Testing Mobile Ipc
trilwu/secskills
Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…
Android 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-mobile-pack --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-mobile-pack .claude/skills/re-mobile-pack && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-mobile-pack" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-mobile-pack into .claude/skills/re-mobile-pack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-mobile-pack", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-mobile-packType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-mobile-pack --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-mobile-pack .agents/skills/re-mobile-pack && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-mobile-pack" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-mobile-pack into .agents/skills/re-mobile-pack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-mobile-pack", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-mobile-pack --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-mobile-pack .cursor/skills/re-mobile-pack && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-mobile-pack" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-mobile-pack into .cursor/skills/re-mobile-pack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-mobile-pack", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-mobile-pack--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-mobile-pack --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-mobile-pack .gemini/skills/re-mobile-pack && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-mobile-pack" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-mobile-pack into .gemini/skills/re-mobile-pack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-mobile-pack", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-mobile-packInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-mobile-pack .github/skills/re-mobile-pack && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-mobile-pack" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-mobile-pack into .github/skills/re-mobile-pack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-mobile-pack", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-mobile-pack --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-mobile-pack .opencode/skills/re-mobile-pack && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-mobile-pack" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-mobile-pack into .opencode/skills/re-mobile-pack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-mobile-pack", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-mobile-packAndroid 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复. An agent skill from dslsdzc/rev-skills.
Re Mobile Pack is an agent skill from dslsdzc/rev-skills. Android 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复。 触发词:脱壳、Android加固、DEX脱壳、乐固、梆梆、360加固、爱加密
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Mobile, covering Mobile application security and Mobile testing and debugging. It works with Android and Frida. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
adbpipjavaFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Mobile Pack loads about 2k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 647 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 647 words, ~1,974 tokens.
.claude/skills/re-mobile-pack/SKILL.md (or your agent's skills folder).动态脱壳默认在受控设备 / 模拟器快照内执行([[re-analyze/platform-tips]] 最高原则——默认沙箱)。所有工具先验证再使用。
pip install frida-tools(Python 3.8+;建议 venv);frida-server 版本必须与主机一致并推送设备(安装与反检测完整流程见 [[re-frida]] 工具准备)pip install frida-dexdump(Python 3)——运行时搜索内存中的 DEX 魔数并 dumpfrida --version;frida-dexdump -h(能看到 -U/-f/-d 参数)frida-dexdump -U -f <包名>(spawn 起步脱壳)、frida-dexdump -U <pid>(attach)、frida-dexdump -U -f <包名> -d(深度搜索,覆盖多 DEX / 部分抽取)https://github.com/CodingGay/BlackDex/releases;32 位与 64 位是两个独立 APK(目标 App 不出现在列表就换另一个架构版本)hook_*.dex(hook 系统 API 得到)与 cookie_*.dex(DexFile cookie 技术)https://github.com/Youlor/Youpk——基于 Android 7.1.2_r33 二次开发,仅支持 Google Pixel 1:Android Studio 构建后 flash-all.sh 刷入定制 ROMadb shell "echo <包名> >> /data/local/tmp/unpacker.config" → 启动目标 App 自动主动调用脱壳(日志见 "unpack end")→ adb pull /data/data/<包名>/unpackerjava -jar dexfixer.jar ./unpacker ./out(配套 DEX 修复,回填方法指令)adb shell ls /data/data/<包名>/unpacker 能看到 dex/method 产物adb --version;模拟器场景 adb shell 即可dexdump -hmemory dump 或按 [[re-memdump]] 从转储 grep DEX 魔数 dex\n0xx 提取——frida-dexdump 不可用时的兜底路径按顺序执行,每步产物(DEX 路径 + sha256)存档(见 [[re-triage]])。
加固识别(先确认再动手):
