Agent skill

Apk Reversing

by zhaji2333 in zhaji2333/CkSKILLS

当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

MITAuto-check passedSecurity

Install Apk Reversing

skills CLI
$ npx skills add zhaji2333/CkSKILLS --skill apk-reversing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhaji2333/CkSKILLS apk-reversing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/apk-reversing .claude/skills/apk-reversing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
apk-reversing
GitHub stars
115
Token cost
~1.7k tokens
SKILL.md length
393 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

  • Tasks that involve Mobile application security
  • SKILL.md covers 何时调用(触发条件), 标准产物(交付标准), 一、APK 获取 and 二、壳识别(先识别再脱壳), plus 7 more sections
  • Calls adb, claude and brew

What it does

Apk Reversing is an agent skill from zhaji2333/CkSKILLS. 当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是 stub/空壳、入口类是 com.stub.StubApp、lib 下只有壳 so、需要还原真实代码后再挖洞。

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security. It works with Java, Frida and Ghidra. The repository describes itself as: 基于 Claude Code / Codex 的 SRC 漏洞挖掘 Agent 技能体系 —— 将顶尖安全研究员的方法论沉淀为可调度、可复用的 Skill 知识资产。 The licence is MIT.

When your agent uses it

  • Tasks that involve Mobile application security

Example prompts

  • “/apk-reversing”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 482fe78. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb
    • claude
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Apk Reversing loads about 1.7k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 393 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhaji2333/CkSKILLS at commit 482fe78, republished under its MIT licence (© zhaji2333). 393 words, ~1,720 tokens.

Download SKILL.mdSave it as .claude/skills/apk-reversing/SKILL.md (or your agent's skills folder).
name
apk-reversing
description
当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是 stub/空壳、入口类是 com.stub.StubApp、lib 下只有壳 so、需要还原真实代码后再挖洞。

apk-reversing — APK 脱壳与全量反编译还原

定位:这是 android-security-audit 的上游准备技能——把 APK 变成"可挖的全量源码",交付标准目录后 android-security-audit 直接开挖(密钥追踪/组件安全)。本技能只负责还原,不挖洞;漏洞挖掘见 android-security-audit。

只有 APK 有加固壳时才必须完整走本技能;无壳 APK 直接 JADX 反编译即可开工。

快筛前置(省时):无壳大包(>100MB)可先用 asc-fast-hunt 秒级快筛(Manifest 组件面 + 密钥/签名/接口定位),确认值得深挖再付全量反编译成本;已知有壳则直接走本技能——壳包的 DEX 里只有 stub,用 ASC 搜不出东西属正常现象,不要误判为"没有密钥"。

何时调用(触发条件)

  • 拿到 APK 但 JADX 打开是 stub/空壳、看不到真实代码
  • 入口类是 com.stub.StubApp / com.secneo.apkwrapper 等加固特征类
  • lib/ 下只有壳 so(libshella、libjiagu、libSecShell 等)
  • 需要提取 so、H5/assets、资源、签名等全量产物
  • 为 android-security-audit 准备标准输入(jadx_out/ + apktool_out/ + lib/ + assets/)
  • 无壳但包很大(>100MB),想先快筛再决定是否值得全量还原 → 先走 asc-fast-hunt(秒级定位密钥/接口)

标准产物(交付标准)

reversing/<package>/
├── jadx_out/          # Java 源码(JADX 反编译,必须是真实代码而非 stub)
├── apktool_out/       # smali + 资源 + AndroidManifest(apktool)
├── dex/               # 脱壳后的 dex(未合并进 jadx 时单独留档)
├── lib/               # 全部 so(arm64-v8a 优先,可 IDA/Ghidra 打开)
├── assets/            # H5/JS/证书/密钥/配置等资源
├── origin.apk         # 原始 APK 存档
└── report.md          # 壳类型 / 脱壳方式 / 产物清单 / 未还原项

交付检查:jadx_out 里能 grep 到真实特征串(appKey/secret/接口域名)、lib/ 的 so 可被 IDA/Ghidra 打开搜导出表、assets/ 的 H5 完整——满足即交付 android-security-audit。


一、APK 获取

bash
# 已安装设备上提取
adb shell pm list packages | grep <关键词>            # 找包名
adb shell pm path <package>                           # 拿到 APK 路径
adb pull <路径> origin.apk                            # 拉取

# 模拟器/真机均可;也可应用商店、官网、第三方平台、抓包拦截下载地址
  • 优先取最新版本(厂商 SRC 要求应用商店最新版)
  • 同一 App 多渠道包(小米/华为/Google Play)差异可能影响脱壳难度,可换渠道试

二、壳识别(先识别再脱壳)

