Agent skill

Tool Reference

by Paresh-Maheshwari in Paresh-Maheshwari/morphe-ai

Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg.

GPL-3.0Auto-check passedSecurity

Install Tool Reference

skills CLI
$ npx skills add Paresh-Maheshwari/morphe-ai --skill tool-reference -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Paresh-Maheshwari/morphe-ai tool-reference --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Paresh-Maheshwari/morphe-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/tool-reference .claude/skills/tool-reference && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tool-reference
GitHub stars
177
Token cost
~1.4k tokens
SKILL.md length
214 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
GPL-3.0

At a glance

Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg.

  • Running any analysis tool to get the best flags and arguments
  • SKILL.md covers ripgrep (rg) — Fast Code Search, jadx — APK Decompiler, baksmali — DEX Disassembler and aapt — APK Info, plus 3 more sections
  • Calls rg and uvx
  • Tasks that involve Reverse engineering and malware

What it does

Tool Reference is an agent skill from Paresh-Maheshwari/morphe-ai. Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg. Use when running any analysis tool to get the best flags and arguments.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware. It works with Android and Kaggle. The repository describes itself as: Morphe's AI-powered Android APK patching workspace — multi-agent pipeline for APK analysis, target hunting, patch writing & deployment. The licence is GPL-3.0.

When your agent uses it

  • Running any analysis tool to get the best flags and arguments
  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/tool-reference”

What it can do on your machine

Read from SKILL.md and the folder at commit 2d7fde2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • uvx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uvx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tool Reference loads about 1.4k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 214 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Paresh-Maheshwari/morphe-ai at commit 2d7fde2, republished under its GPL-3.0 licence (© Paresh-Maheshwari). 214 words, ~1,364 tokens.

Download SKILL.mdSave it as .claude/skills/tool-reference/SKILL.md (or your agent's skills folder).
name
tool-reference
description
Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg. Use when running any analysis tool to get the best flags and arguments.

When to use: Running any RE tool. Use these optimized flags for best results. Always use rg instead of grep. For jadx, the Kaggle runner (.kiro/jadx-decompile) is the primary path for large APKs — explain the data flow and get approval before uploading; local jadx is the fallback for small/quick tasks or when remote is declined.

Tool Reference — Optimized Arguments

Use rg instead of grep everywhere. It's faster, respects .gitignore, and has better output.

bash
# Search Java files only
rg "pattern" path/ -g "*.java"

# List matching files only (fast overview)
rg "pattern" path/ -g "*.java" -l

# With context lines
rg "pattern" path/ -g "*.java" -C 3    # 3 lines before+after
rg "pattern" path/ -g "*.java" -A 10   # 10 lines after

# Case insensitive
rg -i "pattern" path/

# Count matches per file
rg "pattern" path/ -g "*.java" -c

# Only show matching text (extract values)
rg -o "pattern" path/

# Max matches per file (avoid flooding)
rg "pattern" path/ --max-count 3

# Search smali files
rg "pattern" path/ -g "*.smali"

# Fixed string (no regex interpretation)
rg -F "exact.string.match" path/

# Multiple patterns
rg "pattern1|pattern2|pattern3" path/ -g "*.java" -l

# Exclude directories
rg "pattern" path/ --glob '!**/test/**'

jadx — APK Decompiler

Remote (Kaggle — primary path, approval required before upload)

The Kaggle runner is the primary decompilation path for large APKs. Explain that the direct URL and downloaded APK are processed by Kaggle, obtain explicit user approval, then run:

bash
.kiro/jadx-decompile "<url>" analysis/<app>/
Local (small APKs only)
bash
# Full decompile with all optimizations
jadx -d output/ input.apk \
  --deobf \
  --show-bad-code \
  --decompilation-mode restructure \
  -j $(nproc) \
  -Pdex-input.verify-checksum=no \
  -Pkotlin-metadata.class-alias=yes \
  -Pkotlin-metadata.method-args=yes \
  -Pkotlin-metadata.fields=yes \
  -Pkotlin-metadata.data-class=yes \
  -Pkotlin-metadata.to-string=yes \
  -Pkotlin-metadata.getters=yes \
  --use-source-name-as-class-name-alias always \
  --use-kotlin-methods-for-var-names apply-and-hide \
  --rename-flags all

