Frida Mobile Security
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…
$ npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills bypassing-root-jailbreak-detection --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/bypassing-root-jailbreak-detection .claude/skills/bypassing-root-jailbreak-detection && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bypassing-root-jailbreak-detection" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-root-jailbreak-detection into .claude/skills/bypassing-root-jailbreak-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-root-jailbreak-detection", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-root-jailbreak-detectionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills bypassing-root-jailbreak-detection --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-offense/skills/bypassing-root-jailbreak-detection .agents/skills/bypassing-root-jailbreak-detection && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bypassing-root-jailbreak-detection" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-root-jailbreak-detection into .agents/skills/bypassing-root-jailbreak-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-root-jailbreak-detection", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills bypassing-root-jailbreak-detection --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-offense/skills/bypassing-root-jailbreak-detection .cursor/skills/bypassing-root-jailbreak-detection && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bypassing-root-jailbreak-detection" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-root-jailbreak-detection into .cursor/skills/bypassing-root-jailbreak-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-root-jailbreak-detection", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-offense/skills/bypassing-root-jailbreak-detection--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills bypassing-root-jailbreak-detection --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-offense/skills/bypassing-root-jailbreak-detection .gemini/skills/bypassing-root-jailbreak-detection && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bypassing-root-jailbreak-detection" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-root-jailbreak-detection into .gemini/skills/bypassing-root-jailbreak-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-root-jailbreak-detection", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills bypassing-root-jailbreak-detectionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-offense/skills/bypassing-root-jailbreak-detection .github/skills/bypassing-root-jailbreak-detection && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bypassing-root-jailbreak-detection" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-root-jailbreak-detection into .github/skills/bypassing-root-jailbreak-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-root-jailbreak-detection", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills bypassing-root-jailbreak-detection --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-offense/skills/bypassing-root-jailbreak-detection .opencode/skills/bypassing-root-jailbreak-detection && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bypassing-root-jailbreak-detection" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-root-jailbreak-detection into .opencode/skills/bypassing-root-jailbreak-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-root-jailbreak-detection", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bypassing-root-jailbreak-detectionDefeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…
Bypassing Root Jailbreak Detection is an agent skill from trilwu/secskills. Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed attestation like Play Integrity cannot be hooked. Use when an app exits, shows "device not secure", or silently fails on a rooted device or emulator, or when Frida attaches and the app immediately dies.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Mobile application security. It works with Frida. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgadbFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bypassing Root Jailbreak Detection loads about 2.4k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 1,009 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,009 words, ~2,373 tokens.
.claude/skills/bypassing-root-jailbreak-detection/SKILL.md (or your agent's skills folder).Detection is almost never one check. It is a dozen cheap checks scattered across the app, plus — increasingly — one hardware-backed attestation that no hook can touch. Hooking checks one at a time is whack-a-mole; the work is finding the layer the app actually depends on.
Use only against apps you are authorized to test.
frida-ps shows nothingobjection fails to explore, or hooks stop firing after a few secondsbypassing-mobile-pinning; a proxy error
is a different problem, though detection can masquerade as onetesting-mobile-applicationsreversing-* skillDetection lives at four layers, and each needs a different response. Working out which one is firing saves the most time.
| Layer | Signals | Response |
|---|---|---|
| Java/managed checks | RootBeer, File.exists("/system/xbin/su"), package queries for Magisk | Hook at the Java layer (objection, Frida) |
Native checks in .so | stat/access/fopen on su, /proc/self/maps scans | Hook libc, or patch the .so |
| Instrumentation detection | Dies only when Frida is attached; port 27042 probes; thread-name scans | Hide the agent, not the root |
| Hardware attestation | Play Integrity, SafetyNet, DeviceCheck, App Attest | Cannot be hooked — see below |
# What does the app reference? Decompile and look before hooking.
apktool d target.apk -o out
rg -n 'RootBeer|isRooted|su\b|magisk|superuser|test-keys|/system/xbin|busybox|xposed|frida' -i out/smali* out/res 2>/dev/null | head -30
rg -n 'SafetyNet|PlayIntegrity|IntegrityManager|attest|DeviceCheck' -i out/ | head
# Native side
unzip -j target.apk 'lib/arm64-v8a/*' -d libs
rg -a -o 'su|/system/bin/su|magisk|frida|gum-js-loop|gmain' libs/*.so | sort -u | head -20The strings you find in the native libraries tell you what the app looks for, which is far more efficient than hooking blind and waiting for it to die.
Start with environment hiding, not hooking. A well-hidden root defeats most detection without a single hook, and it does not break when the app updates.
# Magisk: DenyList the target so the root is invisible to it
# Settings → Zygisk ON, Enforce DenyList ON, select the target package
# Shamiko (Zygisk module) hides more thoroughly than DenyList alone
# Play Integrity Fix (PIF) module for the attestation layer — see limits below
# Verify what the app can see
adb shell "pm list packages | grep -i magisk" # should return nothing to the appThen hook what remains:
objection -g com.target.app explore
# then: android root disable
frida -U -f com.target.app -l anti-root-bypass.js --no-pauseCommon Java hook points, in the order they usually appear:
// File existence checks — the single most common family
Java.use('java.io.File').exists.implementation = function () {
const p = this.getAbsolutePath();
if (/su$|magisk|superuser|busybox|xposed/i.test(p)) return false;
return this.exists();
};
// Runtime.exec("su") and ProcessBuilder
// Build.TAGS containing "test-keys"
// PackageManager.getPackageInfo for known root packages
// System properties: ro.debuggable, ro.secure, ro.build.selinuxNative checks need native hooks. When Java hooks are in place and the app
still exits, the check is in a .so:
# See which syscall is finding the evidence
frida-trace -U -f com.target.app -i 'stat*' -i 'access' -i 'fopen' -i 'open'
# then edit the generated handlers to lie about the paths it probesIf the app runs fine rooted but dies the moment you attach, you are fighting instrumentation detection, and hiding root will not help.
