Agent skill

Rev Dex Dumper

by index-login in index-login/MobileRE-Skill

Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

MITAuto-check passedSecurity

Install Rev Dex Dumper

skills CLI
$ npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install index-login/MobileRE-Skill rev-dex-dumper --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kilo/skill/rev-dex-dumper .claude/skills/rev-dex-dumper && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rev-dex-dumper
GitHub stars
158
Token cost
~1.9k tokens
SKILL.md length
868 words
Files
4
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

  • Works in 5 steps: Push the tool to device → Determine target package name → Run the dumper → …
  • Tasks that involve Mobile application security
  • SKILL.md covers Tool Location, Workflow, mem-dex-dumper (alternative /… and Guidelines
  • Calls adb

What it does

Rev Dex Dumper is an agent skill from index-login/MobileRE-Skill. Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. Activate to unpack an APK, extract decrypted DEX, or defeat class-loading packing; for extraction shells or Frida-based dumping see frida-mobile-security.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files.

It sits in Security, covering Mobile application security. It works with Frida, Android and Model Context Protocol. The repository describes itself as: AI Agent 驱动的移动端逆向技能集:Frida hook、一键脱壳、反检测绕过、内存 DEX dump、Ghidra MCP 符号/结构恢复。AI-agent skill system for mobile reverse engineering. The licence is MIT.

When your agent uses it

  • Tasks that involve Mobile application security

Example prompts

  • “/rev-dex-dumper”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Push the tool to device
  2. Determine target package name
  3. Run the dumper
  4. Pull DEX files to host
  5. Clean up device cache

What it can do on your machine

Read from SKILL.md and the folder at commit 8a7de21. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rev Dex Dumper loads about 1.9k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 868 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from index-login/MobileRE-Skill at commit 8a7de21, republished under its MIT licence (© index-login). 868 words, ~1,934 tokens.

Download SKILL.mdSave it as .claude/skills/rev-dex-dumper/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
rev-dex-dumper
description
Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. Activate to unpack an APK, extract decrypted DEX, or defeat class-loading packing; for extraction shells or Frida-based dumping see frida-mobile-security.

rev-dex-dumper - Android DEX Dumper

Dump DEX files from a running Android application's memory via ADB. Two bundled tools (arm64):

ToolAccess pathFreezes targetRole
panda-dex-dumper/proc/<pid>/memSIGSTOP / SIGCONTprimary
mem-dex-dumper/proc/<pid>/mem or process_vm_readv(2)nonealternative / cross-check

Neither tool uses ptrace. They read process memory directly (/proc/<pid>/mem; mem-dex-dumper can also use process_vm_readv(2)) and still work against a process that has claimed the ptrace slot via PTRACE_TRACEME (TracerPid != 0): anti-debug that polices TracerPid or blocks PTRACE_ATTACH does not stop them, while a genuinely ptrace-based dumper would be blocked.


Tool Location

The binaries are bundled in this skill's directory. Resolve absolute paths relative to this SKILL.md file:

skills/rev-dex-dumper/panda-dex-dumper
skills/rev-dex-dumper/mem-dex-dumper
skills/rev-dex-dumper/mem-dex-dumper.c    (source)

Workflow

1. Push the tool to device
bash
adb push <path-to>/panda-dex-dumper /data/local/tmp/
adb shell chmod +x /data/local/tmp/panda-dex-dumper
2. Determine target package name

If the user provides a package name, use it directly. Otherwise, get the foreground app:

bash
adb shell dumpsys activity top | grep 'ACTIVITY' | tail -1 | awk '{print $2}' | cut -d/ -f1
3. Run the dumper
bash
adb shell "cd /data/local/tmp && ./panda-dex-dumper -p $(adb shell pidof <package_name>)"

The dumped DEX files are saved to /data/local/tmp/panda/ on the device.

4. Pull DEX files to host
bash
adb pull /data/local/tmp/panda/ ./

Pull to the user's current working directory.

