Agent skill

Performing Dynamic Analysis Of Android App

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…

Apache-2.0Auto-check: warningsSecurity

Install Performing Dynamic Analysis Of Android App

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-dynamic-analysis-of-android-app -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-dynamic-analysis-of-android-app --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-dynamic-analysis-of-android-app .claude/skills/performing-dynamic-analysis-of-android-app && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-dynamic-analysis-of-android-app
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
402 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…

  • Works in 7 steps: Setup Frida Server on Android Device → Enumerate Application Attack Surface → Hook Sensitive Methods → …
  • Testing Android apps for runtime security flaws
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder; calls adb; reaches github.com

What it does

Performing Dynamic Analysis Of Android App is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses. Use when testing Android apps for runtime security flaws, hooking sensitive methods, bypassing client-side protections, or analyzing obfuscated applications. Activates for requests involving Android dynamic analysis, runtime hooking, Frida Android…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Android development, Mobile application security and Static analysis and SAST. It works with Android and Frida. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Testing Android apps for runtime security flaws
  • Hooking sensitive methods
  • Bypassing client-side protections
  • Analyzing obfuscated applications

Example prompts

  • “Use the performing-dynamic-analysis-of-android-app skill to perform runtime dynamic analysis of Android applications using Frida, Objection, and…”
  • “/performing-dynamic-analysis-of-android-app”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Setup Frida Server on Android Device
  2. Enumerate Application Attack Surface
  3. Hook Sensitive Methods
  4. Write Custom Frida Scripts for Deep Analysis
  5. Bypass Root Detection
  6. Analyze Network Communication at Runtime
  7. Extract Decrypted Data and Secrets

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • adb

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Dynamic Analysis Of Android App loads about 2.2k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 402 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningContains instruction-override wording (e.g. “without asking the user”)SKILL.md:171
    // Bypass SafetyNet/Play Integrity

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 402 words, ~2,182 tokens.

Download SKILL.mdSave it as .claude/skills/performing-dynamic-analysis-of-android-app/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-dynamic-analysis-of-android-app
description
Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses. Use when testing Android apps for runtime security flaws, hooking sensitive methods, bypassing client-side protections, or analyzing obfuscated applications. Activates for requests involving Android dynamic analysis, runtime hooking, Frida Android instrumentation, or live app behavior analysis.
domain
cybersecurity
subdomain
mobile-security
author
mahipal
tags
mobile-security, android, frida, dynamic-analysis, owasp-mobile, penetration-testing
version
1.0.0
license
Apache-2.0
nist_csf
PR.PS-01, PR.AA-05, ID.RA-01, DE.CM-09
mitre_attack
T1059, T1056, T1036, T1078, T1027

Performing Dynamic Analysis of Android App

When to Use

Use this skill when:

  • Static analysis results need runtime validation on an actual Android device
  • The target app uses obfuscation (DexGuard, custom packers) that prevents effective static analysis
  • Testing requires observing actual API calls, decrypted data, or runtime-generated values
  • Assessing root detection, tamper detection, or anti-debugging implementations

Do not use this skill on production environments without authorization -- dynamic instrumentation can alter app behavior and trigger security alerts.

Prerequisites

  • Rooted Android device or emulator (Genymotion, Android Studio AVD with writable system)
  • Frida server installed on device matching the architecture (arm64, x86_64)
  • Python 3.10+ with frida-tools and objection packages
  • ADB configured and device connected
  • Target APK installed on device

Workflow

Step 1: Setup Frida Server on Android Device
bash
# Check device architecture
adb shell getprop ro.product.cpu.abi
# Output: arm64-v8a

# Download matching Frida server from GitHub releases
# https://github.com/frida/frida/releases
# Push to device
adb push frida-server-16.x.x-android-arm64 /data/local/tmp/frida-server
adb shell chmod 755 /data/local/tmp/frida-server
adb shell /data/local/tmp/frida-server &

# Verify Frida connection
frida-ps -U
Step 2: Enumerate Application Attack Surface
bash
# List all packages
frida-ps -U -a

# Attach Objection for high-level exploration
objection --gadget com.target.app explore

# List activities, services, receivers
android hooking list activities
android hooking list services
android hooking list receivers

# List loaded classes
android hooking list classes
android hooking search classes com.target.app
Step 3: Hook Sensitive Methods
bash
# Hook all methods of a class
android hooking watch class com.target.app.auth.LoginManager

