Agent skill

Discover iOS Keys

by PoomSmart in PoomSmart/MGKeys

Discover and map new MobileGestalt keys for a new iOS version in MGKeys.

MITAuto-check passedMobile

Install Discover iOS Keys

skills CLI
$ npx skills add PoomSmart/MGKeys --skill discover-ios-keys -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PoomSmart/MGKeys discover-ios-keys --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PoomSmart/MGKeys.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/discover-ios-keys .claude/skills/discover-ios-keys && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
discover-ios-keys
GitHub stars
238
Token cost
~1.4k tokens
SKILL.md length
399 words
Files
2
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Discover and map new MobileGestalt keys for a new iOS version in MGKeys.

  • Works in 7 steps: Extract once → Discover locally (Option A only) → Diff against previous baseline → …
  • The user asks to discover keys for a new iOS version
  • SKILL.md covers Prerequisites, Critical: single download, Workflow checklist and Expected outcomes, plus 3 more sections
  • Calls python3, brew and pip

What it does

Discover iOS Keys is an agent skill from PoomSmart/MGKeys. Discover and map new MobileGestalt keys for a new iOS version in MGKeys. Use when the user asks to discover keys for a new iOS version, update version snapshots, diff against the previous baseline, or run the MGKeys IPSW extraction and discovery pipeline.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `reference.md`).

It sits in Mobile. It works with iOS. The repository describes itself as: MobileGestalt Keys (De)obfuscation. The licence is MIT.

When your agent uses it

  • The user asks to discover keys for a new iOS version
  • Update version snapshots
  • Diff against the previous baseline
  • Run the MGKeys IPSW extraction and discovery pipeline

Example prompts

  • “/discover-ios-keys”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Extract once
  2. Discover locally (Option A only)
  3. Diff against previous baseline
  4. Non-gestalt recovery
  5. Reverse-engineer unknowns in IDA
  6. Remaining unknowns
  7. Validate

What it can do on your machine

Read from SKILL.md and the folder at commit 1b831e9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • brew
    • pip
    • pytest
    • mypy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Discover iOS Keys loads about 1.4k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 399 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PoomSmart/MGKeys at commit 1b831e9, republished under its MIT licence (© PoomSmart). 399 words, ~1,364 tokens.

Download SKILL.mdSave it as .claude/skills/discover-ios-keys/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
discover-ios-keys
description
Discover and map new MobileGestalt keys for a new iOS version in MGKeys. Use when the user asks to discover keys for a new iOS version, update version snapshots, diff against the previous baseline, or run the MGKeys IPSW extraction and discovery pipeline.

Discover iOS MobileGestalt Keys (MGKeys)

Prerequisites

bash
brew install blacktop/tap/ipsw
python3 -m venv .venv && .venv/bin/pip install -r requirements.txt

Defaults: device iPhone15,2, arch arm64e, cache under dyld_shared_cache/<BUILD>__<DEVICE>/.

Critical: single download

Do not run extract-version-hashes.sh, discover-version.sh --remote-extract, and dump-dtree.sh -d -v separately — each re-fetches from Apple's CDN. lib-ipsw-extract.sh has no cache-skip, and full IPSW fallback deletes the .ipsw after dyld extraction.

ApproachWhen to use
Option A (full IPSW once)Need dylib + DeviceTree; preferred
Option B (remote dyld once)Gestalt-only; skip separate hash snapshot

See reference.md for exact commands.

Workflow checklist

- [ ] 1. Extract once (Option A or B)
- [ ] 2. Discover locally + post-process
- [ ] 3. Diff against previous version
- [ ] 4. Recover non-gestalt keys from DeviceTree
- [ ] 5. Reverse-engineer remaining unknowns in the dyld shared-cache IDA database
- [ ] 6. Guess remaining unknowns
- [ ] 7. Validate and update docs
Step 1: Extract once

Option A — download IPSW once, extract dylib and dtree locally. Note: ipsw extract --dyld may nest cache at dyld_shared_cache/<BUILD>__<DEVICE>/<BUILD>__<DEVICE>/.

Option B — one shot:

bash
./discover-version.sh iPhone15,2 <VERSION> --remote-extract

Skip extract-version-hashes.sh; discover-version.sh already writes versions/version-<VERSION>.txt.

