Mobile App Security Testing
langbyyi/CyberStrikeAI-SRC
移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
$ npx skills add trilwu/secskills --skill analyzing-ios-binaries -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills analyzing-ios-binaries --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/analyzing-ios-binaries .claude/skills/analyzing-ios-binaries && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyzing-ios-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-ios-binaries into .claude/skills/analyzing-ios-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-ios-binaries", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-ios-binariesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill analyzing-ios-binaries -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills analyzing-ios-binaries --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/analyzing-ios-binaries .agents/skills/analyzing-ios-binaries && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyzing-ios-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-ios-binaries into .agents/skills/analyzing-ios-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-ios-binaries", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-ios-binaries -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills analyzing-ios-binaries --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/analyzing-ios-binaries .cursor/skills/analyzing-ios-binaries && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyzing-ios-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-ios-binaries into .cursor/skills/analyzing-ios-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-ios-binaries", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/analyzing-ios-binaries--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill analyzing-ios-binaries -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills analyzing-ios-binaries --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/analyzing-ios-binaries .gemini/skills/analyzing-ios-binaries && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyzing-ios-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-ios-binaries into .gemini/skills/analyzing-ios-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-ios-binaries", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills analyzing-ios-binariesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill analyzing-ios-binaries -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/analyzing-ios-binaries .github/skills/analyzing-ios-binaries && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-ios-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-ios-binaries into .github/skills/analyzing-ios-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-ios-binaries", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-ios-binaries -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills analyzing-ios-binaries --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/analyzing-ios-binaries .opencode/skills/analyzing-ios-binaries && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-ios-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-ios-binaries into .opencode/skills/analyzing-ios-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-ios-binaries", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzing-ios-binariesAnalyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Analyzing iOS Binaries is an agent skill from trilwu/secskills. Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and reading Swift metadata. Use when working with an IPA or .app bundle, when a downloaded App Store binary shows cryptid=1, when class-dump returns nothing, or when analyzing iOS frameworks and app extensions.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Mobile, covering iOS development, Mobile application security and App store release. It works with iOS, Objective-C and Frida. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgswiftxcrunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analyzing iOS Binaries loads about 2k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 678 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 678 words, ~1,959 tokens.
.claude/skills/analyzing-ios-binaries/SKILL.md (or your agent's skills folder).App Store binaries are encrypted at rest and decrypted by the kernel at load time, so every static tool fails on a downloaded IPA until you dump the decrypted image from memory. That single step gates everything else, and it is the reason most iOS analysis stalls before it starts.
.app bundle and need to read the binaryclass-dump returns nothing or garbageotool shows cryptid 1testing-mobile-applications or the relevant
reversing-* skilltesting-mobile-applicationsbypassing-mobile-pinningbypassing-root-jailbreak-detection firstotool -l TargetApp | grep -A5 LC_ENCRYPTION_INFO
# cryptid 1 → FairPlay-encrypted, decrypt before anything else
# cryptid 0 → already decrypted (dev build, or you already dumped it)Everything downstream is meaningless on an encrypted binary. class-dump
returning nothing is almost always this, not obfuscation.
# Decrypt on a jailbroken device by dumping the loaded image
frida-ios-dump -l # list installed apps
frida-ios-dump com.target.app # produces a decrypted IPA
bagbak com.target.app # alternative, handles extensions/frameworks well
# Rootless jailbreaks and TrollStore installs work with the same tools
# Older devices: Clutch, flexdecryptDump frameworks and extensions too, not just the main binary. PlugIns/
(share sheets, widgets, keyboards) and Frameworks/ carry their own encrypted
Mach-Os, and app extensions frequently hold the interesting entitlements and a
weaker security posture than the main app.
file TargetApp # thin or fat/universal
lipo -info TargetApp # architectures present
lipo -thin arm64 TargetApp -o app64 # extract one before analysis
otool -hv app64 # header flags: PIE
otool -l app64 | rg 'LC_LOAD_DYLIB|LC_RPATH|LC_CODE_SIGNATURE|LC_ENCRYPTION'
otool -Iv app64 | head # indirect symbols
nm -m app64 | rg -v ' U ' | head # defined symbols
# Protections at a glance
otool -hv app64 | rg PIE # ASLR
otool -Iv app64 | rg stack_chk # stack canaries
otool -Iv app64 | rg objc_release # ARC in useExtract the entitlements — they define what the app is allowed to do and often reveal the interesting attack surface:
codesign -d --entitlements :- TargetApp.app
# Look for: keychain-access-groups, App Groups, associated-domains,
# get-task-allow (debuggable!), custom URL scheme claimsget-task-allow set to true on a production build means the app is debuggable
and is a finding on its own.
