Agent skill

Rev Unicorn Debug

by index-login in index-login/MobileRE-Skill

Debug and emulate specific code fragments or functions using the Unicorn engine.

MITAuto-check passedSecurity

Install Rev Unicorn Debug

skills CLI
$ npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install index-login/MobileRE-Skill rev-unicorn-debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kilo/skill/rev-unicorn-debug .claude/skills/rev-unicorn-debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rev-unicorn-debug
GitHub stars
144
Token cost
~1.9k tokens
SKILL.md length
809 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Debug and emulate specific code fragments or functions using the Unicorn engine.

  • Works in 5 steps: Load file raw first — do NOT parse… → Identify context dependencies — analyze… → Use callbacks extensively — leverage… → …
  • Wants to emulate a function with Unicorn
  • SKILL.md covers Prerequisites, Harness kit…, CLI runner (tools/emu_run.py) and Core Principles, plus 4 more sections
  • Calls python3 and pip

What it does

Rev Unicorn Debug is an agent skill from index-login/MobileRE-Skill. Debug and emulate specific code fragments or functions using the Unicorn engine. Activate when the user wants to emulate a function with Unicorn, trace binary execution without running the full program, decrypt or decode data by emulating the algorithm, or bypass environment dependencies (JNI, syscalls, libc) during emulation.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security, Debugging and Reverse engineering and malware. It works with Model Context Protocol, Python and Frida. The repository describes itself as: AI Agent 驱动的移动端逆向技能集:Frida hook、一键脱壳、反检测绕过、内存 DEX dump、Ghidra MCP 符号/结构恢复。AI-agent skill system for mobile reverse engineering. The licence is MIT.

When your agent uses it

  • Wants to emulate a function with Unicorn
  • Trace binary execution without running the full program
  • Decode data by emulating the algorithm
  • Bypass environment dependencies (JNI

Example prompts

  • “/rev-unicorn-debug”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Load file raw first — do NOT parse ELF/PE/Mach-O headers. Read the file as raw bytes and map directly into Unicorn memory. We only need to…
  2. Identify context dependencies — analyze the target code for external calls (JNI, syscalls, libc, imports) and hook them to provide…
  3. Use callbacks extensively — leverage Unicorn's hook system for debugging, tracing, error recovery, and environment simulation.
  4. Iterative fix — when emulation crashes, use the callback info to diagnose and fix (map missing memory, hook unhandled calls, fix register…
  5. Minimal trace output — prefer block-level tracing over instruction-level. Only enable instruction trace on small targeted ranges. Use…

What it can do on your machine

Read from SKILL.md and the folder at commit 69e7f5e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rev Unicorn Debug loads about 1.9k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 809 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from index-login/MobileRE-Skill at commit 69e7f5e, republished under its MIT licence (© index-login). 809 words, ~1,931 tokens.

Download SKILL.mdSave it as .claude/skills/rev-unicorn-debug/SKILL.md (or your agent's skills folder).
name
rev-unicorn-debug
description
Debug and emulate specific code fragments or functions using the Unicorn engine. Activate when the user wants to emulate a function with Unicorn, trace binary execution without running the full program, decrypt or decode data by emulating the algorithm, or bypass environment dependencies (JNI, syscalls, libc) during emulation.

rev-unicorn-debug - Unicorn Emulation Debugger

Debug and emulate specific code fragments or functions using the Unicorn engine. Analyze context dependencies (JNI, syscalls, library functions) and simulate them through hook mechanisms to complete the user's debugging goal.

Source: P4nda0s/reverse-skills (MIT).

Prerequisites

bash
pip install unicorn

Unicorn is the CPU emulation engine (Python binding, Windows wheel available — no JDK or Android toolchain needed). It emulates instructions only: loading the .so, resolving relocations, and simulating libc/JNI/syscalls are done by the Python harness you write (see below).

Harness kit (tools/uniharness.py)

Import it instead of rewriting boilerplate:

python
from uniharness import Harness, asm, JNI_SLOTS

h = Harness(trace=False)                    # trace=True prints every instruction
h.map_raw("lib.so", 0, 0x10000)             # vaddr==file offset; else h.map_elf("lib.so")
h.setup_stack()
h.setup_tls()                               # TPIDR_EL0 + canary at TLS+40

env = h.jni_env(slots={JNI_SLOTS["NewByteArray"]: cb})   # fake JNIEnv: stub + hook per slot
r = h.call(0x196C, args=[env, 0])           # run until ret; r.x0, r.insns

Helpers: map / map_raw / map_elf / alloc / setup_stack / setup_tls / stub (accepts code= from asm()) / hook / jni_env / call / run / fault. Self-test: python3 uniharness.py.