Step 2: Discover locally (Option A only)
bash
./discover.sh
./deobfuscate.sh arm64e
./discover-version.sh iPhone15,2 <VERSION> --post-process-only

Post-processing writes versions/version-<VERSION>.txt, syncs deobfuscated.py, runs populate_versions.py and gen_mapping.py.

Step 3: Diff against previous baseline
bash
comm -13 <(sort versions/version-<PREV>.txt) <(sort versions/version-<VERSION>.txt)   # new
comm -23 <(sort versions/version-<PREV>.txt) <(sort versions/version-<VERSION>.txt)   # removed

Empty both diffs → metadata-only update (still add version file and bump README).

Step 4: Non-gestalt recovery

Use devicetree.json from Step 1 — do not re-fetch remotely:

bash
python3 recover_from_dtree.py

For multiple IPSWs: python3 recover_from_all_dtrees.py (scans **/*.im4p).

Step 5: Reverse-engineer unknowns in IDA

Prefer the IDA database generated from the dyld shared cache over the extracted dylib because it preserves shared-cache tables and cross-references:

text
dyld_shared_cache/<BUILD>__<DEVICE>/dyld_shared_cache_arm64e.i64

Search unresolved hashes, follow data cross-references into MobileGestalt registration tables, and decompile associated lookup functions. Record only evidence-based paths or call-site findings in keys_desc.py; unresolved keys should remain NULL rather than receive guessed names.

Show full SKILL.md (174 more words)Show less
Step 6: Remaining unknowns
bash
python3 guess_keys.py
python3 guess_keys.py --key <HASH> --verbose

./locate-usage.sh /path/to/iOS/source only if an SDK/source tree is available.

Check triage artifacts:

CategoryWhere to look
Auto-mapped gestaltdiscover-obfuscated-mapped.txt, deobfuscated.py
Non-gestaltmaybe-non-gestalt-keys.txt, mapping.h NULL entries
Unknown gestalthashes.txt minus deobfuscated.py
Removedcomm -23 diff → hashes_legacy.txt
Step 7: Validate
bash
.venv/bin/pytest
.venv/bin/mypy *.py

Update README.md baseline line (The keys are currently based on iOS …). Confirm versions/version-stats.txt lists the new version.

Expected outcomes

Diff resultAction
No changeAdd version-<VERSION>.txt, bump README, extend mapping version comments
New gestalt hashesUsually auto-mapped via _MobileGestalt_* symbols
New non-gestaltmaybe-non-gestalt-keys.txt → dtree recovery
Removed hashessync_discovered_keys.py moves to legacy; verify version-stats

Key files

  • versions/version-<VERSION>.txt — hash snapshot (commit this)
  • versions/version-sim.txt — simulator-only hashes (not in any physical snapshot)
  • deobfuscated.py — key mappings
  • mapping.h, mapping-gestalt.h — generated headers
  • keys_versions.py, versions/version-stats.txt — version metadata
  • keys_desc.py — unknown key hints

Simulator-only list

Do not run device discovery against libMobileGestalt_sim.dylib. Use:

bash
./extract-sim-hashes.sh
./extract-sim-hashes.sh libMobileGestalt_sim.dylib arm64 --no-post-process

That rewrites versions/version-sim.txt, appends new hashes to hashes_legacy.txt, discovers _MobileGestalt_* names into deobfuscated_legacy.py (sync_discovered_keys.py --legacy-only, no device-key moves), and regenerates // Simulator comments. Simulator dylibs are arm64, not arm64e.

Additional resources

© PoomSmart, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .cursor/skills/discover-ios-keys of PoomSmart/MGKeys.

  • SKILL.md
  • reference.md

Open the folder on GitHubat commit 1b831e9

Compare with similar skills

Discover iOS Keys next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Discover iOS Keys compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Discover iOS Keys this skillPoomSmart/MGKeys238—~1.4kAutomated safety check: PassMIT
Hig Project Contextraintree-technology/hig-doctor1445 repos~1.2kAutomated safety check: PassMIT
Hig Components Contentraintree-technology/hig-doctor1445 repos~1.3kAutomated safety check: PassMIT
Argent Metro Debuggerbbplayer-app/BBPlayer1.2k—~3.4kAutomated safety check: PassMIT
iOS Simulator Skilln0an/VivaDicta1301 repos~2.5kAutomated safety check: PassMIT
ThemingCode-with-Beto/skills140—~2.5kAutomated safety check: PassNone

Similar skills

  • Hig Project Context

    raintree-technology/hig-doctor

    Create or update a shared Apple design context document that other HIG skills use to tailor guidance.