# Decompile single class (quick check)
jadx --single-class "com.example.ClassName" -d output/ input.apk

# Sources only (no resources — faster)
jadx -d output/ --no-res input.apk
Key flags
FlagPurpose
--deobfRename obfuscated a/b/c to readable names
--show-bad-codeShow broken code instead of hiding
--decompilation-mode restructureCleanest Java output
-j NThread count (use all cores)
--no-resSkip resources (faster)
--single-classDecompile one class only

baksmali — DEX Disassembler

bash
# Disassemble single DEX
baksmali d classes.dex -o smali/

# Disassemble specific DEX from APK
baksmali d "app.apk/classes2.dex" -o smali/classes2/

# Disassemble with code offsets (useful for debugging)
baksmali d --code-offsets classes.dex -o smali/

# Disassemble specific classes only
baksmali d --classes "Lcom/example/Target;" classes.dex -o smali/

# Use all cores
baksmali d -j $(nproc) classes.dex -o smali/

# Disassemble ALL DEX files from APK
for dex in $(unzip -l app.apk | rg "\.dex" | awk '{print $4}'); do
    name=$(basename $dex .dex)
    unzip -o app.apk $dex -d /tmp/dex_extract
    baksmali d /tmp/dex_extract/$dex -o smali/$name
done

aapt — APK Info

bash
# Package name, version, SDK (most common)
aapt dump badging app.apk | head -5

# Full manifest as XML tree
aapt dump xmltree app.apk AndroidManifest.xml

# Check for split APK requirements
aapt dump xmltree app.apk AndroidManifest.xml | rg -i "split|requiredSplit"

# List permissions
aapt dump permissions app.apk

# List all resources
aapt dump resources app.apk

# List strings
aapt dump strings app.apk

apkid — Protection Detection

bash
# Basic scan
uvx apkid app.apk

# Verbose (more detail)
uvx apkid -v app.apk

# Recursive (scan inside split APKs)
uvx apkid -r app.apk

# JSON output (for parsing)
uvx apkid -j app.apk
What apkid tells you
OutputMeaning
compiler: r8R8 optimizer used (standard)
compiler: d8D8 compiler (no optimization)
obfuscator: proguardProGuard obfuscation
packer: *App is packed (harder to patch)
anti_vmEmulator detection present
anti_debugDebugger detection present

unzip — APK Contents

bash
# List all files in APK
unzip -l app.apk

# List DEX files
unzip -l app.apk | rg "\.dex"

# List native libraries
unzip -l app.apk | rg "\.so|lib/"

# Check framework (React Native, Flutter)
unzip -l app.apk | rg "index.android.bundle|libflutter|libapp"

# Extract specific file
unzip -o app.apk classes5.dex -d /tmp/

# Extract decompiled zip
unzip -qo decompiled.zip -d decompiled/

strings — Binary String Extraction

bash
# Extract all printable strings from APK
strings app.apk | rg -i "premium|entitlement|license"

# Find base64 encoded URLs
strings app.apk | rg "aHR0c" | while read b; do echo "$b" | base64 -d 2>/dev/null; echo; done

# Find API endpoints
strings app.apk | rg "https?://" | sort -u

© Paresh-Maheshwari, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .kiro/skills/tool-reference of Paresh-Maheshwari/morphe-ai.

Open the folder on GitHubat commit 2d7fde2

Compare with similar skills

Tool Reference next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tool Reference compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tool Reference this skillParesh-Maheshwari/morphe-ai177—~1.4kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
APK Static Analysisdslsdzc/rev-skills130—~2kAutomated safety check: PassApache-2.0
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Mobile Auditbriiirussell/cybersecurity-skills413—~2.6kAutomated safety check: WarnMIT
Re Armdslsdzc/rev-skills130—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • APK Static Analysis

    dslsdzc/rev-skills

    Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

    130 GitHub stars~2k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Mobile Audit

    briiirussell/cybersecurity-skills

    Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance.