| Check | Counter |
|---|---|
| TCP 27042 open, or the D-Bus handshake response | Run frida-server on a random port, or use Gadget instead of Server |
/proc/self/maps contains frida-agent, gum | Rename the agent; use a patched build |
Thread names gmain, gum-js-loop, pool-frida | Patched Frida builds rename these |
/proc/self/task/*/stat scanning | Same |
Named pipes and re.frida.server strings | Patched build |
| Periodic re-check after launch | Attach after the check window, or hook the timer |
The practical answer is a patched Frida (community builds exist specifically for this) plus Gadget injection rather than a listening server. If detection still wins, fall back to static analysis plus targeted APK patching — you lose interactivity but keep progress.
objection -g com.target.app explore
# then: ios jailbreak disable
# Tweak-based, system-wide: Liberty Lite, A-Bypass, Shadow (rootless jailbreaks)What iOS apps check, and what to hide:
/Applications/Cydia.app, /bin/bash, /usr/sbin/sshd,
/etc/apt, /private/var/lib/aptfopen("/private/jailbreak.txt", "w"))fork() succeeding, which it should not in a sandboxed appdyld image list containing MobileSubstrate / substitutecydia:// being openableNSFileManager checks, which are easier to hook than raw statHook stat, access, fopen, getenv("DYLD_INSERT_LIBRARIES"), and
_dyld_get_image_name for the native layer; hook NSFileManager methods for
the Objective-C layer. On non-jailbroken devices, repackage with the Frida
gadget (objection patchipa) — and expect that to trip attestation.
Hardware-backed attestation is the hard boundary. Play Integrity's
MEETS_STRONG_INTEGRITY, key attestation via the TEE/StrongBox, and Apple's
App Attest are signed by hardware keys and verified on the vendor's servers.
A client-side hook can change what the app reads, but it cannot forge a
signature the server validates.
What this means in practice:
BASIC and
DEVICE integrity. STRONG requires an unmodified bootloader.Say this in the report rather than quietly reducing scope: "dynamic instrumentation was not possible against production builds due to hardware attestation; testing covered X and not Y" is a finding about your coverage, and hiding it is worse than the limitation.
While bypassing, record how good the detection was — clients ask, and it belongs in the report:
An app whose entire root defense is File.exists("/system/xbin/su") deserves a
low-severity note; one that uses server-verified attestation deserves credit.
testing-mobile-applications — the assessment this unblocksbypassing-mobile-pinning — the other reason a mobile app "just fails"analyzing-binaries — patching native detection routinesreporting-security-findings — how to state a coverage limitation honestly© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-offense/skills/bypassing-root-jailbreak-detection of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Bypassing Root Jailbreak Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bypassing Root Jailbreak Detection this skilltrilwu/secskills | 157 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Frida Mobile Securityindex-login/MobileRE-Skill | 158 | — | ~3k | Automated safety check: Pass | MIT | |
| Mira Risk Collectvw2x/Mira | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | |
| Rev Unicorn Debugindex-login/MobileRE-Skill | 158 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Mira Article Updatervw2x/Mira | 105 | — | ~637 | Automated safety check: Pass | GPL-3.0 | |
| Rev Dex Dumperindex-login/MobileRE-Skill | 158 | — | ~1.9k | Automated safety check: Pass | MIT |
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
index-login/MobileRE-Skill
Debug and emulate specific code fragments or functions using the Unicorn engine.
vw2x/Mira
Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.
index-login/MobileRE-Skill
Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.
vw2x/Mira
Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Categories
Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…. Bypassing Root Jailbreak Detection is an agent skill from trilwu/secskills. Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed attestation like Play Integrity cannot be hooked.
Bypassing Root Jailbreak Detection fits situations like: shows device not secure; silently fails on a rooted device; frida attaches and the app immediately dies.
Run `npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a claude-code`. Or copy the skill folder (secskills-offense/skills/bypassing-root-jailbreak-detection in trilwu/secskills) into .claude/skills/bypassing-root-jailbreak-detection in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a codex`. Or copy the skill folder (secskills-offense/skills/bypassing-root-jailbreak-detection in trilwu/secskills) into .agents/skills/bypassing-root-jailbreak-detection in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill bypassing-root-jailbreak-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bypassing-root-jailbreak-detection, .gemini/skills/bypassing-root-jailbreak-detection, .github/skills/bypassing-root-jailbreak-detection and .opencode/skills/bypassing-root-jailbreak-detection in your project.
Going by SKILL.md and its folder, Bypassing Root Jailbreak Detection needs the command-line tools its instructions call (rg and adb).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bypassing Root Jailbreak Detection is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bypassing Root Jailbreak Detection: Frida Mobile Security (index-login/MobileRE-Skill, 158 stars), Mira Risk Collect (vw2x/Mira, 105 stars), Rev Unicorn Debug (index-login/MobileRE-Skill, 158 stars) and Mira Article Updater (vw2x/Mira, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.