Recon before writing a harness (raw-map check / deps / exports / relocs): tools/so.py info. Dependencies: see repo root requirements.txt (unicorn, capstone, keystone-engine, pyelftools).

CLI runner (tools/emu_run.py)

One-shot emulation without writing a harness:

bash
python3 tools/emu_run.py libfoo.so --sym Java_pkg_Cls_method --jni --args "env,0,'text'" --poke 0x1300c:1=1 --read 0x1000:32

Options: --off 0x.. (address instead of symbol), --imp (extra import stubs), --trace, --timeout, --raw, --setup hooks.py (full Harness access), --stub name=val (override an import stub's return, e.g. getpid=1234), --log-jni (log every JNI call: [jni] name(args) -> ret, string/array args decoded), --dump-jni-out FILE (append NewStringUTF / SetByteArrayRegion payloads), --trace-stubs (log every stub hit: [stub] name(args) -> ret; both logs aggregate beyond --watch-max).

Observability layer (white-box / VM / algorithm work): --watch-code PC --watch-regs x0,x1 --watch-buf "x19+0x61f0:16", --watch-read/--watch-write lo-hi (auto-aggregated beyond --watch-max), --scan hex[,hex] [--scan-at PC]. Pair with tools/trace_recon.py (event log -> buffer state sequence) and tools/cipher_lab.py (layer/table/schedule adjudication).


Core Principles

  1. Load file raw first — do NOT parse ELF/PE/Mach-O headers. Read the file as raw bytes and map directly into Unicorn memory. We only need to emulate specific functions, not the entire binary. If raw loading fails (code references segments at specific addresses), then parse minimally — only map the segments needed.
  2. Identify context dependencies — analyze the target code for external calls (JNI, syscalls, libc, imports) and hook them to provide simulated responses.
  3. Use callbacks extensively — leverage Unicorn's hook system for debugging, tracing, error recovery, and environment simulation.
  4. Iterative fix — when emulation crashes, use the callback info to diagnose and fix (map missing memory, hook unhandled calls, fix register state).
  5. Minimal trace output — prefer block-level tracing over instruction-level. Only enable instruction trace on small targeted ranges. Use counters and summaries instead of per-step logging.

Environment Simulation Strategy

Before emulating, read the target function and identify what it calls. Hook external dependencies by address and simulate in Python:

CategoryExamplesSimulation Strategy
libcmalloc, free, memcpy, strlen, printfHook address, implement logic in Python (bump allocator for malloc)
JNIGetStringUTFChars, FindClass, GetMethodIDBuild fake JNIEnv function table in UC memory, write RET stubs at each entry, hook stub addresses
Syscallsread, write, mmap, ioctlHook UC_HOOK_INTR, dispatch by syscall number
C++ runtimeoperator new, __cxa_throwHook and simulate
Library callspthread_mutex_lock, dlopenHook and return success/stub
TLSmrs xN, TPIDR_EL0 (stack canary, errno)Map a page and set UC_ARM64_REG_TPIDR_EL0 to its base; canary checks pass as long as prologue/epilogue reads hit the same bytes

JNIEnv slot math: table entries are 8 bytes each, in jni.h declaration order — e.g. slot 176 = NewByteArray, 184 = GetByteArrayElements, 208 = SetByteArrayRegion. Derive the slot from the disassembly (ldr x8, [x8, #1408] → 1408 / 8 = 176).

Hook pattern: Register a UC_HOOK_CODE callback. When PC hits a known import address, execute the Python simulation, then set PC = LR to skip the original function.


Show full SKILL.md (263 more words)Show less

Callback Types to Use

CallbackPurpose
UC_HOOK_CODEIntercept import calls by address; instruction-level trace (use sparingly, narrow range only)
UC_HOOK_BLOCKBlock-level trace (preferred over instruction trace)
UC_HOOK_MEM_UNMAPPEDAuto-map missing pages to recover from unmapped access errors
UC_HOOK_MEM_READ | UC_HOOK_MEM_WRITETrace memory access on targeted data ranges only
UC_HOOK_INTRIntercept SVC/INT for syscall simulation

Range gotcha: hook_add's end is inclusive. For a 4-byte stub use end = addr + size - 1; with adjacent stubs an off-by-one makes neighbouring callbacks fire into each other (they see the other call site's registers).


