Mobile Reverse
sickn33/agentic-awesome-skills
Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…
Debug and emulate specific code fragments or functions using the Unicorn engine.
$ npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install index-login/MobileRE-Skill rev-unicorn-debug --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kilo/skill/rev-unicorn-debug .claude/skills/rev-unicorn-debug && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "rev-unicorn-debug" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-unicorn-debug into .claude/skills/rev-unicorn-debug/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-unicorn-debug", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-unicorn-debugType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install index-login/MobileRE-Skill rev-unicorn-debug --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.kilo/skill/rev-unicorn-debug .agents/skills/rev-unicorn-debug && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "rev-unicorn-debug" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-unicorn-debug into .agents/skills/rev-unicorn-debug/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-unicorn-debug", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install index-login/MobileRE-Skill rev-unicorn-debug --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.kilo/skill/rev-unicorn-debug .cursor/skills/rev-unicorn-debug && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "rev-unicorn-debug" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-unicorn-debug into .cursor/skills/rev-unicorn-debug/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-unicorn-debug", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/index-login/MobileRE-Skill.git --path .kilo/skill/rev-unicorn-debug--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install index-login/MobileRE-Skill rev-unicorn-debug --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.kilo/skill/rev-unicorn-debug .gemini/skills/rev-unicorn-debug && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "rev-unicorn-debug" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-unicorn-debug into .gemini/skills/rev-unicorn-debug/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-unicorn-debug", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install index-login/MobileRE-Skill rev-unicorn-debugInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/.kilo/skill/rev-unicorn-debug .github/skills/rev-unicorn-debug && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "rev-unicorn-debug" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-unicorn-debug into .github/skills/rev-unicorn-debug/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-unicorn-debug", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install index-login/MobileRE-Skill rev-unicorn-debug --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.kilo/skill/rev-unicorn-debug .opencode/skills/rev-unicorn-debug && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "rev-unicorn-debug" agent skill from https://github.com/index-login/MobileRE-Skill/tree/main/.kilo/skill/rev-unicorn-debug into .opencode/skills/rev-unicorn-debug/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rev-unicorn-debug", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
rev-unicorn-debugDebug and emulate specific code fragments or functions using the Unicorn engine.
Rev Unicorn Debug is an agent skill from index-login/MobileRE-Skill. Debug and emulate specific code fragments or functions using the Unicorn engine. Activate when the user wants to emulate a function with Unicorn, trace binary execution without running the full program, decrypt or decode data by emulating the algorithm, or bypass environment dependencies (JNI, syscalls, libc) during emulation.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Mobile application security, Debugging and Reverse engineering and malware. It works with Model Context Protocol, Python and Frida. The repository describes itself as: AI Agent 驱动的移动端逆向技能集:Frida hook、一键脱壳、反检测绕过、内存 DEX dump、Ghidra MCP 符号/结构恢复。AI-agent skill system for mobile reverse engineering. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 69e7f5e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3pipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Rev Unicorn Debug loads about 1.9k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 809 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from index-login/MobileRE-Skill at commit 69e7f5e, republished under its MIT licence (© index-login). 809 words, ~1,931 tokens.
.claude/skills/rev-unicorn-debug/SKILL.md (or your agent's skills folder).Debug and emulate specific code fragments or functions using the Unicorn engine. Analyze context dependencies (JNI, syscalls, library functions) and simulate them through hook mechanisms to complete the user's debugging goal.
Source: P4nda0s/reverse-skills (MIT).
pip install unicornUnicorn is the CPU emulation engine (Python binding, Windows wheel available — no JDK or Android toolchain needed). It emulates instructions only: loading the .so, resolving relocations, and simulating libc/JNI/syscalls are done by the Python harness you write (see below).
Import it instead of rewriting boilerplate:
from uniharness import Harness, asm, JNI_SLOTS
h = Harness(trace=False) # trace=True prints every instruction
h.map_raw("lib.so", 0, 0x10000) # vaddr==file offset; else h.map_elf("lib.so")
h.setup_stack()
h.setup_tls() # TPIDR_EL0 + canary at TLS+40
env = h.jni_env(slots={JNI_SLOTS["NewByteArray"]: cb}) # fake JNIEnv: stub + hook per slot
r = h.call(0x196C, args=[env, 0]) # run until ret; r.x0, r.insnsHelpers: map / map_raw / map_elf / alloc / setup_stack / setup_tls / stub (accepts code= from asm()) / hook / jni_env / call / run / fault. Self-test: python3 uniharness.py.
Recon before writing a harness (raw-map check / deps / exports / relocs): tools/so.py info.
Dependencies: see repo root requirements.txt (unicorn, capstone, keystone-engine, pyelftools).
One-shot emulation without writing a harness:
python3 tools/emu_run.py libfoo.so --sym Java_pkg_Cls_method --jni --args "env,0,'text'" --poke 0x1300c:1=1 --read 0x1000:32Options: --off 0x.. (address instead of symbol), --imp (extra import stubs), --trace, --timeout, --raw, --setup hooks.py (full Harness access), --stub name=val (override an import stub's return, e.g. getpid=1234), --log-jni (log every JNI call: [jni] name(args) -> ret, string/array args decoded), --dump-jni-out FILE (append NewStringUTF / SetByteArrayRegion payloads), --trace-stubs (log every stub hit: [stub] name(args) -> ret; both logs aggregate beyond --watch-max).
Observability layer (white-box / VM / algorithm work): --watch-code PC --watch-regs x0,x1 --watch-buf "x19+0x61f0:16", --watch-read/--watch-write lo-hi (auto-aggregated beyond --watch-max), --scan hex[,hex] [--scan-at PC]. Pair with tools/trace_recon.py (event log -> buffer state sequence) and tools/cipher_lab.py (layer/table/schedule adjudication).