Objective-C keeps its full class metadata in the binary, so recovery is excellent — method names, selectors, class hierarchy, ivars.
class-dump -H app64 -o ./headers # classic
class-dump-dyld # for dyld shared cache resident classes
dsdump --objc --color app64 # modern alternative, handles Swift too
# Then read the type map
rg -l 'Manager|Service|API|Auth|Crypto|Keychain|Payment' ./headers | head -20In a disassembler, Objective-C calls go through objc_msgSend, so the callee
is a selector string in a register rather than a direct branch. Both IDA and
Ghidra have plugins that resolve this; without them the call graph is largely
useless.
Swift is harder. Names are mangled, and method dispatch is often static or
through witness tables rather than objc_msgSend.
# Demangle what you find
nm app64 | swift demangle
xcrun swift-demangle '$s10TargetApp11AuthManagerC5loginyyF'
# Swift type metadata lives in dedicated sections
otool -l app64 | rg '__swift5_types|__swift5_proto|__swift5_reflstr'
dsdump --swift app64Practical approach for Swift-heavy apps: @objc and @objcMembers members
still appear in the Objective-C metadata, so class-dump gives you a partial
map. For the rest, work from string references and the reflection sections
rather than trying to recover a full class list. Runtime enumeration with
Frida is usually faster than static recovery:
frida -U -f com.target.app -l enumerate-swift-classes.js# Enumerate everything the runtime knows
objection -g com.target.app explore
# ios hooking list classes
# ios hooking search methods <keyword>
# ios hooking watch method "-[AuthManager login:]" --dump-args --dump-return
# Direct Frida for anything objection does not cover
frida -U -f com.target.app -l hooks.jsRuntime beats static on iOS more often than on other platforms: the
Objective-C runtime is introspectable, so listing classes and watching methods
gets you to the logic faster than reading a disassembly of objc_msgSend
dispatch.
get-task-allow in production__cstring and in the plist files inside the bundlekSecAttrAccessibleAlways rather than a ThisDeviceOnly classWKWebView configuration — allowFileAccessFromFileURLs,
loading remote content into a JS-bridged viewFrameworks/ and check eachcryptid
first. It is almost always encryption.@objc
members, and string references recover a great deal. Enumerate at runtime.testing-mobile-applications — storage, keychain, IPC, and the wider iOS testbypassing-root-jailbreak-detection — when detection blocks your toolingbypassing-mobile-pinning — TLS interception on iOS stacksanalyzing-binaries — deeper native RE of the same Mach-O© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-core/skills/analyzing-ios-binaries of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Analyzing iOS Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyzing iOS Binaries this skilltrilwu/secskills | 157 | — | ~2k | Automated safety check: Pass | MIT | |
| Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC | 135 | — | ~12k | Automated safety check: Pass | Apache-2.0 | |
| Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| iOS SecurityHoangNguyen0403/agent-skills-standard | 571 | — | ~500 | Automated safety check: Pass | MIT | |
| App Store Reviewsafaiyeh/app-store-review-skill | 366 | 1 repos | ~3.4k | Automated safety check: Pass | MIT | |
| OdevioOdevio/Odevio-CLI | 423 | — | ~7.6k | Automated safety check: Pass | MIT |
langbyyi/CyberStrikeAI-SRC
移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…
mukul975/Anthropic-Cybersecurity-Skills
Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…
HoangNguyen0403/agent-skills-standard
Secure iOS apps with secure storage, biometrics, and data protection.
safaiyeh/app-store-review-skill
Evaluates code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill.
Odevio/Odevio-CLI
Take a Flutter project to an iPhone or the App Store with Odevio - build, sign and publish iOS apps from Windows, Linux or macOS with no Mac and no Xcode.
ZestfulPulse/ios-app-store-submit
Build, sign, and submit a Flutter/iOS app to the App Store Connect — covers Xcode archive/export, code signing (including headless-Mac keychain workarounds), the asc CLI for App Store Connect…
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.
Works with
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…. Analyzing iOS Binaries is an agent skill from trilwu/secskills. Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and reading Swift metadata.
Analyzing iOS Binaries fits situations like: working with an IPA; A downloaded App Store binary shows cryptid=1; class-dump returns nothing; analyzing iOS frameworks and app extensions.
Run `npx skills add trilwu/secskills --skill analyzing-ios-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/analyzing-ios-binaries in trilwu/secskills) into .claude/skills/analyzing-ios-binaries in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill analyzing-ios-binaries -a codex`. Or copy the skill folder (secskills-core/skills/analyzing-ios-binaries in trilwu/secskills) into .agents/skills/analyzing-ios-binaries in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-ios-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-ios-binaries, .gemini/skills/analyzing-ios-binaries, .github/skills/analyzing-ios-binaries and .opencode/skills/analyzing-ios-binaries in your project.
Going by SKILL.md and its folder, Analyzing iOS Binaries needs the command-line tools its instructions call (rg, swift and xcrun).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Analyzing iOS Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Analyzing iOS Binaries: Mobile App Security Testing (langbyyi/CyberStrikeAI-SRC, 135 stars), Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), iOS Security (HoangNguyen0403/agent-skills-standard, 571 stars) and App Store Review (safaiyeh/app-store-review-skill, 366 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.