    413 GitHub stars~2.6k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • Re Arm

    dslsdzc/rev-skills

    ARM 架构逆向(非 Android):Cortex-M/A 向量表、Thumb/ARM 切换、AAPCS 调用约定、位置相关代码重定位、MMIO 外设寄存器交叉。

    130 GitHub stars~2.2k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer data sources for, and package FongMi/WebHome custom homepage single-file HTML.

    1.7k GitHub stars~3.8k tokensUpdated yesterday
    Frontend & DesignAuto-check passed

More from Paresh-Maheshwari/morphe-ai

All 13 skills in this repo
  • Build Deploy Troubleshoot

    Paresh-Maheshwari/morphe-ai

    Build, test, deploy, and troubleshoot Morphe patches — gradle commands, CLI usage, git workflow, common errors and fixes.

    177 GitHub stars~1.1k tokensUpdated 10 days ago
    Auto-check passed
  • Dev Environment Setup

    Paresh-Maheshwari/morphe-ai

    Complete Morphe development environment setup — prerequisites, cloning repos, gradle auth, IDE config, build commands.

    177 GitHub stars~1k tokensUpdated 10 days ago
    Auto-check: notes
  • Fingerprinting Guide

    Paresh-Maheshwari/morphe-ai

    Complete guide to Morphe fingerprinting — how to identify obfuscated methods using stable characteristics.

    177 GitHub stars~2.4k tokensUpdated 10 days ago
    Auto-check passed
  • Morphe CLI Reference

    Paresh-Maheshwari/morphe-ai

    Morphe CLI v1.17.0 (morphe-desktop) complete command reference — patch, list-patches, list-versions, options-create, utility install/uninstall.

    177 GitHub stars~2.9k tokensUpdated 10 days ago
    Auto-check passed
  • Morphe Faq And App Notes

    Paresh-Maheshwari/morphe-ai

    Morphe FAQ, current pinned official app targets, and app-specific notes.

    177 GitHub stars~573 tokensUpdated 10 days ago
    Auto-check passed
  • Morphe Library Reference

    Paresh-Maheshwari/morphe-ai

    Complete reference for all Morphe utility libraries — BytecodeUtils, ResourceUtils, FreeRegisterProvider, Settings, UI, Extensions.

    177 GitHub stars~1.9k tokensUpdated 10 days ago
    Auto-check passed

Works with

Categories

Questions about Tool Reference

What does Tool Reference do?

Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg. Tool Reference is an agent skill from Paresh-Maheshwari/morphe-ai. Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg.

When should I use Tool Reference?

Tool Reference fits situations like: running any analysis tool to get the best flags and arguments; tasks that involve Reverse engineering and malware.

How do I install Tool Reference in Claude Code?

Run `npx skills add Paresh-Maheshwari/morphe-ai --skill tool-reference -a claude-code`. Or copy the skill folder (.kiro/skills/tool-reference in Paresh-Maheshwari/morphe-ai) into .claude/skills/tool-reference in your project. Claude Code loads it when a task matches its description.

How do I install Tool Reference in Codex?

Run `npx skills add Paresh-Maheshwari/morphe-ai --skill tool-reference -a codex`. Or copy the skill folder (.kiro/skills/tool-reference in Paresh-Maheshwari/morphe-ai) into .agents/skills/tool-reference in your project. Codex loads it when a task matches its description.

Can I use Tool Reference in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Paresh-Maheshwari/morphe-ai --skill tool-reference -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tool-reference, .gemini/skills/tool-reference, .github/skills/tool-reference and .opencode/skills/tool-reference in your project.

What does Tool Reference need to run?

Going by SKILL.md and its folder, Tool Reference needs the command-line tools its instructions call (rg and uvx).

Does Tool Reference access the network?

SKILL.md contains no URLs. Its commands use uvx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Tool Reference safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tool Reference use?

Tool Reference is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tool Reference use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tool Reference?

Skills that share tags, products or a category with Tool Reference: Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), APK Static Analysis (dslsdzc/rev-skills, 130 stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars) and Mobile Audit (briiirussell/cybersecurity-skills, 413 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tool Reference?

Paresh-Maheshwari (a GitHub user) maintains it in Paresh-Maheshwari/morphe-ai, which has 177 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on September 29, 2026.

Source: Paresh-Maheshwari/morphe-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.