快速判断:

bash
# 1. 解压看 lib 与入口
unzip -l origin.apk | grep -iE "\.so$|stub|wrapper"
# 2. JADX 打开看 Application/入口类
jadx -d /tmp/quick origin.apk && grep -rn "StubApp\|class.*Application" /tmp/quick/sources/

常见壳特征表:

加固特征(lib/入口类)脱壳方式
腾讯乐固libshella-*.so / libtprt.so / com.stub.StubAppfrida-dexdump / 模拟器运行 dump
梆梆libSecShell.so / SecShellfrida-dexdump / 反射大师
爱加密libexec.so / libexecmain.so / com.secneo.apkwrapperfrida-dexdump
360libjiagu.so / libjiagu_x86.so360 脱壳 / 反射大师
娜迦/顶象libchaosvmp.so / libddog.so内存 dump + dex 修复
腾讯御安全/其他libtosprotection.so 等frida-dexdump / 运行 dump
DCloud uni-app无壳 so,assets/apps/<appid>/www/无需脱壳,直接提取 www/ 即前端源码

关键判断:JADX 打开后全是 stub 包装类 = 有壳,必须脱壳;能直接看到业务类 = 无壳,跳过脱壳直接反编译。


三、脱壳(核心)

方式 1:模拟器 + Frida dump(最通用,推荐)
bash
# 1. 准备 root 模拟器(MuMu/夜神/雷电)并安装 frida-server(架构匹配)
adb push frida-server /data/local/tmp/
adb shell "chmod 755 /data/local/tmp/frida-server && /data/local/tmp/frida-server &"
# 2. 安装目标 App 并启动(dex 解密加载后才能 dump)
adb install origin.apk
# 3. dump 内存中的 dex
frida-dexdump -U -f <package> -o dex/
# 4. 或 frida-unpack 脚本(hook DEX 加载点,dump 更全)
  • 脱壳时机:App 启动后 dex 才在内存解密,必须先运行再 dump
  • 多个 dex 分片 → 合并后统一交给 JADX
  • dump 的 dex 可能头部损坏 → 用 dex 修复工具(如 dexfixer)修复后再反编译
方式 2:在线脱壳服务(快速,适合简单壳)
  • 上传 APK 到在线脱壳平台拿还原后的 dex(仅限自有授权目标,注意上传合规)
方式 3:非 root 场景(真机/普通模拟器)
  • 部分旧壳可 adb backup -f app.ab <package> 提取(API 23- 适用)
  • 或换 root 模拟器走方式 1
方式 4:H5 / uni-app 类(无需脱壳)
bash
# DCloud uni-app:assets/apps/<appid>/www/ 直接是前端源码
unzip -o origin.apk -d apktool_out && ls apktool_out/assets/apps/*/www/
# 微信小程序内嵌:见 miniprogram-security

四、反编译与产物还原

bash
# JADX(无壳:直接反编译 APK;有壳:反编译脱壳后的 dex)
jadx -d jadx_out origin.apk
# 或
jadx -d jadx_out dex/

# apktool(Manifest / smali / 资源 / lib)
apktool d origin.apk -o apktool_out

# so 提取(apktool_out/lib/ 或直接解压)
cp -r apktool_out/lib lib/

# H5/assets 提取
cp -r apktool_out/assets assets/
  • so 层:lib/arm64-v8a/ 优先;Ghidra + GhidraMCP 静态优先(list_functions 定位 JNI 导出 → decompile_function 拿伪 C),Radare2(izz/afl)做轻量侦察;导出表搜 Java_ 前缀(静态注册)或 JNI_OnLoad/RegisterNatives(动态注册)——对应 android-security-audit 一、1.3 SO 层追踪
  • H5 层:assets/ 下 HTML/JS 搜加密库(JSEncrypt/CryptoJS)与密钥常量;动态加载的远程 H5 记录加载 URL——对应 android-security-audit 一、1.4 H5/JS 层追踪
  • 签名/证书:META-INF/*.RSA、res/raw/ 下的证书与密钥,供重打包/校验分析

五、Ghidra + GhidraMCP 环境准备(AI 分析 so 的启动路径)

目标:让 Agent 能自主驱动 Ghidra 分析 .so(定位 JNI 导出 → 反编译伪 C → 读算法重写)。GhidraMCP 操作的是"已导入并分析完的程序",所以 .so 必须先导入 Ghidra 并跑完自动分析。

