Mira Risk Collect
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
$ npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install index-login/MobileRE-Skill frida-mobile-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kilo/skill/frida-mobile-security .claude/skills/frida-mobile-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "frida-mobile-security" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/frida-mobile-security into .claude/skills/frida-mobile-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frida-mobile-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/frida-mobile-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install index-login/MobileRE-Skill frida-mobile-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.kilo/skill/frida-mobile-security .agents/skills/frida-mobile-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "frida-mobile-security" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/frida-mobile-security into .agents/skills/frida-mobile-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frida-mobile-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install index-login/MobileRE-Skill frida-mobile-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.kilo/skill/frida-mobile-security .cursor/skills/frida-mobile-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "frida-mobile-security" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/frida-mobile-security into .cursor/skills/frida-mobile-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frida-mobile-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/index-login/MobileRE-Skill.git --path .kilo/skill/frida-mobile-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install index-login/MobileRE-Skill frida-mobile-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.kilo/skill/frida-mobile-security .gemini/skills/frida-mobile-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "frida-mobile-security" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/frida-mobile-security into .gemini/skills/frida-mobile-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frida-mobile-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install index-login/MobileRE-Skill frida-mobile-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/.kilo/skill/frida-mobile-security .github/skills/frida-mobile-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "frida-mobile-security" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/frida-mobile-security into .github/skills/frida-mobile-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frida-mobile-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install index-login/MobileRE-Skill frida-mobile-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.kilo/skill/frida-mobile-security .opencode/skills/frida-mobile-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "frida-mobile-security" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/frida-mobile-security into .opencode/skills/frida-mobile-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frida-mobile-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
frida-mobile-security用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
Frida Mobile Security is an agent skill from index-login/MobileRE-Skill. 用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF 侦察/快速反汇编/JNI/检查证书"等意图时使用。
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 42 other files, including scripts (for example `scripts/bypass/dlsym_tracer.js`, `scripts/bypass/exit_blocker.js` and `scripts/bypass/frida_feature_hider.js`).
It sits in Security, covering Mobile application security. It works with Frida, Model Context Protocol, Android and iOS. The repository describes itself as: AI Agent 驱动的移动端逆向技能集:Frida hook、一键脱壳、反检测绕过、内存 DEX dump、Ghidra MCP 符号/结构恢复。AI-agent skill system for mobile reverse engineering. The licence is MIT.
