Agent skill

Analyzing iOS Binaries

by trilwu in trilwu/secskills

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

MITAuto-check passedMobile

Install Analyzing iOS Binaries

skills CLI
$ npx skills add trilwu/secskills --skill analyzing-ios-binaries -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills analyzing-ios-binaries --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/analyzing-ios-binaries .claude/skills/analyzing-ios-binaries && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-ios-binaries
GitHub stars
157
Token cost
~2k tokens
SKILL.md length
678 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

  • Working with an IPA
  • SKILL.md covers When to Use, When NOT to Use, Check Encryption First and Mach-O Structure and Protections, plus 6 more sections
  • Calls rg, swift and xcrun
  • A downloaded App Store binary shows cryptid=1

What it does

Analyzing iOS Binaries is an agent skill from trilwu/secskills. Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and reading Swift metadata. Use when working with an IPA or .app bundle, when a downloaded App Store binary shows cryptid=1, when class-dump returns nothing, or when analyzing iOS frameworks and app extensions.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering iOS development, Mobile application security and App store release. It works with iOS, Objective-C and Frida. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Working with an IPA
  • A downloaded App Store binary shows cryptid=1
  • Class-dump returns nothing
  • Analyzing iOS frameworks and app extensions

Example prompts

  • “/analyzing-ios-binaries”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • swift
    • xcrun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing iOS Binaries loads about 2k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 678 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 678 words, ~1,959 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-ios-binaries/SKILL.md (or your agent's skills folder).
name
analyzing-ios-binaries
description
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and reading Swift metadata. Use when working with an IPA or .app bundle, when a downloaded App Store binary shows cryptid=1, when class-dump returns nothing, or when analyzing iOS frameworks and app extensions.
verified
2026-07-27

Analyzing iOS Binaries

App Store binaries are encrypted at rest and decrypted by the kernel at load time, so every static tool fails on a downloaded IPA until you dump the decrypted image from memory. That single step gates everything else, and it is the reason most iOS analysis stalls before it starts.

When to Use

  • You have an IPA or .app bundle and need to read the binary
  • class-dump returns nothing or garbage
  • otool shows cryptid 1
  • You need to enumerate Objective-C classes, Swift types, or exported symbols
  • Analyzing embedded frameworks, app extensions, or dynamic libraries

When NOT to Use

  • Android targets — use testing-mobile-applications or the relevant reversing-* skill
  • The wider iOS assessment (storage, keychain, IPC) — use testing-mobile-applications
  • TLS interception — use bypassing-mobile-pinning
  • Jailbreak detection blocking your tooling — use bypassing-root-jailbreak-detection first
  • Cross-platform frameworks — Flutter, Unity, and Xamarin have their own skills; use them for the managed layer and this one for the native shell

Check Encryption First

bash
otool -l TargetApp | grep -A5 LC_ENCRYPTION_INFO
# cryptid 1  → FairPlay-encrypted, decrypt before anything else
# cryptid 0  → already decrypted (dev build, or you already dumped it)

Everything downstream is meaningless on an encrypted binary. class-dump returning nothing is almost always this, not obfuscation.

bash
# Decrypt on a jailbroken device by dumping the loaded image
frida-ios-dump -l                 # list installed apps
frida-ios-dump com.target.app     # produces a decrypted IPA
bagbak com.target.app             # alternative, handles extensions/frameworks well

# Rootless jailbreaks and TrollStore installs work with the same tools
# Older devices: Clutch, flexdecrypt

Dump frameworks and extensions too, not just the main binary. PlugIns/ (share sheets, widgets, keyboards) and Frameworks/ carry their own encrypted Mach-Os, and app extensions frequently hold the interesting entitlements and a weaker security posture than the main app.