# Hook specific method with argument dumping
android hooking watch class_method com.target.app.auth.LoginManager.authenticate --dump-args --dump-return

# Hook crypto operations
android hooking watch class javax.crypto.Cipher --dump-args
android hooking watch class java.security.MessageDigest --dump-args

# Hook network calls
android hooking watch class okhttp3.OkHttpClient --dump-args
android hooking watch class java.net.URL --dump-args
Step 4: Write Custom Frida Scripts for Deep Analysis
javascript
// hook_crypto.js - Intercept encryption/decryption operations
Java.perform(function() {
    var Cipher = Java.use("javax.crypto.Cipher");

    Cipher.doFinal.overload("[B").implementation = function(input) {
        var mode = this.getAlgorithm();
        console.log("[Cipher] Algorithm: " + mode);
        console.log("[Cipher] Input: " + bytesToHex(input));

        var result = this.doFinal(input);
        console.log("[Cipher] Output: " + bytesToHex(result));
        return result;
    };

    function bytesToHex(bytes) {
        var hex = [];
        for (var i = 0; i < bytes.length; i++) {
            hex.push(("0" + (bytes[i] & 0xFF).toString(16)).slice(-2));
        }
        return hex.join("");
    }
});
bash
# Execute custom Frida script
frida -U -f com.target.app -l hook_crypto.js --no-pause
Step 5: Bypass Root Detection
javascript
// root_bypass.js - Common root detection bypass
Java.perform(function() {
    // Bypass RootBeer library
    var RootBeer = Java.use("com.scottyab.rootbeer.RootBeer");
    RootBeer.isRooted.implementation = function() {
        console.log("[RootBeer] isRooted() bypassed");
        return false;
    };

    // Bypass generic file-based root checks
    var File = Java.use("java.io.File");
    var originalExists = File.exists;
    File.exists.implementation = function() {
        var path = this.getAbsolutePath();
        var rootPaths = ["/system/app/Superuser.apk", "/system/xbin/su",
                         "/sbin/su", "/system/bin/su", "/data/local/bin/su"];
        if (rootPaths.indexOf(path) >= 0) {
            console.log("[Root] Blocked check for: " + path);
            return false;
        }
        return originalExists.call(this);
    };

    // Bypass SafetyNet/Play Integrity
    try {
        var SafetyNet = Java.use("com.google.android.gms.safetynet.SafetyNetApi");
        console.log("[SafetyNet] Class found - may need additional bypass");
    } catch(e) {}
});
Step 6: Analyze Network Communication at Runtime
javascript
// network_monitor.js - Monitor all HTTP requests
Java.perform(function() {
    // Hook OkHttp3
    try {
        var OkHttpClient = Java.use("okhttp3.OkHttpClient");
        var Interceptor = Java.use("okhttp3.Interceptor");
        var Chain = Java.use("okhttp3.Interceptor$Chain");

        console.log("[OkHttp] Monitoring network requests...");

        var Request = Java.use("okhttp3.Request");
        Request.url.implementation = function() {
            var url = this.url();
            console.log("[OkHttp] URL: " + url.toString());
            return url;
        };
    } catch(e) {
        console.log("[OkHttp] Not found, trying HttpURLConnection");
    }

    // Hook HttpURLConnection
    var URL = Java.use("java.net.URL");
    URL.openConnection.overload().implementation = function() {
        console.log("[URL] Opening: " + this.toString());
        return this.openConnection();
    };
});
Step 7: Extract Decrypted Data and Secrets
bash
# Using Objection for quick extraction
objection --gadget com.target.app explore

# Dump Android Keystore entries
android keystore list
android keystore dump

# Search heap for sensitive objects
android heap search instances com.target.app.model.User
android heap evaluate <handle> "JSON.stringify(clazz)"

# Memory string search
memory search "password" --string
memory search "api_key" --string

Key Concepts

TermDefinition
Dynamic InstrumentationModifying application behavior at runtime by injecting code into the running process
Method HookingReplacing or wrapping function implementations to intercept arguments and return values
Frida ServerDaemon running on the target device that receives instrumentation commands from the host
Dalvik/ART RuntimeAndroid runtime environments; Frida hooks at the ART level for Java/Kotlin methods
Heap InspectionExamining live objects in the application's memory heap to extract runtime data
Show full SKILL.md (164 more words)Show less