Read from SKILL.md and the folder at commit 69e7f5e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 15 files in scripts/ (JavaScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
adbpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Frida Mobile Security loads about 3k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 709 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from index-login/MobileRE-Skill at commit 69e7f5e, republished under its MIT licence (© index-login). 709 words, ~2,968 tokens.
.claude/skills/frida-mobile-security/SKILL.md (or your agent's skills folder). This skill also uses 37 other files; get the full folder from GitHub.模块优先,决策树驱动。 本文件是总控:任务路由 + 决策树导航 + 模块目录。各技巧域的详细打法在项目根 references/ 分域文件(全量索引 references/_index.md),按需读取。
路径基准:
references/*相对项目根;scripts/*相对本文件所在目录(.kilo/skill/frida-mobile-security/)。给用户的 frida CLI 命令必须写全路径(如-l .kilo/skill/frida-mobile-security/scripts/core/utils.js),或让用户先cd .kilo/skill/frida-mobile-security;tools/frida_run.py -l scripts/...短路径自动解析(实测:短路径直接跑 frida CLI 会Errno 2)。
硬性规则:scripts/core/utils.js 必须作为第一个 -l 参数加载。
# 从项目根执行:先 cd .kilo/skill/frida-mobile-security,或把 scripts/ 展开为 .kilo/skill/frida-mobile-security/scripts/
# 例:frida -U -f com.app -l .kilo/skill/frida-mobile-security/scripts/core/utils.js -l .kilo/skill/frida-mobile-security/scripts/monitors/crypto_monitor.js
# 加解密自吐
frida -U -f com.app -l scripts/core/utils.js -l scripts/monitors/crypto_monitor.js
# 行为摸底
frida -U -f com.app -l scripts/core/utils.js -l scripts/monitors/file_monitor.js -l scripts/monitors/network_monitor.js -l scripts/monitors/thread_monitor.js
# 反检测 Phase 1 (保活 + 定位检测 so)
frida -U -f com.app -l scripts/core/utils.js -l scripts/bypass/exit_blocker.js -l scripts/bypass/so_loader_tracer.js
# HTTP 明文拦截
frida -U -f com.app -l scripts/core/utils.js -l scripts/monitors/ssl_plaintext.js
# Native 函数发现
frida -U -f com.app -l scripts/core/utils.js -l scripts/monitors/native_hooker.js
# 跨组件 Intent 污点追踪
frida -U -f com.app -l scripts/core/utils.js -l scripts/monitors/intent_tracker.js
# 内存敏感数据扫描 + 密码输入监听
frida -U -f com.app -l scripts/core/utils.js -l scripts/monitors/memory_scanner.js通道说明:
-U是 USB 直连;走端口转发时换成-H 127.0.0.1:8888(先adb forward tcp:8888 tcp:8888)。 Agent 无人值守运行用tools/frida_run.py(非交互:加载 → 观察 N 秒 → 存活报告 → detach);也可直接用原生frida -F -q -t N -o log(静默、定时退出、落盘)。frida CLI 是 REPL,stdin EOF 会自动退出,不能直接在后台跑。Windows 控制台打印非 UTF-8 payload 会崩输出线程:优先-o落盘或设PYTHONIOENCODING=utf-8。 设备操控用tools/device_ui.py:元素树elements、按文本/ID 点击tap --text/--id(现 dump 现定位,无 ref 失效问题)、等待wait-for、常亮stayon、清空clear。
运行时配置通过 -e 'var CONFIG_OVERRIDE={...}' 注入,见 §五。
adb devices -l # 1. 设备在线
adb shell su -c "ps -A | grep -i frida" # 2. server 是否在跑
adb forward tcp:8888 tcp:8888; frida-ps -H 127.0.0.1:8888 # 3. 通道验证(有进程列表即通)启动 frida-server 用 nohup ... &(-D 会挂住 adb shell 不返回,容易误判未启动)。server 版本需与本地 frida CLI 一致:
adb shell "su -c 'nohup <设备上 frida-server 路径> -l 127.0.0.1:8888 > /dev/null 2>&1 &'"匹配用户意图 → 加载对应 references 分域 → 按决策树执行。不要逐章浏览。
| 意图关键词 | 手法域名 | 加载 |
|---|---|---|
| "绕过检测" "过掉反调试" "挂上就闪退" "防注入" "加固壳" "SVC" "TracerPid" "GDB" | 环境对抗 | references/anti-detection.md |
| "脱壳" "加固解密" "提取 dex" "so 提取" | 脱壳 | references/unpacking.md(先分诊:无壳直接解包;有壳先 root 内存 dump;需回填再上 tools/unpack.py) |
| "加密明文" "算法" "密钥" "AES" "hook 方法" "修改参数" "伪造返回值" "SSL 证书" "TrustManager" "onReceivedSslError" | 加密/功能 hook | references/crypto-hook.md |
| "看网络请求" "抓包" "还原协议" "行为摸底" "全程监控" "污点追踪" "内存扫描" "Intent" "Serializable" "文件落地" "内核视角" "谁写的" | 行为分析 | references/behavior-analysis.md |
| "分析这个类" "攻击面" "序列化" "WebView" "深链" "Provider" "反序列化" | 静态分析 | references/static-analysis.md |
| "分析这个 so" "native 函数" "so 里的加密" "字符串引用" "交叉引用" "逆向 so" "找不到导出" | SO 层分析 | references/native-analysis.md |
| "模块无输出" "闪退" "ANR" "hook 不生效" "报错" | 故障诊断 | references/troubleshooting.md |
| "写自定义 hook" "API 用法" "Stalker" "RegisterNatives" "内存搜索" | API 参考 | references/api-reference.md |
用户是否已能稳定挂载 Frida?