Before emulating, read the target function and identify what it calls. Hook external dependencies by address and simulate in Python:
| Category | Examples | Simulation Strategy |
|---|---|---|
| libc | malloc, free, memcpy, strlen, printf | Hook address, implement logic in Python (bump allocator for malloc) |
| JNI | GetStringUTFChars, FindClass, GetMethodID | Build fake JNIEnv function table in UC memory, write RET stubs at each entry, hook stub addresses |
| Syscalls | read, write, mmap, ioctl | Hook UC_HOOK_INTR, dispatch by syscall number |
| C++ runtime | operator new, __cxa_throw | Hook and simulate |
| Library calls | pthread_mutex_lock, dlopen | Hook and return success/stub |
| TLS | mrs xN, TPIDR_EL0 (stack canary, errno) | Map a page and set UC_ARM64_REG_TPIDR_EL0 to its base; canary checks pass as long as prologue/epilogue reads hit the same bytes |
JNIEnv slot math: table entries are 8 bytes each, in jni.h declaration order — e.g. slot 176 = NewByteArray, 184 = GetByteArrayElements, 208 = SetByteArrayRegion. Derive the slot from the disassembly (ldr x8, [x8, #1408] → 1408 / 8 = 176).
Hook pattern: Register a UC_HOOK_CODE callback. When PC hits a known import address, execute the Python simulation, then set PC = LR to skip the original function.
| Callback | Purpose |
|---|---|
UC_HOOK_CODE | Intercept import calls by address; instruction-level trace (use sparingly, narrow range only) |
UC_HOOK_BLOCK | Block-level trace (preferred over instruction trace) |
UC_HOOK_MEM_UNMAPPED | Auto-map missing pages to recover from unmapped access errors |
UC_HOOK_MEM_READ | UC_HOOK_MEM_WRITE | Trace memory access on targeted data ranges only |
UC_HOOK_INTR | Intercept SVC/INT for syscall simulation |
Range gotcha: hook_add's end is inclusive. For a 4-byte stub use end = addr + size - 1; with adjacent stubs an off-by-one makes neighbouring callbacks fire into each other (they see the other call site's registers).
When emulation fails, follow this loop:
mrs xN, TPIDR_EL0 followed by a load from an offset) or __stack_chk_fail reached → map a TLS page and set UC_ARM64_REG_TPIDR_EL0 (see Environment Simulation)| Arch | Uc Const | Mode | SP | LR | Args | Return | Syscall |
|---|---|---|---|---|---|---|---|
| ARM64 | UC_ARCH_ARM64 | UC_MODE_LITTLE_ENDIAN | SP | X30 | X0-X7 | X0 | X8 + SVC #0 |
| ARM32 | UC_ARCH_ARM | UC_MODE_THUMB / UC_MODE_ARM | SP | LR | R0-R3 | R0 | R7 + SVC #0 |
| x86-64 | UC_ARCH_X86 | UC_MODE_64 | RSP | (stack) | RDI,RSI,RDX,RCX,R8,R9 | RAX | RAX + syscall |
| x86-32 | UC_ARCH_X86 | UC_MODE_32 | ESP | (stack) | (stack) | EAX | EAX + int 0x80 |
| MIPS32 | UC_ARCH_MIPS | UC_MODE_MIPS32 + UC_MODE_BIG_ENDIAN | $sp | $ra | $a0-$a3 | $v0 | $v0 + syscall |
© index-login, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .kilo/skill/rev-unicorn-debug of index-login/MobileRE-Skill.
Open the folder on GitHubat commit 69e7f5e
Rev Unicorn Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Rev Unicorn Debug this skillindex-login/MobileRE-Skill | 144 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Mobile Reversesickn33/agentic-awesome-skills | 47k | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Re Fridadslsdzc/rev-skills | 130 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Re Frida Script Authordslsdzc/rev-skills | 130 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Re Android Cryptodslsdzc/rev-skills | 130 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 |
sickn33/agentic-awesome-skills
Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…
mukul975/Anthropic-Cybersecurity-Skills
Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…
dslsdzc/rev-skills
Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。
langbot-app/LangBot
Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
index-login/MobileRE-Skill
Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.
index-login/MobileRE-Skill
减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。
Works with
Categories
Debug and emulate specific code fragments or functions using the Unicorn engine. Rev Unicorn Debug is an agent skill from index-login/MobileRE-Skill. Debug and emulate specific code fragments or functions using the Unicorn engine.
Rev Unicorn Debug fits situations like: wants to emulate a function with Unicorn; trace binary execution without running the full program; decode data by emulating the algorithm; bypass environment dependencies (JNI.
Run `npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a claude-code`. Or copy the skill folder (.kilo/skill/rev-unicorn-debug in index-login/MobileRE-Skill) into .claude/skills/rev-unicorn-debug in your project. Claude Code loads it when a task matches its description.
Run `npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a codex`. Or copy the skill folder (.kilo/skill/rev-unicorn-debug in index-login/MobileRE-Skill) into .agents/skills/rev-unicorn-debug in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add index-login/MobileRE-Skill --skill rev-unicorn-debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rev-unicorn-debug, .gemini/skills/rev-unicorn-debug, .github/skills/rev-unicorn-debug and .opencode/skills/rev-unicorn-debug in your project.
Going by SKILL.md and its folder, Rev Unicorn Debug needs the command-line tools its instructions call (python3 and pip). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Rev Unicorn Debug is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Rev Unicorn Debug: Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Re Frida (dslsdzc/rev-skills, 130 stars) and Re Frida Script Author (dslsdzc/rev-skills, 130 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
index-login (a GitHub user) maintains it in index-login/MobileRE-Skill, which has 144 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 30, 2026.
Source: index-login/MobileRE-Skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.