Agent skill

Mira Case Capture

by vw2x in vw2x/Mira

Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

GPL-3.0Auto-check passedSecurity

Install Mira Case Capture

skills CLI
$ npx skills add vw2x/Mira --skill mira-case-capture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vw2x/Mira mira-case-capture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vw2x/Mira.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mira-case-capture .claude/skills/mira-case-capture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mira-case-capture
GitHub stars
105
Token cost
~892 tokens
SKILL.md length
421 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
GPL-3.0

At a glance

Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

  • Works in 4 steps: Select validated, reproducible findings… → Exclude raw dumps, transient logs,… → Keep observations, supported… → …
  • Explicitly requests promotion into a report
  • SKILL.md covers Default: local investigation, Promotion: only selected,… and Verification
  • Calls git

What it does

Mira Case Capture is an agent skill from vw2x/Mira. Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

Its SKILL.md is about 890 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Knowledge bases and Mobile application security. It works with Frida. The repository describes itself as: Mobile runtime detection workbench for AI (iOS and Android). The licence is GPL-3.0.

When your agent uses it

  • Explicitly requests promotion into a report
  • The knowledge repository

Example prompts

  • “/mira-case-capture”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Select validated, reproducible findings covered by the request.
  2. Exclude raw dumps, transient logs, timestamps/instance values, tool chatter, speculative claims, duplicates, and unrelated failures…
  3. Keep observations, supported interpretation, and remaining uncertainty distinct. Document false positives and measurement-tool artifacts.
  4. Include enough method to reproduce: script path, invocation, environment, parameters, known limitations, and a minimal verification…

What it can do on your machine

Read from SKILL.md and the folder at commit b744801. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mira Case Capture loads about 892 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 421 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~892

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vw2x/Mira at commit b744801, republished under its GPL-3.0 licence (© vw2x). 421 words, ~892 tokens.

Download SKILL.mdSave it as .claude/skills/mira-case-capture/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
mira-case-capture
description
Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

Mira Case Capture

Default: local investigation

Testing, exploring a device, collecting evidence, and asking for a summary do not authorize promotion into the knowledge repository.

Write working notes, command output, screenshots, scripts, failed attempts, and draft reports under reports/local/<YYYY-MM-DD>-<investigation>/. Verify this path is Git-ignored before writing. Preserve relative subdirectories when moving an existing investigation so its links remain usable. Do not stage, commit, or push these files.

Do not create files in knowledge/cases/, knowledge/topics/, knowledge/articles/, or maintained tools/ merely because an experiment is interesting or succeeds. Experimental scripts stay beside local evidence. Ordinary product fixes explicitly requested by the user are separate from this evidence-staging rule.

Capture only what the investigation needs: the tested object, app identity and permission context, commands or script snapshots, exact invocation and parameters, observations, failures, and unresolved questions. Distinguish observations from interpretation. No mandatory bilingual draft or large template during testing. Redact credentials and unnecessary device/instance identifiers.

Promotion: only selected, authorized material

Promote when the user explicitly asks to distill specified findings into a report, case, or the knowledge repository. Confirmation of a research topic, permission to test, or a request to continue is not promotion authorization. If selected material is clear, proceed without asking again; otherwise keep work local and clarify the scope.

Before writing the tracked case:

  1. Select validated, reproducible findings covered by the request.
  2. Exclude raw dumps, transient logs, timestamps/instance values, tool chatter, speculative claims, duplicates, and unrelated failures. Include a failure only when it explains a method's reliability or a likely misinterpretation.
  3. Keep observations, supported interpretation, and remaining uncertainty distinct. Document false positives and measurement-tool artifacts.
  4. Include enough method to reproduce: script path, invocation, environment, parameters, known limitations, and a minimal verification. Promote a maintained script only if requested or necessary for the authorized case. Never embed detector logic into Mira App components.
Show full SKILL.md (115 more words)Show less

Write English and Chinese cases under knowledge/cases/en/YYYY/YYYY-MM-DD-<slug>.md and knowledge/cases/zh/YYYY/YYYY-MM-DD-<slug>.md. Only small, necessary executable snapshots belong in knowledge/cases/artifacts/YYYY/; raw investigation evidence remains local. Use the existing tooling directory for an authorized reusable script.

