Agent skill

Mira Detection Distill

by vw2x in vw2x/Mira

Route Mira detection findings into a reusable knowledge pipeline.

GPL-3.0Auto-check passedSecurity

Install Mira Detection Distill

skills CLI
$ npx skills add vw2x/Mira --skill mira-detection-distill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vw2x/Mira mira-detection-distill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vw2x/Mira.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mira-detection-distill .claude/skills/mira-detection-distill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mira-detection-distill
GitHub stars
105
Token cost
~1.1k tokens
SKILL.md length
589 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
GPL-3.0

At a glance

Route Mira detection findings into a reusable knowledge pipeline.

  • Works in 4 steps: Triage the request → Confirm topic dynamically → Route to the correct execution skill → …
  • Codex needs to turn a new detection clue
  • SKILL.md covers Overview, Core Contract, Workflow and Output Rules, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Mira Detection Distill is an agent skill from vw2x/Mira. Route Mira detection findings into a reusable knowledge pipeline. Use when Codex needs to turn a new detection clue, risk-environment observation, or research note into topic confirmation, case capture, topic maintenance, and article update suggestions inside the Mira repository.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Mobile application security. It works with Frida. The repository describes itself as: Mobile runtime detection workbench for AI (iOS and Android). The licence is GPL-3.0.

When your agent uses it

  • Codex needs to turn a new detection clue
  • Risk-environment observation
  • Research note into topic confirmation
  • Topic maintenance

Example prompts

  • “/mira-detection-distill”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Triage the request
  2. Confirm topic dynamically
  3. Route to the correct execution skill
  4. Produce explicit next actions

What it can do on your machine

Read from SKILL.md and the folder at commit b744801. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mira Detection Distill loads about 1.1k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 589 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vw2x/Mira at commit b744801, republished under its GPL-3.0 licence (© vw2x). 589 words, ~1,137 tokens.

Download SKILL.mdSave it as .claude/skills/mira-detection-distill/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
mira-detection-distill
description
Route Mira detection findings into a reusable knowledge pipeline. Use when Codex needs to turn a new detection clue, risk-environment observation, or research note into topic confirmation, case capture, topic maintenance, and article update suggestions inside the Mira repository.

Mira Detection Distill

Overview

Use this skill as the entry point for Mira detection knowledge work. Do not predefine topic trees. Start from the user's current clue, object, phenomenon, or draft note. Always confirm topic dynamically before creating or updating topic assets.

Core Contract

Investigation is local-first: keep experiments, raw evidence, trial scripts and draft reports in Git-ignored reports/local/<investigation>/. Testing or topic confirmation does not authorize tracked case/article/tool creation. Apply the local-versus-promotion boundary in $mira-case-capture; the output paths and script routing below apply only after the user explicitly requests promotion of selected material.

Treat the pipeline as four layers:

  1. case for one concrete detection record.
  2. topic for one evolving research theme.
  3. pattern for reusable judgment distilled from multiple cases.
  4. article for English-first publication drafts and Chinese adaptations.

Do not merge these layers into one artifact. Do not write article prose into case files. Do not turn skill instructions into article text.

Workflow

1. Triage the request

Classify the current task as one of:

  1. new case capture.
  2. existing topic update.
  3. article update suggestion.
  4. mixed request spanning multiple layers.
2. Confirm topic dynamically

Never invent a permanent topic silently. Ask for topic confirmation using the minimum needed prompt. Base the suggestion on the current material only.

When the user has not named a topic, provide 1 to 3 candidate topic directions:

  1. the most likely topic suggestion.
  2. why it fits.
  3. how it differs from adjacent directions.
  4. whether creating a new topic is justified.

Wait for user confirmation before creating or updating knowledge/topics/<topic-slug>/.

3. Route to the correct execution skill

Use:

  1. $mira-case-capture for one concrete case.
  2. $mira-topic-maintainer after topic confirmation.
  3. $mira-article-updater when the user wants article updates, or when enough new material may justify article changes.
4. Produce explicit next actions

Always end with the smallest useful next step. Examples:

  1. confirm topic.
  2. capture case only.
  3. update topic and backlog.
  4. suggest article delta only.
Show full SKILL.md (261 more words)Show less

Output Rules

Keep outputs separate by path:

  1. knowledge/cases/en/YYYY/... and knowledge/cases/zh/YYYY/... for bilingual case records.
  2. knowledge/topics/<topic-slug>/... for topic assets.
  3. knowledge/articles/en/<topic-slug>.md for English-first drafts.
  4. knowledge/articles/zh/<topic-slug>.md for Chinese adaptations.
  5. reusable scripts under the closest existing tooling path, such as tools/android/..., plus case-specific executable snapshots under knowledge/cases/artifacts/YYYY/ when needed for reproduction.

When context is incomplete, do not emit a fake template. Instead, state what is missing and preserve the pipeline state.

