Agent skill

Bypassing Root Jailbreak Detection

by trilwu in trilwu/secskills

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…

MITAuto-check passedSecurity

Install Bypassing Root Jailbreak Detection

skills CLI
$ npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills bypassing-root-jailbreak-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/bypassing-root-jailbreak-detection .claude/skills/bypassing-root-jailbreak-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bypassing-root-jailbreak-detection
GitHub stars
157
Token cost
~2.4k tokens
SKILL.md length
1,009 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…

  • Shows device not secure
  • SKILL.md covers When to Use, When NOT to Use, Identify the Layer First and Android, plus 6 more sections
  • Calls rg and adb
  • Silently fails on a rooted device

What it does

Bypassing Root Jailbreak Detection is an agent skill from trilwu/secskills. Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed attestation like Play Integrity cannot be hooked. Use when an app exits, shows "device not secure", or silently fails on a rooted device or emulator, or when Frida attaches and the app immediately dies.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security. It works with Frida. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Shows device not secure
  • Silently fails on a rooted device
  • Frida attaches and the app immediately dies

Example prompts

  • “device not secure”
  • “/bypassing-root-jailbreak-detection”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • adb

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bypassing Root Jailbreak Detection loads about 2.4k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 1,009 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,009 words, ~2,373 tokens.

Download SKILL.mdSave it as .claude/skills/bypassing-root-jailbreak-detection/SKILL.md (or your agent's skills folder).
name
bypassing-root-jailbreak-detection
description
Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed attestation like Play Integrity cannot be hooked. Use when an app exits, shows "device not secure", or silently fails on a rooted device or emulator, or when Frida attaches and the app immediately dies.
verified
2026-07-27

Bypassing Root and Jailbreak Detection

Detection is almost never one check. It is a dozen cheap checks scattered across the app, plus — increasingly — one hardware-backed attestation that no hook can touch. Hooking checks one at a time is whack-a-mole; the work is finding the layer the app actually depends on.

Use only against apps you are authorized to test.

When to Use

  • The app exits on launch, shows "rooted device detected", or degrades silently
  • The app works on a stock device but not on your test device or emulator
  • Frida attaches and the process dies immediately, or frida-ps shows nothing
  • objection fails to explore, or hooks stop firing after a few seconds
  • You need a stable instrumentation environment before any other testing

When NOT to Use

  • TLS interception failures — use bypassing-mobile-pinning; a proxy error is a different problem, though detection can masquerade as one
  • The wider assessment — use testing-mobile-applications
  • Framework-specific reversing — use the relevant reversing-* skill
  • Defeating DRM or licensing to pirate an app — out of scope

Identify the Layer First

Detection lives at four layers, and each needs a different response. Working out which one is firing saves the most time.

LayerSignalsResponse
Java/managed checksRootBeer, File.exists("/system/xbin/su"), package queries for MagiskHook at the Java layer (objection, Frida)
Native checks in .sostat/access/fopen on su, /proc/self/maps scansHook libc, or patch the .so
Instrumentation detectionDies only when Frida is attached; port 27042 probes; thread-name scansHide the agent, not the root
Hardware attestationPlay Integrity, SafetyNet, DeviceCheck, App AttestCannot be hooked — see below
bash
# What does the app reference? Decompile and look before hooking.
apktool d target.apk -o out
rg -n 'RootBeer|isRooted|su\b|magisk|superuser|test-keys|/system/xbin|busybox|xposed|frida' -i out/smali* out/res 2>/dev/null | head -30
rg -n 'SafetyNet|PlayIntegrity|IntegrityManager|attest|DeviceCheck' -i out/ | head

# Native side
unzip -j target.apk 'lib/arm64-v8a/*' -d libs
rg -a -o 'su|/system/bin/su|magisk|frida|gum-js-loop|gmain' libs/*.so | sort -u | head -20

The strings you find in the native libraries tell you what the app looks for, which is far more efficient than hooking blind and waiting for it to die.

