Agent skill

Mira Risk Collect

by vw2x in vw2x/Mira

Run Mira environment risk collection. An agent skill from vw2x/Mira.

GPL-3.0Auto-check passedSecurity

Install Mira Risk Collect

skills CLI
$ npx skills add vw2x/Mira --skill mira-risk-collect -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vw2x/Mira mira-risk-collect --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vw2x/Mira.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mira-risk-collect .claude/skills/mira-risk-collect && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mira-risk-collect
GitHub stars
105
Token cost
~793 tokens
SKILL.md length
409 words
Files
3 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
GPL-3.0

At a glance

Run Mira environment risk collection. An agent skill from vw2x/Mira.

  • Works in 6 steps: Identify target platform and available… → Capture low-risk baseline context. → Collect risk surfaces relevant to the… → …
  • The user says /collect
  • SKILL.md covers Overview, Workflow, Output Shape and Tool Guidance, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Mira Risk Collect is an agent skill from vw2x/Mira. Run Mira environment risk collection. Use when the user says /collect, asks to collect or review device environment risks, wants automatic analysis of Android/iOS/Mira runtime signals, or wants to turn fresh Mira observations into reusable risk clues and follow-up checks.

Its SKILL.md is about 790 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/risk-surfaces.md`).

It sits in Security, covering Mobile application security and MCP servers. It works with iOS, Android and Frida. The repository describes itself as: Mobile runtime detection workbench for AI (iOS and Android). The licence is GPL-3.0.

When your agent uses it

  • The user says /collect
  • Asks to collect
  • Review device environment risks
  • Wants automatic analysis of Android/iOS/Mira runtime signals

Example prompts

  • “/mira-risk-collect”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify target platform and available connector.
  2. Capture low-risk baseline context.
  3. Collect risk surfaces relevant to the current platform.
  4. Separate observations from interpretation.
  5. Produce a risk summary.
  6. Capture durable cases when a concrete signal is found.

What it can do on your machine

Read from SKILL.md and the folder at commit b744801. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mira Risk Collect loads about 793 tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 73 tokens; SKILL.md has 409 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~793
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vw2x/Mira at commit b744801, republished under its GPL-3.0 licence (© vw2x). 409 words, ~793 tokens.

Download SKILL.mdSave it as .claude/skills/mira-risk-collect/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
mira-risk-collect
description
Run Mira environment risk collection. Use when the user says /collect, asks to collect or review device environment risks, wants automatic analysis of Android/iOS/Mira runtime signals, or wants to turn fresh Mira observations into reusable risk clues and follow-up checks.

Mira Risk Collect

Overview

Use this skill to turn the current Mira-connected environment into a compact risk assessment. Prefer evidence-first collection over broad speculation. Treat /collect as the canonical user shorthand for this workflow.

Workflow

  1. Identify target platform and available connector.
    • Prefer Mira MCP tools when a device is connected.
    • If no device connector is available, inspect local repository state and provide a blocked collection plan.
  2. Capture low-risk baseline context.
    • Device identity, OS version, ABI, app package or bundle, current screen, focused app, and Mira install/session state.
    • Frida status only as environment context unless the user asks for deeper runtime instrumentation.
  3. Collect risk surfaces relevant to the current platform.
    • Read references/risk-surfaces.md before deciding checks.
    • Run only checks that are supported by the available device primitives.
  4. Separate observations from interpretation.
    • Use observed, implies, and needsVerification fields in the final answer.
  5. Produce a risk summary.
    • Group findings as confirmed, suspected, noise, and nextChecks.
    • Include exact commands or Mira tool calls only when they are useful for reproduction.
  6. Capture durable cases when a concrete signal is found.
    • Use mira-case-capture if a finding should be saved under knowledge/cases.
    • Do not create a case for generic absence of risk.

Output Shape

Return Chinese output with these sections:

  1. 采集范围.
  2. 已观察到的信号.
  3. 风险判断.
  4. 噪音与误判可能.
  5. 建议的下一步检查.
  6. 是否值得沉淀为 case.

Keep each item evidence-backed. Do not overclaim root, jailbreak, hook, emulator, or tamper status without a supporting signal.

Show full SKILL.md (170 more words)Show less

Tool Guidance

When Mira MCP tools are available:

  1. Use device listing or current-device selection first.
  2. Use screen state before shell checks when the user is asking about UI behavior.
  3. Use shell checks for environment state, filesystem clues, process state, logcat, SELinux, Magisk, emulator, and input-event surfaces.
  4. Keep iOS sessions long-lived; avoid frequent PTY reopen.
  5. Prefer one batched Android shell script for related checks instead of many tiny commands.

