 运行)
  • [[re-mobile]] / [[re-android-native]]:移动目标场景衔接
  • [[re-analyze/anti-dynamic-workflow]]:检测面与崩溃迭代法
  • [[re-frida/frida-scripts]]:模板素材库(re-frida references)
  • [[re-analyze/analysis-contract]]:脚本输出按数据契约消费(证据存档)
  • [[re-ios-jb]]:iOS 越狱环境执行侧

常见坑与陷阱

  • overload 不匹配静默失效:现象——hook 无输出;原因——目标方法 overload 签名与定义不符;对策——先 Java.use(...).<method>.overloads 列出全部重载再选
  • Java.use 缓存覆盖:现象——多个 hook 只生效最后一个;原因——同类多次 .implementation 赋值静默覆盖;对策——合并进一个 hook
  • 参数索引版本相关:现象——native 参数读错;原因——目标版本字段/参数位次变化;对策——对照目标符号核实,不照搬经验值
  • 不侦察就写脚本:现象——脚本对不上目标;原因——跳过步骤 1;对策——先探后写
  • 绕过类脚本只观察不持久化:现象——测试后目标状态被改;原因——脚本含写操作;对策——脚本只做读取/日志,绕过仅用于观察(红线)
  • 类未加载时 hook 不生效:现象——类存在但无输出;原因——懒加载/加固延迟加载;对策——Java.choose 或对类加载点下 hook([[re-analyze/anti-dynamic-workflow]])
  • 版本相关 API 报错:现象——Module.getExportByName is not a function;原因——Frida 17 移除静态 Module 查找 API;对策——按 [[gotchas]] 版本组迁移写法
  • 模板选择分支与验证排查树见 [[decision-tree]];版本差异与边界见 [[gotchas]];全部在沙箱内执行([[re-analyze/platform-tips]] 最高原则),脚本输出按 [[re-analyze/analysis-contract]] 契约存档

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-frida-script-author of dslsdzc/rev-skills.

  • SKILL.md
  • references/decision-tree.md
  • references/gotchas.md

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Frida Script Author next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Frida Script Author compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Frida Script Author this skilldslsdzc/rev-skills117—~1.2kAutomated safety check: PassApache-2.0
Apk Reversingzhaji2333/CkSKILLS112—~1.7kAutomated safety check: PassMIT
Rev Unicorn Debugindex-login/MobileRE-Skill111—~1.9kAutomated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Skylosduriantaco/skylos843—~581Automated safety check: PassApache-2.0
Skylos Securityduriantaco/skylos843—~545Automated safety check: PassApache-2.0

Similar skills

  • Apk Reversing

    zhaji2333/CkSKILLS

    当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

    112 GitHub stars~1.7k tokensUpdated 22 days ago
    SecurityAuto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    111 GitHub stars~1.9k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Skylos

    duriantaco/skylos

    Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

    843 GitHub stars~581 tokensUpdated yesterday
    SecurityAuto-check passed
  • Skylos Security

    duriantaco/skylos

    Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

    843 GitHub stars~545 tokensUpdated yesterday
    SecurityAuto-check passed
  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    213 GitHub stars~4.2k tokensUpdated 29 days ago
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    117 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    117 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Categories

Questions about Re Frida Script Author

What does Re Frida Script Author do?

Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills. Re Frida Script Author is an agent skill from dslsdzc/rev-skills.

When should I use Re Frida Script Author?

Re Frida Script Author fits situations like: tasks that involve Mobile application security.

How do I install Re Frida Script Author in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a claude-code`. Or copy the skill folder (.claude/skills/re-frida-script-author in dslsdzc/rev-skills) into .claude/skills/re-frida-script-author in your project. Claude Code loads it when a task matches its description.

How do I install Re Frida Script Author in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a codex`. Or copy the skill folder (.claude/skills/re-frida-script-author in dslsdzc/rev-skills) into .agents/skills/re-frida-script-author in your project. Codex loads it when a task matches its description.

Can I use Re Frida Script Author in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-frida-script-author -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-frida-script-author, .gemini/skills/re-frida-script-author, .github/skills/re-frida-script-author and .opencode/skills/re-frida-script-author in your project.

What does Re Frida Script Author need to run?

Going by SKILL.md and its folder, Re Frida Script Author needs the command-line tools its instructions call (python and brew). Our summary lists: Python 3.

Does Re Frida Script Author access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Frida Script Author safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Frida Script Author use?

Re Frida Script Author is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Frida Script Author use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Re Frida Script Author?

Skills that share tags, products or a category with Re Frida Script Author: Apk Reversing (zhaji2333/CkSKILLS, 112 stars), Rev Unicorn Debug (index-login/MobileRE-Skill, 111 stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars) and Skylos (duriantaco/skylos, 843 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Frida Script Author?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.