A promoted case should explain the detection object, initial suspicion, topic status, key clues, validation, result, false-positive risks, reusable judgment, remaining checks, and related articles when relevant. Do not invent a confirmed topic or article. Avoid full article prose and empty fields.

Verification

  • Local-only investigation: git status --short must not list its working artifacts; git check-ignore must confirm the destination.
  • Promotion: every tracked finding fits the authorized scope, is useful without the conversation, and links to reproducible methods without requiring unavailable local dumps.

© vw2x, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/mira-case-capture of vw2x/Mira.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit b744801

Compare with similar skills

Mira Case Capture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mira Case Capture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mira Case Capture this skillvw2x/Mira105—~892Automated safety check: PassGPL-3.0
Frida Mobile Securityindex-login/MobileRE-Skill152—~3kAutomated safety check: PassMIT
Rev Unicorn Debugindex-login/MobileRE-Skill152—~1.9kAutomated safety check: PassMIT
Rev Dex Dumperindex-login/MobileRE-Skill152—~1.9kAutomated safety check: PassMIT
Apk Reversingzhaji2333/CkSKILLS115—~1.7kAutomated safety check: PassMIT
Karpathy Guidelinesindex-login/MobileRE-Skill152—~242Automated safety check: PassMIT

Similar skills

  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    152 GitHub stars~3k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    152 GitHub stars~1.9k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Rev Dex Dumper

    index-login/MobileRE-Skill

    Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

    152 GitHub stars~1.9k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Apk Reversing

    zhaji2333/CkSKILLS

    当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

    115 GitHub stars~1.7k tokensUpdated 26 days ago
    SecurityAuto-check passed
  • Karpathy Guidelines

    index-login/MobileRE-Skill

    减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

    152 GitHub stars~242 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    312 GitHub stars~1.2k tokensUpdated 20 days ago
    SecurityAuto-check passed

More from vw2x/Mira

  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 6 days ago
    Auto-check passed
  • Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.

    105 GitHub stars~637 tokensUpdated 6 days ago
    Auto-check passed
  • Route Mira detection findings into a reusable knowledge pipeline.

    105 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Maintain a Mira detection topic after user confirmation. An agent skill from vw2x/Mira.

    105 GitHub stars~575 tokensUpdated 6 days ago
    Auto-check passed

Works with

Questions about Mira Case Capture

What does Mira Case Capture do?

Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository. Mira Case Capture is an agent skill from vw2x/Mira. Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

When should I use Mira Case Capture?

Mira Case Capture fits situations like: explicitly requests promotion into a report; the knowledge repository.

How do I install Mira Case Capture in Claude Code?

Run `npx skills add vw2x/Mira --skill mira-case-capture -a claude-code`. Or copy the skill folder (skills/mira-case-capture in vw2x/Mira) into .claude/skills/mira-case-capture in your project. Claude Code loads it when a task matches its description.

How do I install Mira Case Capture in Codex?

Run `npx skills add vw2x/Mira --skill mira-case-capture -a codex`. Or copy the skill folder (skills/mira-case-capture in vw2x/Mira) into .agents/skills/mira-case-capture in your project. Codex loads it when a task matches its description.

Can I use Mira Case Capture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vw2x/Mira --skill mira-case-capture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mira-case-capture, .gemini/skills/mira-case-capture, .github/skills/mira-case-capture and .opencode/skills/mira-case-capture in your project.

What does Mira Case Capture need to run?

Going by SKILL.md and its folder, Mira Case Capture needs the command-line tools its instructions call (git).

Does Mira Case Capture access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Mira Case Capture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mira Case Capture use?

Mira Case Capture is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mira Case Capture use?

About 892 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mira Case Capture?

Skills that share tags, products or a category with Mira Case Capture: Frida Mobile Security (index-login/MobileRE-Skill, 152 stars), Rev Unicorn Debug (index-login/MobileRE-Skill, 152 stars), Rev Dex Dumper (index-login/MobileRE-Skill, 152 stars) and Apk Reversing (zhaji2333/CkSKILLS, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mira Case Capture?

vw2x (a GitHub user) maintains it in vw2x/Mira, which has 105 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 5, 2026.

Source: vw2x/Mira on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.