    144 GitHub starsUsed in 5 repos~1.2k tokens
    MobileAuto-check passed
  • Hig Components Content

    raintree-technology/hig-doctor

    Apple Human Interface Guidelines for content display components.

    144 GitHub starsUsed in 5 repos~1.3k tokens
    MobileAuto-check passed
  • Argent Metro Debugger

    bbplayer-app/BBPlayer

    Debug a JS runtime via CDP using argent debugger tools. An agent skill from bbplayer-app/BBPlayer.

    1.2k GitHub stars~3.4k tokensUpdated 3 days ago
    MobileAuto-check passed
  • iOS Simulator Skill

    n0an/VivaDicta

    21 production-ready scripts for iOS app testing, building, and automation.

    130 GitHub starsUsed in 1 repo~2.5k tokens
    MobileAuto-check passed
  • Theming

    Code-with-Beto/skills

    Scaffold a unified, cross-platform color theme system into an Expo Router app.

    140 GitHub stars~2.5k tokensUpdated 3 mo ago
    MobileAuto-check passed
  • Inspector Implementation

    ipedro/Inspector

    A skill your agent uses when an agent needs to implement or modify the Inspector library itself — panel UI, hierarchy/runtime behavior, custom property models, macros, or Example-app dogfooding.

    170 GitHub stars~729 tokensUpdated 5 mo ago
    MobileAuto-check passed

Works with

Categories

Questions about Discover iOS Keys

What does Discover iOS Keys do?

Discover and map new MobileGestalt keys for a new iOS version in MGKeys. Discover iOS Keys is an agent skill from PoomSmart/MGKeys. Discover and map new MobileGestalt keys for a new iOS version in MGKeys.

When should I use Discover iOS Keys?

Discover iOS Keys fits situations like: the user asks to discover keys for a new iOS version; update version snapshots; diff against the previous baseline; run the MGKeys IPSW extraction and discovery pipeline.

How do I install Discover iOS Keys in Claude Code?

Run `npx skills add PoomSmart/MGKeys --skill discover-ios-keys -a claude-code`. Or copy the skill folder (.cursor/skills/discover-ios-keys in PoomSmart/MGKeys) into .claude/skills/discover-ios-keys in your project. Claude Code loads it when a task matches its description.

How do I install Discover iOS Keys in Codex?

Run `npx skills add PoomSmart/MGKeys --skill discover-ios-keys -a codex`. Or copy the skill folder (.cursor/skills/discover-ios-keys in PoomSmart/MGKeys) into .agents/skills/discover-ios-keys in your project. Codex loads it when a task matches its description.

Can I use Discover iOS Keys in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PoomSmart/MGKeys --skill discover-ios-keys -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/discover-ios-keys, .gemini/skills/discover-ios-keys, .github/skills/discover-ios-keys and .opencode/skills/discover-ios-keys in your project.

What does Discover iOS Keys need to run?

Going by SKILL.md and its folder, Discover iOS Keys needs the command-line tools its instructions call (python3, brew, pip, pytest and mypy). Our summary lists: Python 3.

Does Discover iOS Keys access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Discover iOS Keys safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Discover iOS Keys use?

Discover iOS Keys is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Discover iOS Keys use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Discover iOS Keys?

Skills that share tags, products or a category with Discover iOS Keys: Hig Project Context (raintree-technology/hig-doctor, 144 stars), Hig Components Content (raintree-technology/hig-doctor, 144 stars), Argent Metro Debugger (bbplayer-app/BBPlayer, 1.2k stars) and iOS Simulator Skill (n0an/VivaDicta, 130 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Discover iOS Keys?

PoomSmart (a GitHub user) maintains it in PoomSmart/MGKeys, which has 238 GitHub stars. The repository was last updated on September 19, 2026.

Source: PoomSmart/MGKeys on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.