Iterative Debugging Workflow

When emulation fails, follow this loop:

  1. Run — start emulation, let it crash
  2. Read callback output — which address faulted? What type (read/write/fetch)?
  3. Diagnose:
    • Unmapped memory fetch → missing code page, map it
    • Unmapped memory read/write → missing data section or uninitialized pointer, map or hook
    • Hitting an import stub → identify the function, add a simulation hook
    • TLS access fault (mrs xN, TPIDR_EL0 followed by a load from an offset) or __stack_chk_fail reached → map a TLS page and set UC_ARM64_REG_TPIDR_EL0 (see Environment Simulation)
    • Infinite loop → add a code hook with execution counter, stop after threshold
  4. Fix — add the hook / map the memory / adjust registers
  5. Re-run — repeat until the target function completes

Architecture Quick Reference

ArchUc ConstModeSPLRArgsReturnSyscall
ARM64UC_ARCH_ARM64UC_MODE_LITTLE_ENDIANSPX30X0-X7X0X8 + SVC #0
ARM32UC_ARCH_ARMUC_MODE_THUMB / UC_MODE_ARMSPLRR0-R3R0R7 + SVC #0
x86-64UC_ARCH_X86UC_MODE_64RSP(stack)RDI,RSI,RDX,RCX,R8,R9RAXRAX + syscall
x86-32UC_ARCH_X86UC_MODE_32ESP(stack)(stack)EAXEAX + int 0x80
MIPS32UC_ARCH_MIPSUC_MODE_MIPS32 + UC_MODE_BIG_ENDIAN$sp$ra$a0-$a3$v0$v0 + syscall

© index-login, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .kilo/skill/rev-unicorn-debug of index-login/MobileRE-Skill.

Open the folder on GitHubat commit 69e7f5e

Compare with similar skills

Rev Unicorn Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rev Unicorn Debug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rev Unicorn Debug this skillindex-login/MobileRE-Skill144—~1.9kAutomated safety check: PassMIT
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Re Fridadslsdzc/rev-skills130—~2.8kAutomated safety check: PassApache-2.0
Re Frida Script Authordslsdzc/rev-skills130—~1.2kAutomated safety check: PassApache-2.0
Re Android Cryptodslsdzc/rev-skills130—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Performing iOS App Security Assessment

    mukul975/Anthropic-Cybersecurity-Skills

    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Re Frida

    dslsdzc/rev-skills

    Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~2.8k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Re Frida Script Author

    dslsdzc/rev-skills

    Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.2k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Re Android Crypto

    dslsdzc/rev-skills

    Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。

    130 GitHub stars~1.1k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • LangBot Plugin Development

    langbot-app/LangBot

    Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.

    18k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed

More from index-login/MobileRE-Skill

  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    144 GitHub stars~3k tokensUpdated 9 days ago
    Auto-check passed
  • Rev Dex Dumper

    index-login/MobileRE-Skill

    Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

    144 GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Karpathy Guidelines

    index-login/MobileRE-Skill

    减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

    144 GitHub stars~242 tokensUpdated 9 days ago
    Auto-check passed

Categories

Questions about Rev Unicorn Debug

What does Rev Unicorn Debug do?

Debug and emulate specific code fragments or functions using the Unicorn engine. Rev Unicorn Debug is an agent skill from index-login/MobileRE-Skill. Debug and emulate specific code fragments or functions using the Unicorn engine.

When should I use Rev Unicorn Debug?

Rev Unicorn Debug fits situations like: wants to emulate a function with Unicorn; trace binary execution without running the full program; decode data by emulating the algorithm; bypass environment dependencies (JNI.

How do I install Rev Unicorn Debug in Claude Code?

Run `npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a claude-code`. Or copy the skill folder (.kilo/skill/rev-unicorn-debug in index-login/MobileRE-Skill) into .claude/skills/rev-unicorn-debug in your project. Claude Code loads it when a task matches its description.

How do I install Rev Unicorn Debug in Codex?

Run `npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a codex`. Or copy the skill folder (.kilo/skill/rev-unicorn-debug in index-login/MobileRE-Skill) into .agents/skills/rev-unicorn-debug in your project. Codex loads it when a task matches its description.

Can I use Rev Unicorn Debug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rev-unicorn-debug, .gemini/skills/rev-unicorn-debug, .github/skills/rev-unicorn-debug and .opencode/skills/rev-unicorn-debug in your project.

What does Rev Unicorn Debug need to run?

Going by SKILL.md and its folder, Rev Unicorn Debug needs the command-line tools its instructions call (python3 and pip). Our summary lists: Python 3.

Does Rev Unicorn Debug access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Rev Unicorn Debug safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rev Unicorn Debug use?

Rev Unicorn Debug is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rev Unicorn Debug use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rev Unicorn Debug?

Skills that share tags, products or a category with Rev Unicorn Debug: Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Re Frida (dslsdzc/rev-skills, 130 stars) and Re Frida Script Author (dslsdzc/rev-skills, 130 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rev Unicorn Debug?

index-login (a GitHub user) maintains it in index-login/MobileRE-Skill, which has 144 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 30, 2026.

Source: index-login/MobileRE-Skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.