├─ [否] "挂上就闪退" → 加载 anti-detection.md
├─ [是] 已用 hluda/魔改 frida/已跑过 exit_blocker → 跳过反检测,直接匹配任务
└─ [不确定] → 快速探路:utils + exit_blocker + so_loader_tracer
├─ exit_blocker 有 BLOCKED → 存在检测但已被保活 → 可继续
└─ exit_blocker 无日志且进程正常 → 无检测 → 可继续每种技巧在对应 references 有完整决策树,此处只给入口:
| 技巧域 | 入口决策树 | 详细 |
|---|---|---|
| 加密算法 | Step 1 crypto_monitor → Step 2 native_hooker → Step 3 network_monitor | crypto-hook.md |
| 网络协议 | Step 1 network_monitor → 明文/密文分流 | behavior-analysis.md |
| 行为摸底 | file + network + thread 三模块画像 → 按信号追加 | behavior-analysis.md |
| 反检测 | Phase 1 保活 → 分支 A/B → Phase 2-6 | anti-detection.md |
| 跨组件污点 | intent_tracker → 三链路对齐 | behavior-analysis.md |
| 内存敏感数据 | memory_scanner 自动扫描 + 交互式搜索 | crypto-hook.md |
| SO 层分析 | 分层下钻:Java → JNI → .so → libc → syscall → svc | native-analysis.md |
| 静态攻击面 | 攻击面枚举 → 逐类审查 → 序列化链路 | static-analysis.md |
scripts/ 下全部模块,按用途分类。utils.js 始终首个加载。
| 模块 | 用途 |
|---|---|
utils.js | 公共工具(日志格式化/hexdump/backtrace),必须首个加载 |
| 模块 | 用途 | 归属 |
|---|---|---|
crypto_monitor.js | Java 层加解密自吐(算法/密钥/IV/明文) | crypto-hook |
native_crypto_monitor.js | OpenSSL/BoringSSL 加密监控 | crypto-hook |
native_hooker.js | 任意 native 函数 hook(加密/发送/校验) | native-analysis |
jni_bridge_monitor.js | 方法索引桥加固分析(梆梆/360 VMP/Dex2C 特征) | native-analysis |
ssl_plaintext.js | OkHttp/Retrofit HTTP 明文 | crypto-hook |
memory_scanner.js | 内存敏感数据扫描 + 密码输入监听 | crypto-hook |
file_monitor.js | 文件读写监控 | behavior-analysis |
network_monitor.js | 网络连接/收发监控 | behavior-analysis |
thread_monitor.js | 线程创建监控 | behavior-analysis |
dl_monitor.js | SO 加载/卸载监控 | native-analysis |
proc_monitor.js | 子进程/命令执行监控 | behavior-analysis |
mem_trace.js | 设备侧内存访问追踪(MemoryAccessMonitor;输出 trace_recon 同格式日志;默认单次触发,rearm 可选) | native-analysis |
syscall_tracer.js | syscall 层追踪 | native-analysis |
svc_tracer.js | SVC #0 指令追踪(Stalker) | native-analysis |
intent_tracker.js | 跨组件 Intent 污点追踪 | behavior-analysis |
| 模块 | 用途 | 归属 |
|---|---|---|
exit_blocker.js | 拦截 exit_group/_exit/abort/kill/tgkill 保活 | anti-detection |
thread_blocker.js | 阻断检测线程 pthread_create | anti-detection |
init_hook.js | call_constructors 抢时机(init_array 检测) | anti-detection |
frida_feature_hider.js | 隐藏 Frida 特征(/proc/线程/内存) | anti-detection |
function_patcher.js | 已知偏移 NOP patch | anti-detection |
shellcode_detector.js | 定位 mmap+PROT_EXEC shellcode | anti-detection |
dlsym_tracer.js | 追踪运行时符号解析 | anti-detection |
so_loader_tracer.js | 记录 do_dlopen 路径+基址 | anti-detection |
root_bypass.js | Root 检测绕过(File.exists/系统属性) | anti-detection |
| 工具 | 用途 | 归属 |
|---|---|---|
so_dump.js | 内存 dump SO(脱壳提取) | unpacking |
dex_cache_dump.js | DexCache 精确 dump(免疫假 DEX/抹 magic) | unpacking |
dex_finder.js | 内存搜索 + 指纹校验 + 去重(备选:frida-dexdump 不可用时直接用) | unpacking |
dex_defineclass_dump.js | DefineClass 被动拦截 dump | unpacking |
codeitem_dump.js | 二代壳提取:主动 loadClass 触发回填 + 整 DEX dump | unpacking |
scan_register_natives.js | 定位 native 方法实现(Dex2C 按需分析) | native-analysis |
按 python3 tools/<工具> ... 直接跑(工作目录 = 项目根)。检测项(注入/调试/Janus)见 §六。
| 工具 | 用途 | 归属 |
|---|---|---|
unpack.py | 脱壳升级项(Frida 回填:loadClass+补充+自动pull+fix-checksum+去重+方法体标记);仅在 root 内存 dump 拿不到完整方法体时用 | unpacking |
dex_rebuilder.py | ① --fix-checksum 重算 checksum(默认操作)② CodeItem 离线重组回填 | unpacking |
dex_dedupe.py | 产物去重/校验 | unpacking |
fix_elf.py | 修复 ELF header | unpacking |
fix_axml.py | 修复爱加密魔改 AXML(Manifest 多 4 字节填充+headerSize 谎报 0x000C,jadx/apktool 无法解析时用) | static-analysis |
patch_gadget_threadnames.py | patch gadget 线程名 | native-analysis |