When only the repository is available:

  1. Inspect tools/android, tools/ios, knowledge/cases, and relevant docs.
  2. Report which checks can be run later on-device.
  3. If a new reusable check is obvious, propose or implement it as a script under tools/android or tools/ios.

Quality Bar

Before finishing, verify:

  1. Every risk has direct evidence or is explicitly marked as a hypothesis.
  2. Every unsupported claim has a next verification step.
  3. The final answer is short enough to be used as an operator note.
  4. Any durable finding is routed toward mira-case-capture rather than buried only in chat.

© vw2x, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/mira-risk-collect of vw2x/Mira.

  • SKILL.md
  • agents/openai.yaml
  • references/risk-surfaces.md

Open the folder on GitHubat commit b744801

Compare with similar skills

Mira Risk Collect next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mira Risk Collect compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mira Risk Collect this skillvw2x/Mira105—~793Automated safety check: PassGPL-3.0
Frida Mobile Securityindex-login/MobileRE-Skill158—~3kAutomated safety check: PassMIT
R0crawl Skillsmanyuegong33/r0crawl_skills312—~1.2kAutomated safety check: PassNone
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Offensive MobileSnailSploit/Claude-Red7.4k—~3.5kAutomated safety check: PassMIT
Mobile Securitytransilienceai/communitytools563—~2.5kAutomated safety check: PassMIT

Similar skills

  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    312 GitHub stars~1.2k tokensUpdated 21 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.4k GitHub stars~3.5k tokensUpdated 21 days ago
    SecurityAuto-check passed
  • Mobile Security

    transilienceai/communitytools

    Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

    563 GitHub stars~2.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Re Frida

    dslsdzc/rev-skills

    Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.

    135 GitHub stars~2.8k tokensUpdated 6 days ago
    SecurityAuto-check passed

More from vw2x/Mira

  • Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.

    105 GitHub stars~637 tokensUpdated 6 days ago
    Auto-check passed
  • Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

    105 GitHub stars~892 tokensUpdated 6 days ago
    Auto-check passed
  • Route Mira detection findings into a reusable knowledge pipeline.

    105 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Maintain a Mira detection topic after user confirmation. An agent skill from vw2x/Mira.

    105 GitHub stars~575 tokensUpdated 6 days ago
    Auto-check passed

Works with

Questions about Mira Risk Collect

What does Mira Risk Collect do?

Run Mira environment risk collection. An agent skill from vw2x/Mira. Mira Risk Collect is an agent skill from vw2x/Mira. Run Mira environment risk collection.

When should I use Mira Risk Collect?

Mira Risk Collect fits situations like: the user says /collect; asks to collect; review device environment risks; wants automatic analysis of Android/iOS/Mira runtime signals.

How do I install Mira Risk Collect in Claude Code?

Run `npx skills add vw2x/Mira --skill mira-risk-collect -a claude-code`. Or copy the skill folder (skills/mira-risk-collect in vw2x/Mira) into .claude/skills/mira-risk-collect in your project. Claude Code loads it when a task matches its description.

How do I install Mira Risk Collect in Codex?

Run `npx skills add vw2x/Mira --skill mira-risk-collect -a codex`. Or copy the skill folder (skills/mira-risk-collect in vw2x/Mira) into .agents/skills/mira-risk-collect in your project. Codex loads it when a task matches its description.

Can I use Mira Risk Collect in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vw2x/Mira --skill mira-risk-collect -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mira-risk-collect, .gemini/skills/mira-risk-collect, .github/skills/mira-risk-collect and .opencode/skills/mira-risk-collect in your project.

What does Mira Risk Collect need to run?

SKILL.md names no scripts, command-line tools or credentials: Mira Risk Collect is instructions for the agent only.

Does Mira Risk Collect access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mira Risk Collect safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mira Risk Collect use?

Mira Risk Collect is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mira Risk Collect use?

About 793 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 568 tokens, read only when the agent opens those files.

What are the alternatives to Mira Risk Collect?

Skills that share tags, products or a category with Mira Risk Collect: Frida Mobile Security (index-login/MobileRE-Skill, 158 stars), R0crawl Skills (manyuegong33/r0crawl_skills, 312 stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars) and Offensive Mobile (SnailSploit/Claude-Red, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mira Risk Collect?

vw2x (a GitHub user) maintains it in vw2x/Mira, which has 105 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 5, 2026.

Source: vw2x/Mira on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.