Mira Risk Collect
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.
$ npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install index-login/MobileRE-Skill rev-dex-dumper --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kilo/skill/rev-dex-dumper .claude/skills/rev-dex-dumper && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "rev-dex-dumper" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-dex-dumper into .claude/skills/rev-dex-dumper/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-dex-dumper", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-dex-dumperType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install index-login/MobileRE-Skill rev-dex-dumper --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.kilo/skill/rev-dex-dumper .agents/skills/rev-dex-dumper && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "rev-dex-dumper" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-dex-dumper into .agents/skills/rev-dex-dumper/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-dex-dumper", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install index-login/MobileRE-Skill rev-dex-dumper --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.kilo/skill/rev-dex-dumper .cursor/skills/rev-dex-dumper && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "rev-dex-dumper" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-dex-dumper into .cursor/skills/rev-dex-dumper/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-dex-dumper", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/index-login/MobileRE-Skill.git --path .kilo/skill/rev-dex-dumper--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install index-login/MobileRE-Skill rev-dex-dumper --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.kilo/skill/rev-dex-dumper .gemini/skills/rev-dex-dumper && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "rev-dex-dumper" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-dex-dumper into .gemini/skills/rev-dex-dumper/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-dex-dumper", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install index-login/MobileRE-Skill rev-dex-dumperInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/.kilo/skill/rev-dex-dumper .github/skills/rev-dex-dumper && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "rev-dex-dumper" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-dex-dumper into .github/skills/rev-dex-dumper/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-dex-dumper", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install index-login/MobileRE-Skill rev-dex-dumper --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.kilo/skill/rev-dex-dumper .opencode/skills/rev-dex-dumper && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "rev-dex-dumper" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-dex-dumper into .opencode/skills/rev-dex-dumper/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-dex-dumper", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
rev-dex-dumperRoot memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.
Rev Dex Dumper is an agent skill from index-login/MobileRE-Skill. Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. Activate to unpack an APK, extract decrypted DEX, or defeat class-loading packing; for extraction shells or Frida-based dumping see frida-mobile-security.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files.
It sits in Security, covering Mobile application security. It works with Frida, Android and Model Context Protocol. The repository describes itself as: AI Agent 驱动的移动端逆向技能集:Frida hook、一键脱壳、反检测绕过、内存 DEX dump、Ghidra MCP 符号/结构恢复。AI-agent skill system for mobile reverse engineering. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8a7de21. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
adbFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Rev Dex Dumper loads about 1.9k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 868 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from index-login/MobileRE-Skill at commit 8a7de21, republished under its MIT licence (© index-login). 868 words, ~1,934 tokens.
.claude/skills/rev-dex-dumper/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Dump DEX files from a running Android application's memory via ADB. Two bundled tools (arm64):
| Tool | Access path | Freezes target | Role |
|---|---|---|---|
panda-dex-dumper | /proc/<pid>/mem | SIGSTOP / SIGCONT | primary |
mem-dex-dumper | /proc/<pid>/mem or process_vm_readv(2) | none | alternative / cross-check |
Neither tool uses ptrace. They read process memory directly (/proc/<pid>/mem; mem-dex-dumper can also use process_vm_readv(2)) and still work against a process that has claimed the ptrace slot via PTRACE_TRACEME (TracerPid != 0): anti-debug that polices TracerPid or blocks PTRACE_ATTACH does not stop them, while a genuinely ptrace-based dumper would be blocked.
The binaries are bundled in this skill's directory. Resolve absolute paths relative to this SKILL.md file:
skills/rev-dex-dumper/panda-dex-dumper
skills/rev-dex-dumper/mem-dex-dumper
skills/rev-dex-dumper/mem-dex-dumper.c (source)adb push <path-to>/panda-dex-dumper /data/local/tmp/
adb shell chmod +x /data/local/tmp/panda-dex-dumperIf the user provides a package name, use it directly. Otherwise, get the foreground app:
adb shell dumpsys activity top | grep 'ACTIVITY' | tail -1 | awk '{print $2}' | cut -d/ -f1adb shell "cd /data/local/tmp && ./panda-dex-dumper -p $(adb shell pidof <package_name>)"The dumped DEX files are saved to /data/local/tmp/panda/ on the device.
adb pull /data/local/tmp/panda/ ./Pull to the user's current working directory.
adb shell rm -rf /data/local/tmp/panda/
adb shell rm /data/local/tmp/panda-dex-dumperadb push <path-to>/mem-dex-dumper /data/local/tmp/
adb shell chmod +x /data/local/tmp/mem-dex-dumper
adb shell "su -c 'cd /data/local/tmp && ./mem-dex-dumper -p <pid> -o /data/local/tmp/memdump'"
adb pull /data/local/tmp/memdump/ ./
adb shell "su -c 'rm -rf /data/local/tmp/memdump/ /data/local/tmp/mem-dex-dumper'"Options: -p <pid> (required), -o <outdir> (default /data/local/tmp/memdump), -b mem|vmreadv (default mem = /proc/<pid>/mem; vmreadv = process_vm_readv(2)). Use it to cross-check a panda dump, for extra coverage, or when the target must not be frozen.