Android

Start with environment hiding, not hooking. A well-hidden root defeats most detection without a single hook, and it does not break when the app updates.

bash
# Magisk: DenyList the target so the root is invisible to it
#   Settings → Zygisk ON, Enforce DenyList ON, select the target package
# Shamiko (Zygisk module) hides more thoroughly than DenyList alone
# Play Integrity Fix (PIF) module for the attestation layer — see limits below

# Verify what the app can see
adb shell "pm list packages | grep -i magisk"     # should return nothing to the app

Then hook what remains:

bash
objection -g com.target.app explore
# then: android root disable

frida -U -f com.target.app -l anti-root-bypass.js --no-pause

Common Java hook points, in the order they usually appear:

javascript
// File existence checks — the single most common family
Java.use('java.io.File').exists.implementation = function () {
  const p = this.getAbsolutePath();
  if (/su$|magisk|superuser|busybox|xposed/i.test(p)) return false;
  return this.exists();
};

// Runtime.exec("su") and ProcessBuilder
// Build.TAGS containing "test-keys"
// PackageManager.getPackageInfo for known root packages
// System properties: ro.debuggable, ro.secure, ro.build.selinux

Native checks need native hooks. When Java hooks are in place and the app still exits, the check is in a .so:

bash
# See which syscall is finding the evidence
frida-trace -U -f com.target.app -i 'stat*' -i 'access' -i 'fopen' -i 'open'
# then edit the generated handlers to lie about the paths it probes

Frida Detection Is a Separate Problem

If the app runs fine rooted but dies the moment you attach, you are fighting instrumentation detection, and hiding root will not help.

CheckCounter
TCP 27042 open, or the D-Bus handshake responseRun frida-server on a random port, or use Gadget instead of Server
/proc/self/maps contains frida-agent, gumRename the agent; use a patched build
Thread names gmain, gum-js-loop, pool-fridaPatched Frida builds rename these
/proc/self/task/*/stat scanningSame
Named pipes and re.frida.server stringsPatched build
Periodic re-check after launchAttach after the check window, or hook the timer

The practical answer is a patched Frida (community builds exist specifically for this) plus Gadget injection rather than a listening server. If detection still wins, fall back to static analysis plus targeted APK patching — you lose interactivity but keep progress.

iOS

bash
objection -g com.target.app explore
# then: ios jailbreak disable

# Tweak-based, system-wide: Liberty Lite, A-Bypass, Shadow (rootless jailbreaks)

What iOS apps check, and what to hide:

  • Existence of /Applications/Cydia.app, /bin/bash, /usr/sbin/sshd, /etc/apt, /private/var/lib/apt
  • Writability outside the sandbox (fopen("/private/jailbreak.txt", "w"))
  • fork() succeeding, which it should not in a sandboxed app
  • dyld image list containing MobileSubstrate / substitute
  • URL scheme cydia:// being openable
  • NSFileManager checks, which are easier to hook than raw stat

Hook stat, access, fopen, getenv("DYLD_INSERT_LIBRARIES"), and _dyld_get_image_name for the native layer; hook NSFileManager methods for the Objective-C layer. On non-jailbroken devices, repackage with the Frida gadget (objection patchipa) — and expect that to trip attestation.

Show full SKILL.md (439 more words)Show less

What You Cannot Hook

Hardware-backed attestation is the hard boundary. Play Integrity's MEETS_STRONG_INTEGRITY, key attestation via the TEE/StrongBox, and Apple's App Attest are signed by hardware keys and verified on the vendor's servers. A client-side hook can change what the app reads, but it cannot forge a signature the server validates.

What this means in practice:

  • Magisk plus a Play Integrity Fix module can often reach BASIC and DEVICE integrity. STRONG requires an unmodified bootloader.
  • If the app fails closed on strong integrity, the honest options are a non-rooted device with a repackaged app (which itself fails signature checks), a device with a stock ROM plus network-layer testing only, or agreeing an attestation exemption with the client for the test window.
  • Ask for the exemption. A test build with attestation disabled is a normal engagement request and is far cheaper than days spent losing to a TEE.

Say this in the report rather than quietly reducing scope: "dynamic instrumentation was not possible against production builds due to hardware attestation; testing covered X and not Y" is a finding about your coverage, and hiding it is worse than the limitation.

Detection Quality Is Itself a Finding

While bypassing, record how good the detection was — clients ask, and it belongs in the report:

  • Does it fail closed (exit) or fail open (log and continue)?
  • Is the check result sent to the server, or trusted locally? Local-only checks are advisory at best.
  • Is it one central function (trivially hooked) or distributed and re-checked?
  • Is hardware attestation used, or only filesystem heuristics?