Mach-O Structure and Protections

bash
file TargetApp                       # thin or fat/universal
lipo -info TargetApp                 # architectures present
lipo -thin arm64 TargetApp -o app64  # extract one before analysis

otool -hv app64                      # header flags: PIE
otool -l app64 | rg 'LC_LOAD_DYLIB|LC_RPATH|LC_CODE_SIGNATURE|LC_ENCRYPTION'
otool -Iv app64 | head               # indirect symbols
nm -m app64 | rg -v ' U ' | head     # defined symbols

# Protections at a glance
otool -hv app64 | rg PIE             # ASLR
otool -Iv app64 | rg stack_chk       # stack canaries
otool -Iv app64 | rg objc_release    # ARC in use

Extract the entitlements — they define what the app is allowed to do and often reveal the interesting attack surface:

bash
codesign -d --entitlements :- TargetApp.app
# Look for: keychain-access-groups, App Groups, associated-domains,
# get-task-allow (debuggable!), custom URL scheme claims

get-task-allow set to true on a production build means the app is debuggable and is a finding on its own.

Objective-C

Objective-C keeps its full class metadata in the binary, so recovery is excellent — method names, selectors, class hierarchy, ivars.

bash
class-dump -H app64 -o ./headers        # classic
class-dump-dyld                          # for dyld shared cache resident classes
dsdump --objc --color app64              # modern alternative, handles Swift too

# Then read the type map
rg -l 'Manager|Service|API|Auth|Crypto|Keychain|Payment' ./headers | head -20

In a disassembler, Objective-C calls go through objc_msgSend, so the callee is a selector string in a register rather than a direct branch. Both IDA and Ghidra have plugins that resolve this; without them the call graph is largely useless.

Swift

Swift is harder. Names are mangled, and method dispatch is often static or through witness tables rather than objc_msgSend.

bash
# Demangle what you find
nm app64 | swift demangle
xcrun swift-demangle '$s10TargetApp11AuthManagerC5loginyyF'

# Swift type metadata lives in dedicated sections
otool -l app64 | rg '__swift5_types|__swift5_proto|__swift5_reflstr'
dsdump --swift app64

Practical approach for Swift-heavy apps: @objc and @objcMembers members still appear in the Objective-C metadata, so class-dump gives you a partial map. For the rest, work from string references and the reflection sections rather than trying to recover a full class list. Runtime enumeration with Frida is usually faster than static recovery:

bash
frida -U -f com.target.app -l enumerate-swift-classes.js

Runtime Analysis

bash
# Enumerate everything the runtime knows
objection -g com.target.app explore
#   ios hooking list classes
#   ios hooking search methods <keyword>
#   ios hooking watch method "-[AuthManager login:]" --dump-args --dump-return

# Direct Frida for anything objection does not cover
frida -U -f com.target.app -l hooks.js

Runtime beats static on iOS more often than on other platforms: the Objective-C runtime is introspectable, so listing classes and watching methods gets you to the logic faster than reading a disassembly of objc_msgSend dispatch.

Show full SKILL.md (253 more words)Show less

What to Look For

  • Entitlements over-provisioned — App Groups shared with less-trusted extensions, keychain groups shared too widely, get-task-allow in production
  • Hardcoded secrets in __cstring and in the plist files inside the bundle
  • Weak keychain accessibility — items stored with kSecAttrAccessibleAlways rather than a ThisDeviceOnly class
  • Custom crypto in the binary rather than CryptoKit/CommonCrypto
  • Debug and logging code left in release builds
  • Insecure WKWebView configuration — allowFileAccessFromFileURLs, loading remote content into a JS-bridged view
  • Third-party SDKs with their own network stacks and their own pinning behaviour; enumerate Frameworks/ and check each

Rationalizations to Reject

  • "class-dump returned nothing, the app is obfuscated." Check cryptid first. It is almost always encryption.
  • "I dumped the main binary, that's the app." Extensions and frameworks are separate Mach-Os with separate entitlements, and are frequently weaker.
  • "It's Swift, so nothing is recoverable." Reflection sections, @objc members, and string references recover a great deal. Enumerate at runtime.
  • "Static analysis is enough." On iOS the runtime is introspectable; skipping it costs more than it saves.
  • "The binary has PIE and canaries, so it's hardened." Those are compiler defaults, not evidence of a security review.
  • "I can't jailbreak, so I can't analyze." You can still read the bundle, plists, entitlements, and assets, and repackage with a Frida gadget for sideloading. Say what the constraint cost you in the report.