5. Clean up device cache
bash
adb shell rm -rf /data/local/tmp/panda/
adb shell rm /data/local/tmp/panda-dex-dumper

mem-dex-dumper (alternative / cross-check)

bash
adb push <path-to>/mem-dex-dumper /data/local/tmp/
adb shell chmod +x /data/local/tmp/mem-dex-dumper
adb shell "su -c 'cd /data/local/tmp && ./mem-dex-dumper -p <pid> -o /data/local/tmp/memdump'"
adb pull /data/local/tmp/memdump/ ./
adb shell "su -c 'rm -rf /data/local/tmp/memdump/ /data/local/tmp/mem-dex-dumper'"

Options: -p <pid> (required), -o <outdir> (default /data/local/tmp/memdump), -b mem|vmreadv (default mem = /proc/<pid>/mem; vmreadv = process_vm_readv(2)). Use it to cross-check a panda dump, for extra coverage, or when the target must not be frozen.

Source: mem-dex-dumper.c in this directory. Rebuild with the NDK (r21+):

bash
aarch64-linux-android29-clang -O2 -static -o mem-dex-dumper mem-dex-dumper.c
llvm-strip mem-dex-dumper
Background
  • mem-dex-dumper is a tool we developed in-house — source (mem-dex-dumper.c) and rebuild steps ship with the skill. When it misbehaves, fix the source and rebuild (see Debugging / fixing below).
  • panda-dex-dumper is a third-party binary without source, so it can only be worked around, not fixed.
  • The two tools cross-check each other: for the same address, output is byte-identical whenever both choose the same size.
How it works
  1. Parse /proc/<pid>/maps; iterate readable regions ≥ 0x70 bytes.
  2. Read in 1 MiB chunks with a 7-byte overlap, so a dex\n magic straddling a chunk boundary is still seen.
  3. Scan for dex\n + 3 digits + NUL (any DEX version).
  4. try_dump() validates the header before dumping: header_size == 0x70, endian_tag ∈ {0x12345678, 0x78563412}, 0x70 ≤ file_size ≤ 1 GiB, string_ids/class_defs tables inside file_size.
  5. Dedupe: hits inside an already-dumped range are skipped (also suppresses re-hits from chunk overlap).
  6. Dump file_size bytes in 1 MiB chunks; on a failed read keep the partial data (dumped < file_size in the log).

Per-hit log: find dex off: 0x<addr> file_size: 0x<n> dumped: 0x<n>; final line scanned <N> bytes, done. — the primary diagnostic surface.

Known issues
SymptomCauseAction
open /proc/<pid>/mem: Permission deniednot root / SELinux / kernel restrictionrun via su -c; if still denied, try -b vmreadv
-b vmreadv fails (EPERM/EINVAL)kernel/SELinux blocks process_vm_readv for the targetuse the default backend; syscall presence: grep process_vm_readv /proc/kallsyms
No hits although the app is packedpayload not decrypted yet, or header intentionally scrambledkeep the app foregrounded past splash; cross-check with panda
Fewer files than panda(a) strict validation rejects corrupted headers that panda dumps as guess_size fragments; (b) range-dedupe swallows a DEX nested inside a bigger claimed rangecompare logs; for (b) bypass in_dumped() temporarily, or extract the inner address manually (dd from /proc/<pid>/mem)
Very large file (tens of MB).vdex-embedded header with inflated file_sizenoise — the payload lives in anon heap ([anon:libc_malloc]); verify structure first
Some classes fail to parsetorn live read (packer wrote memory while scanning)re-run; if reproducible, prefer panda (SIGSTOP gives a frozen snapshot)
Won't exec on another devicearm64-only, static, API 29rebuild for the target ABI (above)

Not bugs: extra/missing hits vs panda in mapped system-jar territory (/system/framework/*.jar, /apex/*/javalib/*.jar, *.vdex) — different scan heuristics, treat as noise. pidof returning several PIDs: dump each process separately, the payload may live in any of them.

Show full SKILL.md (270 more words)Show less
Debugging / fixing
  1. Read stdout first: per-hit lines + scanned N bytes. Name each hit's mapping with grep <addr-prefix> /proc/<pid>/maps (file-backed = usually system noise; anon heap = payload).
  2. Validate a suspicious dump structurally (header fields + class descriptors) before blaming the tool.
  3. Missing hits → loosen try_dump() checks (start with header_size), or confirm the region is readable (dd from /proc/<pid>/mem).
  4. Compare with panda on shared addresses — md5-equal means both extracted the same bytes.
  5. Sandbox: a tiny process that loads a known DEX into heap and sleeps (run via su) is a good repro target — dump it with both backends, compare md5 with the source file.
  6. After any change: rebuild + strip (above), re-run the sandbox test, keep the log format stable.