An app whose entire root defense is File.exists("/system/xbin/su") deserves a low-severity note; one that uses server-verified attestation deserves credit.

Rationalizations to Reject

  • "objection's bypass didn't work, the detection is too strong." It covers the common Java checks. Look at the native layer next.
  • "I hid root, so it should work." If it dies only under Frida, you are fighting instrumentation detection, not root detection.
  • "Play Integrity can be bypassed with Frida." Not the hardware-backed verdicts. Hooks change what the app reads, not what the TEE signs.
  • "I'll patch every check I find." Distributed checks re-run. Find the central decision point, or hide the environment instead.
  • "Root detection is a vulnerability." It is a control, and a weak one. Its absence is a low-severity note, not a headline finding.
  • "I couldn't instrument it, so there's nothing to report." Report the coverage limitation explicitly.

References

  • testing-mobile-applications — the assessment this unblocks
  • bypassing-mobile-pinning — the other reason a mobile app "just fails"
  • analyzing-binaries — patching native detection routines
  • reporting-security-findings — how to state a coverage limitation honestly
  • Magisk + Zygisk, Shamiko, objection, Frida (and patched builds), Liberty Lite, Shadow

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-offense/skills/bypassing-root-jailbreak-detection of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Bypassing Root Jailbreak Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bypassing Root Jailbreak Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bypassing Root Jailbreak Detection this skilltrilwu/secskills157—~2.4kAutomated safety check: PassMIT
Frida Mobile Securityindex-login/MobileRE-Skill158—~3kAutomated safety check: PassMIT
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
Rev Unicorn Debugindex-login/MobileRE-Skill158—~1.9kAutomated safety check: PassMIT
Mira Article Updatervw2x/Mira105—~637Automated safety check: PassGPL-3.0
Rev Dex Dumperindex-login/MobileRE-Skill158—~1.9kAutomated safety check: PassMIT

Similar skills

  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.

    105 GitHub stars~637 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Rev Dex Dumper

    index-login/MobileRE-Skill

    Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

    105 GitHub stars~892 tokensUpdated 6 days ago
    SecurityAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Bypassing Root Jailbreak Detection

What does Bypassing Root Jailbreak Detection do?

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…. Bypassing Root Jailbreak Detection is an agent skill from trilwu/secskills. Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed attestation like Play Integrity cannot be hooked.

When should I use Bypassing Root Jailbreak Detection?

Bypassing Root Jailbreak Detection fits situations like: shows device not secure; silently fails on a rooted device; frida attaches and the app immediately dies.

How do I install Bypassing Root Jailbreak Detection in Claude Code?

Run `npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a claude-code`. Or copy the skill folder (secskills-offense/skills/bypassing-root-jailbreak-detection in trilwu/secskills) into .claude/skills/bypassing-root-jailbreak-detection in your project. Claude Code loads it when a task matches its description.

How do I install Bypassing Root Jailbreak Detection in Codex?

Run `npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a codex`. Or copy the skill folder (secskills-offense/skills/bypassing-root-jailbreak-detection in trilwu/secskills) into .agents/skills/bypassing-root-jailbreak-detection in your project. Codex loads it when a task matches its description.

Can I use Bypassing Root Jailbreak Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bypassing-root-jailbreak-detection, .gemini/skills/bypassing-root-jailbreak-detection, .github/skills/bypassing-root-jailbreak-detection and .opencode/skills/bypassing-root-jailbreak-detection in your project.

What does Bypassing Root Jailbreak Detection need to run?

Going by SKILL.md and its folder, Bypassing Root Jailbreak Detection needs the command-line tools its instructions call (rg and adb).

Does Bypassing Root Jailbreak Detection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bypassing Root Jailbreak Detection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bypassing Root Jailbreak Detection use?

Bypassing Root Jailbreak Detection is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bypassing Root Jailbreak Detection use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bypassing Root Jailbreak Detection?

Skills that share tags, products or a category with Bypassing Root Jailbreak Detection: Frida Mobile Security (index-login/MobileRE-Skill, 158 stars), Mira Risk Collect (vw2x/Mira, 105 stars), Rev Unicorn Debug (index-login/MobileRE-Skill, 158 stars) and Mira Article Updater (vw2x/Mira, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bypassing Root Jailbreak Detection?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.