Tools & Systems

  • Frida: Dynamic instrumentation toolkit for injecting JavaScript into native Android processes
  • Objection: Higher-level Frida wrapper with pre-built Android and iOS security testing commands
  • frida-trace: Automated method tracing utility for quick reconnaissance of app behavior
  • Drozer: Android security assessment framework for testing IPC and exported components
  • Android Studio Profiler: Runtime monitoring for CPU, memory, and network activity

Common Pitfalls

  • Frida version mismatch: The Frida server on the device must match the frida-tools version on the host. Version mismatches cause connection failures.
  • Anti-Frida detection: Some apps detect Frida by checking for the Frida server process, scanning memory for Frida signatures, or monitoring /proc/self/maps. Use Frida Gadget injection or custom server builds.
  • Obfuscated class names: When ProGuard/R8 is applied, class and method names are shortened (e.g., a.b.c.d()). Use android hooking search classes to discover actual runtime names.
  • Multi-DEX apps: Large apps split across multiple DEX files may not have all classes loaded at startup. Hook class loaders or use Java.enumerateLoadedClasses() after app is fully initialized.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-dynamic-analysis-of-android-app of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Dynamic Analysis Of Android App next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Dynamic Analysis Of Android App compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Dynamic Analysis Of Android App this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.0
Offensive MobileSnailSploit/Claude-Red7.4k—~3.5kAutomated safety check: PassMIT
Android APK Pentesterptn1411/skill219—~917Automated safety check: PassNone
APK Static Analysisdslsdzc/rev-skills135—~2kAutomated safety check: PassApache-2.0
Mobile Securitytransilienceai/communitytools563—~2.5kAutomated safety check: PassMIT
Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC129—~12kAutomated safety check: PassApache-2.0

Similar skills

  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.4k GitHub stars~3.5k tokensUpdated 21 days ago
    SecurityAuto-check passed
  • Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

    219 GitHub stars~917 tokensUpdated 19 days ago
    SecurityAuto-check passed
  • APK Static Analysis

    dslsdzc/rev-skills

    Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

    135 GitHub stars~2k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Mobile Security

    transilienceai/communitytools

    Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

    563 GitHub stars~2.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Mobile App Security Testing

    langbyyi/CyberStrikeAI-SRC

    移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…

    129 GitHub stars~12k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Performing Dynamic Analysis Of Android App

What does Performing Dynamic Analysis Of Android App do?

Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…. Performing Dynamic Analysis Of Android App is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses.

When should I use Performing Dynamic Analysis Of Android App?

Performing Dynamic Analysis Of Android App fits situations like: testing Android apps for runtime security flaws; hooking sensitive methods; bypassing client-side protections; analyzing obfuscated applications.

How do I install Performing Dynamic Analysis Of Android App in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-dynamic-analysis-of-android-app -a claude-code`. Or copy the skill folder (skills/performing-dynamic-analysis-of-android-app in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-dynamic-analysis-of-android-app in your project. Claude Code loads it when a task matches its description.

How do I install Performing Dynamic Analysis Of Android App in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-dynamic-analysis-of-android-app -a codex`. Or copy the skill folder (skills/performing-dynamic-analysis-of-android-app in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-dynamic-analysis-of-android-app in your project. Codex loads it when a task matches its description.

Can I use Performing Dynamic Analysis Of Android App in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-dynamic-analysis-of-android-app -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-dynamic-analysis-of-android-app, .gemini/skills/performing-dynamic-analysis-of-android-app, .github/skills/performing-dynamic-analysis-of-android-app and .opencode/skills/performing-dynamic-analysis-of-android-app in your project.

What does Performing Dynamic Analysis Of Android App need to run?

Going by SKILL.md and its folder, Performing Dynamic Analysis Of Android App needs Python for the scripts in its folder and the command-line tools its instructions call (adb). Our summary lists: Python 3.

Does Performing Dynamic Analysis Of Android App access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Performing Dynamic Analysis Of Android App safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Dynamic Analysis Of Android App use?

Performing Dynamic Analysis Of Android App is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Dynamic Analysis Of Android App use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Performing Dynamic Analysis Of Android App?

Skills that share tags, products or a category with Performing Dynamic Analysis Of Android App: Offensive Mobile (SnailSploit/Claude-Red, 7.4k stars), Android APK Pentester (ptn1411/skill, 219 stars), APK Static Analysis (dslsdzc/rev-skills, 135 stars) and Mobile Security (transilienceai/communitytools, 563 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Dynamic Analysis Of Android App?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.