References

  • testing-mobile-applications — storage, keychain, IPC, and the wider iOS test
  • bypassing-root-jailbreak-detection — when detection blocks your tooling
  • bypassing-mobile-pinning — TLS interception on iOS stacks
  • analyzing-binaries — deeper native RE of the same Mach-O
  • frida-ios-dump, bagbak, class-dump, dsdump, objection, Hopper/IDA/Ghidra

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/analyzing-ios-binaries of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Analyzing iOS Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing iOS Binaries compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing iOS Binaries this skilltrilwu/secskills157—~2kAutomated safety check: PassMIT
Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC135—~12kAutomated safety check: PassApache-2.0
Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
iOS SecurityHoangNguyen0403/agent-skills-standard571—~500Automated safety check: PassMIT
App Store Reviewsafaiyeh/app-store-review-skill3661 repos~3.4kAutomated safety check: PassMIT
OdevioOdevio/Odevio-CLI423—~7.6kAutomated safety check: PassMIT

Similar skills

  • Mobile App Security Testing

    langbyyi/CyberStrikeAI-SRC

    移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…

    135 GitHub stars~12k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Performing iOS App Security Assessment

    mukul975/Anthropic-Cybersecurity-Skills

    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • iOS Security

    HoangNguyen0403/agent-skills-standard

    Secure iOS apps with secure storage, biometrics, and data protection.

    571 GitHub stars~500 tokensUpdated today
    MobileAuto-check passed
  • App Store Review

    safaiyeh/app-store-review-skill

    Evaluates code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill.

    366 GitHub starsUsed in 1 repo~3.4k tokens
    MobileAuto-check passed
  • Odevio

    Odevio/Odevio-CLI

    Take a Flutter project to an iPhone or the App Store with Odevio - build, sign and publish iOS apps from Windows, Linux or macOS with no Mac and no Xcode.

    423 GitHub stars~7.6k tokensUpdated 15 days ago
    MobileAuto-check passed
  • iOS App Store Submit

    ZestfulPulse/ios-app-store-submit

    Build, sign, and submit a Flutter/iOS app to the App Store Connect — covers Xcode archive/export, code signing (including headless-Mac keychain workarounds), the asc CLI for App Store Connect…

    142 GitHub stars~4.7k tokensUpdated 8 days ago
    MobileAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Malware

    trilwu/secskills

    Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.

    157 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Analyzing iOS Binaries

What does Analyzing iOS Binaries do?

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…. Analyzing iOS Binaries is an agent skill from trilwu/secskills. Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and reading Swift metadata.

When should I use Analyzing iOS Binaries?

Analyzing iOS Binaries fits situations like: working with an IPA; A downloaded App Store binary shows cryptid=1; class-dump returns nothing; analyzing iOS frameworks and app extensions.

How do I install Analyzing iOS Binaries in Claude Code?

Run `npx skills add trilwu/secskills --skill analyzing-ios-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/analyzing-ios-binaries in trilwu/secskills) into .claude/skills/analyzing-ios-binaries in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing iOS Binaries in Codex?

Run `npx skills add trilwu/secskills --skill analyzing-ios-binaries -a codex`. Or copy the skill folder (secskills-core/skills/analyzing-ios-binaries in trilwu/secskills) into .agents/skills/analyzing-ios-binaries in your project. Codex loads it when a task matches its description.

Can I use Analyzing iOS Binaries in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-ios-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-ios-binaries, .gemini/skills/analyzing-ios-binaries, .github/skills/analyzing-ios-binaries and .opencode/skills/analyzing-ios-binaries in your project.

What does Analyzing iOS Binaries need to run?

Going by SKILL.md and its folder, Analyzing iOS Binaries needs the command-line tools its instructions call (rg, swift and xcrun).

Does Analyzing iOS Binaries access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Analyzing iOS Binaries safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Analyzing iOS Binaries use?

Analyzing iOS Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing iOS Binaries use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Analyzing iOS Binaries?

Skills that share tags, products or a category with Analyzing iOS Binaries: Mobile App Security Testing (langbyyi/CyberStrikeAI-SRC, 135 stars), Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), iOS Security (HoangNguyen0403/agent-skills-standard, 571 stars) and App Store Review (safaiyeh/app-store-review-skill, 366 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing iOS Binaries?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.