Script Artifact Routing

When a detection finding includes a reusable shell script or command harness:

  1. create or update the maintained script artifact in the appropriate tools path.
  2. store the validated script snapshot under knowledge/cases/artifacts/YYYY/ when the script is central to reproducing the case.
  3. capture execution semantics in both English and Chinese case records, including how to run it inside Mira.
  4. link the script from any topic pattern that depends on it.
  5. keep articles focused on method and boundaries, not full script dumps, unless the article is explicitly script-centered.
  6. preserve known-bad invocation forms and parameter pitfalls as case evidence.

Dynamic Topic Protocol

Use this short protocol whenever topic is unclear:

  1. state the current signal in one sentence.
  2. propose up to 3 topic directions.
  3. explain each direction with one discriminator.
  4. ask the user to confirm or rename the topic.

Quality Bar

Before finishing, verify:

  1. topic was not predefined without confirmation.
  2. case, topic, pattern, and article responsibilities stayed separate.
  3. at least one reusable judgment or next-check idea was surfaced.
  4. the response kept the English-first publication strategy in mind.

© vw2x, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/mira-detection-distill of vw2x/Mira.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit b744801

Compare with similar skills

Mira Detection Distill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mira Detection Distill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mira Detection Distill this skillvw2x/Mira105—~1.1kAutomated safety check: PassGPL-3.0
Frida Mobile Securityindex-login/MobileRE-Skill158—~3kAutomated safety check: PassMIT
Rev Unicorn Debugindex-login/MobileRE-Skill158—~1.9kAutomated safety check: PassMIT
Rev Dex Dumperindex-login/MobileRE-Skill158—~1.9kAutomated safety check: PassMIT
Apk Reversingzhaji2333/CkSKILLS115—~1.7kAutomated safety check: PassMIT
Karpathy Guidelinesindex-login/MobileRE-Skill158—~242Automated safety check: PassMIT

Similar skills

  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Rev Dex Dumper

    index-login/MobileRE-Skill

    Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Apk Reversing

    zhaji2333/CkSKILLS

    当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

    115 GitHub stars~1.7k tokensUpdated 26 days ago
    SecurityAuto-check passed
  • Karpathy Guidelines

    index-login/MobileRE-Skill

    减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

    158 GitHub stars~242 tokensUpdated yesterday
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    312 GitHub stars~1.2k tokensUpdated 21 days ago
    SecurityAuto-check passed

More from vw2x/Mira

  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 6 days ago
    Auto-check passed
  • Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.

    105 GitHub stars~637 tokensUpdated 6 days ago
    Auto-check passed
  • Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

    105 GitHub stars~892 tokensUpdated 6 days ago
    Auto-check passed
  • Maintain a Mira detection topic after user confirmation. An agent skill from vw2x/Mira.

    105 GitHub stars~575 tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Mira Detection Distill

What does Mira Detection Distill do?

Route Mira detection findings into a reusable knowledge pipeline. Mira Detection Distill is an agent skill from vw2x/Mira. Route Mira detection findings into a reusable knowledge pipeline.

When should I use Mira Detection Distill?

Mira Detection Distill fits situations like: Codex needs to turn a new detection clue; risk-environment observation; research note into topic confirmation; topic maintenance.

How do I install Mira Detection Distill in Claude Code?

Run `npx skills add vw2x/Mira --skill mira-detection-distill -a claude-code`. Or copy the skill folder (skills/mira-detection-distill in vw2x/Mira) into .claude/skills/mira-detection-distill in your project. Claude Code loads it when a task matches its description.

How do I install Mira Detection Distill in Codex?

Run `npx skills add vw2x/Mira --skill mira-detection-distill -a codex`. Or copy the skill folder (skills/mira-detection-distill in vw2x/Mira) into .agents/skills/mira-detection-distill in your project. Codex loads it when a task matches its description.

Can I use Mira Detection Distill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vw2x/Mira --skill mira-detection-distill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mira-detection-distill, .gemini/skills/mira-detection-distill, .github/skills/mira-detection-distill and .opencode/skills/mira-detection-distill in your project.

What does Mira Detection Distill need to run?

SKILL.md names no scripts, command-line tools or credentials: Mira Detection Distill is instructions for the agent only.

Does Mira Detection Distill access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mira Detection Distill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mira Detection Distill use?

Mira Detection Distill is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mira Detection Distill use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mira Detection Distill?

Skills that share tags, products or a category with Mira Detection Distill: Frida Mobile Security (index-login/MobileRE-Skill, 158 stars), Rev Unicorn Debug (index-login/MobileRE-Skill, 158 stars), Rev Dex Dumper (index-login/MobileRE-Skill, 158 stars) and Apk Reversing (zhaji2333/CkSKILLS, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mira Detection Distill?

vw2x (a GitHub user) maintains it in vw2x/Mira, which has 105 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 5, 2026.

Source: vw2x/Mira on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.