com.stub.StubApp(爱加密)、com.secneo.apkwrapper / com.bangcle.*(梆梆)等;入口 Application 被替换成壳类ls out/lib/——libjiagu.so / libprotectClass.so(360 加固)、libDexHelper.so / libexec.so(爱加密)、libsecexe.so / libsecmain.so(梆梆)ls -la out/classes*.dex——真实 DEX 加密存放(assets/ 或运行时解密),壳内 classes.dex 体积异常小运行脱壳(frida-dexdump,默认路径):
adb shell monkey -p <包名> 1 # 先启动 App,让壳把真 dex 加载进内存
frida-dexdump -U -f <包名> # 或 spawn 起步
frida-dexdump -U <pid> # 已运行 attach
frida-dexdump -U -f <包名> -d # 深度搜索(多 DEX / 部分抽取场景)产物在当前目录 <包名>/<时间戳>/*.dex。时机:等 App 进到业务页面再 dump([[re-analyze/platform-tips]] 关键经验——转储时机),一启动就 dump 拿到的是壳初始状态。
静态脱壳(BlackDex / Youpk,frida 被检测时的替代路径):
unpacker/ 目录 → java -jar dexfixer.jar ./unpacker ./outDEX 修复与完整性检查:
file out/*.dex # 应见 "Dalvik dex file version 035"(magic: dex\n035\0)
dexdump out/classes.dex 2>/dev/null | head -30
jadx -d java-out out/ # 反编译验证:业务类是否齐全-d 深度搜索兜底;jadx 多 DEX 直接分析脱壳后分析(走 [[re-apk]] 全流程):
-d 深度搜索、hook ClassLoader 枚举已加载 dex([[re-frida]] 枚举)、内存转储全部提取;jadx 直接加载全部 dex 分析VMRunner.invoke("...") 空壳,模拟器上跑几秒就退;原因——Play 上架自动套的加固三件套:①代码虚拟化:逻辑抽进加密 VM blob(assets 随机名无扩展名文件,\x00IAP 头为解密判据)+ native 解释器 libpairipcore.so(executeVM 等符号名运行时从 XOR 表解码,strings 搜不到);②TEE 密钥:blob 是 AES/GCM 密文,wrapping key 存在设备 TEE(AndroidKeyStore),Play 经 importWrappedKey(SecureKeyWrapper ASN.1)下发——三个硬前提:Play 安装(gpdeku split 载体)、过 Play Integrity、有登录 Google 账号,缺一即 Finsky 日志 FAILURE → 本地伪造 isEncryptionKeyPresent() 也没用;③运行时反篡改:dl_iterate_phdr/opendir 扫 maps 发现注入 so → 故意给 std::vector 喂非法 length → std::__throw_length_error abort(tombstone 指纹 length_error was thrown in -fno-exceptions mode)→ abort 被中和则执行流落 abort 下一条指令踩内存 SIGSEGV + SIG_DFL 复位——信号层 hook 拦不住,根因在检测端(maps 不露脸);对策——先过 Integrity(三绿真机或 PlayIntegrityFix)+ 清掉可见注入模块(Zygisk disable 后重启)VMRunner 任何方法(getVmByteCode/executeVM/readByteCode)进程立刻自毁;原因——PairIP 盯 ArtMethod 完整性:frida hook 改写 entry_point_from_quick_compiled_code 即命中检测;对策——反射直接调用解密函数(getVmByteCode 是 private static,frida 反射可调;blob 名带不带 assets/ 前缀版本间不一致,两种都试),零 hook 零 ArtMethod 改动即可解出全部 blob 明文——脱 PairIP 不需要内核级隐身,只有必须动态跟解释器时才需要lib*sec*/lib*shell* 风格)、动态 DEX loader so、壳 stub 入口类、单一超大 classes.dex 且无业务字符串、smali→dex 往返拆出多个空 stub DEX);确认加固即放弃 apktool 重打包;转储内存必须卡解密窗口——壳瞬态自卸载,/proc/self/maps 里可能都看不到壳,过早/过晚都拿不到解密 DEX;若应用自身还自检「壳是否存在」,脱壳需一并中和该检查(来源:reverse-skills(inliver233),MIT)© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/re-mobile-pack of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Mobile Pack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Mobile Pack this skilldslsdzc/rev-skills | 125 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Testing Mobile Ipctrilwu/secskills | 156 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Performing Dynamic Analysis Of Android Appmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | |
| Mobile Securitytransilienceai/communitytools | 562 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC | 134 | — | ~12k | Automated safety check: Pass | Apache-2.0 | |
| Frida Mobile Securityindex-login/MobileRE-Skill | 123 | — | ~3k | Automated safety check: Pass | MIT |
trilwu/secskills
Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…
mukul975/Anthropic-Cybersecurity-Skills
Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…
transilienceai/communitytools
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…
langbyyi/CyberStrikeAI-SRC
移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Android 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复. An agent skill from dslsdzc/rev-skills. Re Mobile Pack is an agent skill from dslsdzc/rev-skills.
Re Mobile Pack fits situations like: tasks that involve Mobile application security; tasks that involve Mobile testing and debugging.
Run `npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a claude-code`. Or copy the skill folder (.claude/skills/re-mobile-pack in dslsdzc/rev-skills) into .claude/skills/re-mobile-pack in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a codex`. Or copy the skill folder (.claude/skills/re-mobile-pack in dslsdzc/rev-skills) into .agents/skills/re-mobile-pack in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-mobile-pack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-mobile-pack, .gemini/skills/re-mobile-pack, .github/skills/re-mobile-pack and .opencode/skills/re-mobile-pack in your project.
Going by SKILL.md and its folder, Re Mobile Pack needs the command-line tools its instructions call (adb, pip and java). Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Mobile Pack is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Re Mobile Pack: Testing Mobile Ipc (trilwu/secskills, 156 stars), Performing Dynamic Analysis Of Android App (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Mobile Security (transilienceai/communitytools, 562 stars) and Mobile App Security Testing (langbyyi/CyberStrikeAI-SRC, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.