frida_run.py | 非交互 Frida 运行器(spawn/attach → 加载 → 观察 N 秒 → 存活报告 → detach;-l 支持 skill 内相对路径;-e @cfg.js 注入 CONFIG_OVERRIDE) | native-analysis |
device_ui.py | 设备交互(text/tap/swipe/key/shot/logs/launch/clear/foreground/size) | behavior-analysis |
emu_run.py / uniharness.py | 离线仿真(rev-unicorn-debug):单函数模拟 / JNI·libc 打桩基座;emu_run 内置观测层(--watch-code/--watch-regs/--watch-buf/--watch-read/--watch-write/--scan,超限自动聚合)与 JNI/桩日志(--log-jni/--trace-stubs/--stub/--dump-jni-out) | native-analysis |
trace_recon.py | 仿真 trace 状态重建:观测日志 → 缓冲状态序列(COPY/PASS 自动分段) | native-analysis |
fsmon_run.py | 设备侧内核文件事件采集与分析(capture/diff/compare/summary;流式、读风暴自动降噪、写活动视图、敏感路径检测画像、落盘件 pull+分类)。不注入/跨进程/无内容(内容走 Frida);Frida 上不去时的兜底观察。需 root;设备侧 fsmon 二进制缺件自装(nowsecure/fsmon Release) | behavior-analysis |
cipher_lab.py | 密码结构判定器:layers 层写法双轨迹判定 / table 白盒表反推 / schedule 编排归因(出主密钥) | native-analysis |
| 文件 | 用途 |
|---|---|
templates/analysis.py | Python 工作流模板(推荐,自动处理模块加载顺序) |
templates/custom_hook.js | 自定义 hook 模板 |
checklist/webview_ssl_check.js | WebView SSL 检测清单 |
checklist/fridainject.js | frida 环境检测项:注入后弹窗不出现/进程被杀 = 存在检测(验证注入是否成功) |
当上层 hook 失效时,按此递推下钻(完整方法见 native-analysis.md):
Java/ObjC → JNI/Runtime → Native .so → libc → syscall → SVC #0常见下钻:crypto_monitor 无输出→native_hooker;file_monitor 无输出→syscall_tracer;network_monitor 无 connect→检查 recvfrom;dl_monitor 无输出→syscall_tracer(mmap+PROT_EXEC)。
所有模块接受 CONFIG_OVERRIDE,通过 -e 或 Python dict 注入:
var CONFIG_OVERRIDE = {
file_monitor: { filterPath: ["/data/data/com.target/"] },
network_monitor: { showPayload: true },
crypto_monitor: { showStack: true },
native_hooker: { targetLibs: ["libencrypt.so"] },
ssl_plaintext: { urlFilter: ["api.example.com"] },
exit_blocker: { showBacktrace: false },
init_hook: { onModuleInit: [{ moduleName: "libDetect.so" }], probeCallers: true, autoHideFrida: true },
thread_blocker: { blockCallers: ["libmsaoaidsec.so"] },
frida_feature_hider: { indirectHook: true },
};各模块特有配置见对应 references 文件。
项目根 tools/ 下 bat 脚本,Agent 不能代跑,输出命令让用户自行执行(方便截图取证)。Python 工具可直接跑(python3 tools/janus_check.py ...、py -3 tools/debug-gdb.py ...,本机 python 可能是 Python 2)。
| 工具 | 检测目标 | 用法 |
|---|---|---|
check-anti-inject.bat | 防注入(ptrace + /proc/pid/mem) | tools/check-anti-inject.bat <包名> |
debug-gdb.py | 防调试(ptrace / TracerPid) | py -3 tools/debug-gdb.py <包名> |
check-janus.bat | APK 元数据提取(GetAPKInfo.jar) | tools/check-janus.bat <apk路径> |
janus_check.py | Janus 备选检测:apksigner V1/V2/V3 签名验证(不解析 Manifest,免疫加固魔改) | python3 tools/janus_check.py <apk路径> |
首次分析新 App:check-janus → debug-gdb → check-anti-inject → Frida Phase 1。所有工具前置条件:root + SELinux Permissive。注意 debug-gdb.py 附加成功后目标若被反调试杀死,属于检测到反调试(正结论),非工具失败。
GetAPKInfo.jar 解析失败(爱加密等魔改 Manifest,报 0x000c0003)时,直接用 janus_check.py——经 apksigner 验证签名方案(V1+V2 通过 = Janus 安全),效果与 GetAPKInfo.jar 一致。
冒烟自检(可选,验证整套链路):L2/L3 回归与离线复算的预期结果见 references/smoke-test.md。
需要用户在 app 上手动操作时(点击按钮/切换页面触发行为):
配置 analysis.py(TIMEOUT=0 手动停止、LOG_TO_FILE=True 日志落盘)
→ 运行 → 用户操作 app → 停止 → 读日志 → 改 CUSTOM_HOOK_SCRIPT → 再运行日志分析:读 .txt 日志,按时间戳锚定用户操作窗口,关联多模块信号。详见 references/behavior-analysis.md 交叉分析。
references/_index.md)| 场景 | 读取 |
|---|---|
| 反检测 Pipeline / 经验模式 / 检测工具 | references/anti-detection.md |
| 脱壳流程 / 壳识别 / 提取修复 | references/unpacking.md |
| 加密决策树 / SSL/TLS / Hook 模板 / Python 工作流 | references/crypto-hook.md |
| 行为摸底 / 网络协议 / 污点追踪 / 交叉分析 | references/behavior-analysis.md |
| 攻击面枚举 / 序列化 / WebView / jadx-mcp | references/static-analysis.md |