Source: mem-dex-dumper.c in this directory. Rebuild with the NDK (r21+):
aarch64-linux-android29-clang -O2 -static -o mem-dex-dumper mem-dex-dumper.c
llvm-strip mem-dex-dumpermem-dex-dumper is a tool we developed in-house — source (mem-dex-dumper.c) and rebuild steps ship with the skill. When it misbehaves, fix the source and rebuild (see Debugging / fixing below).panda-dex-dumper is a third-party binary without source, so it can only be worked around, not fixed./proc/<pid>/maps; iterate readable regions ≥ 0x70 bytes.dex\n magic straddling a chunk boundary is still seen.dex\n + 3 digits + NUL (any DEX version).try_dump() validates the header before dumping: header_size == 0x70, endian_tag ∈ {0x12345678, 0x78563412}, 0x70 ≤ file_size ≤ 1 GiB, string_ids/class_defs tables inside file_size.file_size bytes in 1 MiB chunks; on a failed read keep the partial data (dumped < file_size in the log).Per-hit log: find dex off: 0x<addr> file_size: 0x<n> dumped: 0x<n>; final line scanned <N> bytes, done. — the primary diagnostic surface.
| Symptom | Cause | Action |
|---|---|---|
open /proc/<pid>/mem: Permission denied | not root / SELinux / kernel restriction | run via su -c; if still denied, try -b vmreadv |
-b vmreadv fails (EPERM/EINVAL) | kernel/SELinux blocks process_vm_readv for the target | use the default backend; syscall presence: grep process_vm_readv /proc/kallsyms |
| No hits although the app is packed | payload not decrypted yet, or header intentionally scrambled | keep the app foregrounded past splash; cross-check with panda |
| Fewer files than panda | (a) strict validation rejects corrupted headers that panda dumps as guess_size fragments; (b) range-dedupe swallows a DEX nested inside a bigger claimed range | compare logs; for (b) bypass in_dumped() temporarily, or extract the inner address manually (dd from /proc/<pid>/mem) |
| Very large file (tens of MB) | .vdex-embedded header with inflated file_size | noise — the payload lives in anon heap ([anon:libc_malloc]); verify structure first |
| Some classes fail to parse | torn live read (packer wrote memory while scanning) | re-run; if reproducible, prefer panda (SIGSTOP gives a frozen snapshot) |
| Won't exec on another device | arm64-only, static, API 29 | rebuild for the target ABI (above) |
Not bugs: extra/missing hits vs panda in mapped system-jar territory (/system/framework/*.jar, /apex/*/javalib/*.jar, *.vdex) — different scan heuristics, treat as noise. pidof returning several PIDs: dump each process separately, the payload may live in any of them.
scanned N bytes. Name each hit's mapping with grep <addr-prefix> /proc/<pid>/maps (file-backed = usually system noise; anon heap = payload).try_dump() checks (start with header_size), or confirm the region is readable (dd from /proc/<pid>/mem).su) is a good repro target — dump it with both backends, compare md5 with the source file.adb devices and confirm a device is listed before proceeding.adb root fails; run via su -c.pidof returns empty, the app may not be running. Launch it first with adb shell monkey -p <package_name> -c android.intent.category.LAUNCHER 1./data/local/tmp/panda/ should be pulled.© index-login, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files in .kilo/skill/rev-dex-dumper of index-login/MobileRE-Skill.
Open the folder on GitHubat commit 8a7de21
Rev Dex Dumper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Rev Dex Dumper this skillindex-login/MobileRE-Skill | 158 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Mira Risk Collectvw2x/Mira | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | |
| R0crawl Skillsmanyuegong33/r0crawl_skills | 312 | — | ~1.2k | Automated safety check: Pass | None | |
| Mobile Reversesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Offensive MobileSnailSploit/Claude-Red | 7.4k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Performing Dynamic Analysis Of Android Appmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 |
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
manyuegong33/r0crawl_skills
面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。
sickn33/agentic-awesome-skills
Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
mukul975/Anthropic-Cybersecurity-Skills
Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…
transilienceai/communitytools
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
index-login/MobileRE-Skill
Debug and emulate specific code fragments or functions using the Unicorn engine.
index-login/MobileRE-Skill
减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。
Works with
Categories
Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. Rev Dex Dumper is an agent skill from index-login/MobileRE-Skill. Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.
Rev Dex Dumper fits situations like: tasks that involve Mobile application security.
Run `npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a claude-code`. Or copy the skill folder (.kilo/skill/rev-dex-dumper in index-login/MobileRE-Skill) into .claude/skills/rev-dex-dumper in your project. Claude Code loads it when a task matches its description.
Run `npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a codex`. Or copy the skill folder (.kilo/skill/rev-dex-dumper in index-login/MobileRE-Skill) into .agents/skills/rev-dex-dumper in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add index-login/MobileRE-Skill --skill rev-dex-dumper -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rev-dex-dumper, .gemini/skills/rev-dex-dumper, .github/skills/rev-dex-dumper and .opencode/skills/rev-dex-dumper in your project.
Going by SKILL.md and its folder, Rev Dex Dumper needs the command-line tools its instructions call (adb).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Rev Dex Dumper is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Rev Dex Dumper: Mira Risk Collect (vw2x/Mira, 105 stars), R0crawl Skills (manyuegong33/r0crawl_skills, 312 stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars) and Offensive Mobile (SnailSploit/Claude-Red, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
index-login (a GitHub user) maintains it in index-login/MobileRE-Skill, which has 158 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.
Source: index-login/MobileRE-Skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.