Guidelines

  1. Always verify ADB connection first — run adb devices and confirm a device is listed before proceeding.
  2. Root is required — both tools read another UID's process memory. On production builds adb root fails; run via su -c.
  3. Wait for app to fully load — if the user is dumping a packed app, the real DEX is only available after the packer's class loader has decrypted it. Advise the user to navigate past the splash screen before dumping.
  4. Handle pidof failure — if pidof returns empty, the app may not be running. Launch it first with adb shell monkey -p <package_name> -c android.intent.category.LAUNCHER 1.
  5. Multiple DEX files are normal — packed apps often produce several DEX files. All files in /data/local/tmp/panda/ should be pulled.
  6. Always clean up — remove both the dumped DEX files and the tool binary from the device after pulling results to avoid leaving artifacts.

© index-login, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in .kilo/skill/rev-dex-dumper of index-login/MobileRE-Skill.

  • SKILL.md
  • mem-dex-dumper
  • mem-dex-dumper.c
  • panda-dex-dumper

Open the folder on GitHubat commit 8a7de21

Compare with similar skills

Rev Dex Dumper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rev Dex Dumper compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rev Dex Dumper this skillindex-login/MobileRE-Skill158—~1.9kAutomated safety check: PassMIT
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
R0crawl Skillsmanyuegong33/r0crawl_skills312—~1.2kAutomated safety check: PassNone
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Offensive MobileSnailSploit/Claude-Red7.4k—~3.5kAutomated safety check: PassMIT
Performing Dynamic Analysis Of Android Appmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.0

Similar skills

  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    312 GitHub stars~1.2k tokensUpdated 21 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.4k GitHub stars~3.5k tokensUpdated 21 days ago
    SecurityAuto-check passed
  • Performing Dynamic Analysis Of Android App

    mukul975/Anthropic-Cybersecurity-Skills

    Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Mobile Security

    transilienceai/communitytools

    Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

    563 GitHub stars~2.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from index-login/MobileRE-Skill

  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    158 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Karpathy Guidelines

    index-login/MobileRE-Skill

    减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

    158 GitHub stars~242 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Rev Dex Dumper

What does Rev Dex Dumper do?

Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. Rev Dex Dumper is an agent skill from index-login/MobileRE-Skill. Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

When should I use Rev Dex Dumper?

Rev Dex Dumper fits situations like: tasks that involve Mobile application security.

How do I install Rev Dex Dumper in Claude Code?

Run `npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a claude-code`. Or copy the skill folder (.kilo/skill/rev-dex-dumper in index-login/MobileRE-Skill) into .claude/skills/rev-dex-dumper in your project. Claude Code loads it when a task matches its description.

How do I install Rev Dex Dumper in Codex?

Run `npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a codex`. Or copy the skill folder (.kilo/skill/rev-dex-dumper in index-login/MobileRE-Skill) into .agents/skills/rev-dex-dumper in your project. Codex loads it when a task matches its description.

Can I use Rev Dex Dumper in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rev-dex-dumper, .gemini/skills/rev-dex-dumper, .github/skills/rev-dex-dumper and .opencode/skills/rev-dex-dumper in your project.

What does Rev Dex Dumper need to run?

Going by SKILL.md and its folder, Rev Dex Dumper needs the command-line tools its instructions call (adb).

Does Rev Dex Dumper access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rev Dex Dumper safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rev Dex Dumper use?

Rev Dex Dumper is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rev Dex Dumper use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rev Dex Dumper?

Skills that share tags, products or a category with Rev Dex Dumper: Mira Risk Collect (vw2x/Mira, 105 stars), R0crawl Skills (manyuegong33/r0crawl_skills, 312 stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars) and Offensive Mobile (SnailSploit/Claude-Red, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rev Dex Dumper?

index-login (a GitHub user) maintains it in index-login/MobileRE-Skill, which has 158 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: index-login/MobileRE-Skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.