| SO 层分析 / Ghidra / unidbg / 分层下钻 / 字符串引用 | references/native-analysis.md |
| 故障排查(无输出/闪退/init_hook 陷阱) | references/troubleshooting.md |
| Frida API 手册(写自定义 hook 时) | references/api-reference.md |
| 参考文章索引(脱壳原理/攻击面方法论) | references/articles.md |
© index-login, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 37 other files (scripts) in .kilo/skill/frida-mobile-security of index-login/MobileRE-Skill.
Open the folder on GitHubat commit 69e7f5e
Frida Mobile Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Frida Mobile Security this skillindex-login/MobileRE-Skill | 152 | — | ~3k | Automated safety check: Pass | MIT | |
| Mira Risk Collectvw2x/Mira | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | |
| R0crawl Skillsmanyuegong33/r0crawl_skills | 312 | — | ~1.2k | Automated safety check: Pass | None | |
| Mobile Reversesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Offensive MobileSnailSploit/Claude-Red | 7.4k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Mobile Securitytransilienceai/communitytools | 563 | — | ~2.5k | Automated safety check: Pass | MIT |
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
manyuegong33/r0crawl_skills
面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。
sickn33/agentic-awesome-skills
Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
transilienceai/communitytools
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…
dslsdzc/rev-skills
Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.
index-login/MobileRE-Skill
Debug and emulate specific code fragments or functions using the Unicorn engine.
index-login/MobileRE-Skill
Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.
index-login/MobileRE-Skill
减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。
Works with
Categories
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…. Frida Mobile Security is an agent skill from index-login/MobileRE-Skill.
Frida Mobile Security fits situations like: tasks that involve Mobile application security.
Run `npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a claude-code`. Or copy the skill folder (.kilo/skill/frida-mobile-security in index-login/MobileRE-Skill) into .claude/skills/frida-mobile-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a codex`. Or copy the skill folder (.kilo/skill/frida-mobile-security in index-login/MobileRE-Skill) into .agents/skills/frida-mobile-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add index-login/MobileRE-Skill --skill frida-mobile-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/frida-mobile-security, .gemini/skills/frida-mobile-security, .github/skills/frida-mobile-security and .opencode/skills/frida-mobile-security in your project.
Going by SKILL.md and its folder, Frida Mobile Security needs JavaScript for the scripts in its folder and the command-line tools its instructions call (adb and python3). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Frida Mobile Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Frida Mobile Security: Mira Risk Collect (vw2x/Mira, 105 stars), R0crawl Skills (manyuegong33/r0crawl_skills, 312 stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars) and Offensive Mobile (SnailSploit/Claude-Red, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
index-login (a GitHub user) maintains it in index-login/MobileRE-Skill, which has 152 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 30, 2026.
Source: index-login/MobileRE-Skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.