Show full SKILL.md (156 more words)Show less
5.1 安装与启动
  • Java 21+(Ghidra 11.x 要求);macOS:brew install --cask ghidra 或官网下载
  • 装 GhidraMCP 插件:下载 LaurieWired/GhidraMCP 的 Ghidra 扩展 zip → Ghidra File → Install Extensions 安装 → 重启 Ghidra
  • 启动 MCP server:Ghidra 内 Window → Script Manager 运行 ghidra_mcp.py → 起本地 HTTP MCP server(默认端口 8192,SSE 端点;端口/工具名以仓库 README 为准)
5.2 导入 .so(两种方式,任选)

方式 A(GUI 手动):File → New Project 建工程 → File → Import File 选 libxxx.so → Import → 勾选 Auto Analysis → 等分析跑完

方式 B(命令行,Agent 可代劳):

bash
# 建工程 + 导入 + 自动分析(一次完成)
analyzeHeadless /tmp/ghidra_proj proj -import lib/arm64-v8a/libxxx.so -overwrite
# 之后 GUI `File → Open Project` 打开该工程,GhidraMCP 即挂到已分析程序上
5.3 Agent 连接 MCP
bash
# Claude Code 示例
claude mcp add ghidra -sse http://localhost:8192/mcp
# Codex 等其他框架按各自 MCP 配置方式指向同一端点
5.4 AI 驱动分析路径(工具调用序列)
1. list_functions            → 定位 JNI 导出(Java_ 前缀 / JNI_OnLoad)
2. get_function_by_name <签名函数>
3. decompile_function        → 拿伪 C → 识别算法(MD5/SHA/AES)与拼接顺序 → Python 重写
4. get_strings               → 提取硬编码密钥/常量线索
5. 伪 C 读不动(ollvm/VMP/字符串加密)→ 记录"需动态路径",回落 android-security-audit 1.3 抓包兜底
5.5 注意事项
  • 首次自动分析大 .so 需要几分钟,等跑完再调工具
  • arm64-v8a 原生支持;x86/x86_64 模拟器 so 也可分析
  • 分析对象是从 APK 提取的具体 .so(apk-reversing 产物 lib/arm64-v8a/),不是整个 APK
  • 没有 GhidraMCP 时:Radare2(izz/afl/pdf)做轻量无头侦察作为降级

六、质量检查(保证"拿全部")

  • 入口类真实:JADX 打开 Application/入口 Activity 是业务代码,非 stub
  • 特征串可命中:grep -rniE "appKey|secret|sign|接口域名" jadx_out/sources/ 有结果
  • so 完整:lib/arm64-v8a/ 下 so 齐全,IDA 可打开、导出表可搜
  • H5 完整:assets/www 或远程加载地址已记录
  • dex 合并:多分片 dex 已合并,无遗漏
  • report.md 已写:壳类型、脱壳方式、产物清单、未还原项(如实记录,不编造)

七、验证要点

  • JADX 打开核心类确认真实代码(截图存证)
  • 交付给 android-security-audit 后,其快速开始 Step 2 的 grep 应能直接命中
  • 壳 so 无法静态分析时,如实记录"该模块需动态追踪",不硬编

八、注意与边界

  • 脱壳/反编译仅用于授权目标;在线脱壳上传前确认目标已授权
  • 加固对抗在升级,新壳(VMP/混淆壳)可能需要针对性方案:先跑起来抓 dex 加载点,或结合 windows-reverse-engineering 思路分析壳 so
  • 本技能产出的是审计输入,不直接定级漏洞——定级与成稿交给 android-security-audit + report

联动

  • 下游挖洞:产物直接交给 android-security-audit(密钥追踪→未授权接口 / 组件安全)
  • 快筛前置:asc-fast-hunt(大包秒级定位密钥/签名/接口,决定是否值得全量还原;脱壳后的 dex 打包成 zip 也能回它检索)
  • H5 内嵌小程序:miniprogram-security
  • 提取的密钥/域名上报深挖:recon-js-analysis
  • 正式报告:report

© zhaji2333, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/apk-reversing of zhaji2333/CkSKILLS.

Open the folder on GitHubat commit 482fe78

Compare with similar skills

Apk Reversing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Apk Reversing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Apk Reversing this skillzhaji2333/CkSKILLS115—~1.7kAutomated safety check: PassMIT
Re Frida Script Authordslsdzc/rev-skills135—~1.2kAutomated safety check: PassApache-2.0
Frida Mobile Securityindex-login/MobileRE-Skill158—~3kAutomated safety check: PassMIT
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
Rev Unicorn Debugindex-login/MobileRE-Skill158—~1.9kAutomated safety check: PassMIT
Mira Article Updatervw2x/Mira105—~637Automated safety check: PassGPL-3.0

Similar skills

  • Re Frida Script Author

    dslsdzc/rev-skills

    Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.

    135 GitHub stars~1.2k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.

    105 GitHub stars~637 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Rev Dex Dumper

    index-login/MobileRE-Skill

    Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed

More from zhaji2333/CkSKILLS

All 15 skills in this repo
  • Asc Fast Hunt

    zhaji2333/CkSKILLS

    当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…

    115 GitHub stars~3.3k tokensUpdated 26 days ago
    Auto-check passed
  • Business Logic Race

    zhaji2333/CkSKILLS

    当目标存在支付/下单/退款/提现/转账/优惠券/积分/红包/会员/订阅/审批/库存/抽奖等业务功能,或发现状态可跳变、金额参数可控、并发可重放时调用。负责业务状态机建模、金额篡改、订单状态跳变、竞态条件与重放攻击深度挖掘。

    115 GitHub stars~466 tokensUpdated 26 days ago
    Auto-check passed
  • AI LLM Agent Security

    zhaji2333/CkSKILLS

    当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…

    115 GitHub stars~4.7k tokensUpdated 26 days ago
    Auto-check: warnings
  • Hunt Clueboard

    zhaji2333/CkSKILLS

    当开始挖新目标、换会话/压缩后续挖、用户说线索板/写板/读板/建板,或信息收集、反编译、JS/接口线索需要跨轮保留时调用。负责为当前系统维护一份 Markdown 线索板(读→挖→写回),不负责拆 webpack、打越权或成稿。模板见同目录 CLUEBOARD.template.md。

    115 GitHub stars~606 tokensUpdated 26 days ago
    Auto-check passed
  • Cloud Infra Supply Chain

    zhaji2333/CkSKILLS

    当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。

    115 GitHub stars~688 tokensUpdated 26 days ago
    Auto-check: warnings
  • Injection Vulns

    zhaji2333/CkSKILLS

    当发现参数拼接SQL、动态排序/筛选、JSON查询条件可控、模板渲染、命令执行点、搜索/统计/自动补全接口时调用,进行SQL/NoSQL/命令/SSTI/表达式注入的深度挖掘。命中场景:搜索框、排序参数、登录绕过、导出条件、文件名参数、模板/报表生成、爬虫URL参数。

    115 GitHub stars~579 tokensUpdated 26 days ago
    Auto-check passed

Works with

Categories

Questions about Apk Reversing

What does Apk Reversing do?

当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…. Apk Reversing is an agent skill from zhaji2333/CkSKILLS.

When should I use Apk Reversing?

Apk Reversing fits situations like: tasks that involve Mobile application security.

How do I install Apk Reversing in Claude Code?

Run `npx skills add zhaji2333/CkSKILLS --skill apk-reversing -a claude-code`. Or copy the skill folder (.agents/skills/apk-reversing in zhaji2333/CkSKILLS) into .claude/skills/apk-reversing in your project. Claude Code loads it when a task matches its description.

How do I install Apk Reversing in Codex?

Run `npx skills add zhaji2333/CkSKILLS --skill apk-reversing -a codex`. Or copy the skill folder (.agents/skills/apk-reversing in zhaji2333/CkSKILLS) into .agents/skills/apk-reversing in your project. Codex loads it when a task matches its description.

Can I use Apk Reversing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhaji2333/CkSKILLS --skill apk-reversing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apk-reversing, .gemini/skills/apk-reversing, .github/skills/apk-reversing and .opencode/skills/apk-reversing in your project.

What does Apk Reversing need to run?

Going by SKILL.md and its folder, Apk Reversing needs the command-line tools its instructions call (adb, claude and brew). Our summary lists: Python 3.

Does Apk Reversing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Apk Reversing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Apk Reversing use?

Apk Reversing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Apk Reversing use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Apk Reversing?

Skills that share tags, products or a category with Apk Reversing: Re Frida Script Author (dslsdzc/rev-skills, 135 stars), Frida Mobile Security (index-login/MobileRE-Skill, 158 stars), Mira Risk Collect (vw2x/Mira, 105 stars) and Rev Unicorn Debug (index-login/MobileRE-Skill, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Apk Reversing?

zhaji2333 (a GitHub user) maintains it in zhaji2333/CkSKILLS, which has 115 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on September 15, 2026.

Source: zhaji2333/CkSKILLS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.