Agent skill

Asc Fast Hunt

by zhaji2333 in zhaji2333/CkSKILLS

当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…

MITAuto-check passedSecurity

Install Asc Fast Hunt

skills CLI
$ npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhaji2333/CkSKILLS asc-fast-hunt --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/asc-fast-hunt .claude/skills/asc-fast-hunt && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
asc-fast-hunt
GitHub stars
115
Token cost
~3.3k tokens
SKILL.md length
648 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…

  • Works in 6 steps: :壳预检(30 秒,决定要不要转 apk-reversing) → :Manifest 秒读(攻击面清单) → :关键词矩阵搜索(核心,一波流) → …
  • Tasks that involve Mobile application security
  • SKILL.md covers 出处声明(必须保留), 何时调用(触发条件), 一、环境安装与自检 and 二、工具速查, plus 6 more sections
  • Calls git and pip; reaches github.com

What it does

Asc Fast Hunt is an agent skill from zhaji2333/CkSKILLS. 当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest 秒读),是 android-security-audit「密钥追踪→未授权接口」链的快速前置引擎,也是 apk-reversing 全量还原前的 triage 快筛。命中场景:大包快速 triage、搜 appkey/secret/sign/Authorization/RSA、按类名秒看实现逻辑、追字符串/方法/字段引用链、脱壳 dex 快速检索、Dex 分片全局搜索。注意本技能不能替代 JADX:它无资源层(res/ 全解不出)、DAD 输出类型不可信、无法搜共现模式,因此精读/数据流推理/资源审计/报告取证仍须走 apk-reversing 全量产物。加固壳识别与脱壳见 apk-reversing;组件安全深挖与漏洞验证见…

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security. The repository describes itself as: 基于 Claude Code / Codex 的 SRC 漏洞挖掘 Agent 技能体系 —— 将顶尖安全研究员的方法论沉淀为可调度、可复用的 Skill 知识资产。 The licence is MIT.

When your agent uses it

  • Tasks that involve Mobile application security

Example prompts

  • “/asc-fast-hunt”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. :壳预检(30 秒,决定要不要转 apk-reversing)
  2. :Manifest 秒读(攻击面清单)
  3. :关键词矩阵搜索(核心,一波流)
  4. :按需读实现(getclass)
  5. :追引用链(找调用方与数据流)
  6. :出链归档与交棒

What it can do on your machine

Read from SKILL.md and the folder at commit 482fe78. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Asc Fast Hunt loads about 3.3k tokens when it runs. Until then it costs about 143 tokens; SKILL.md has 648 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhaji2333/CkSKILLS at commit 482fe78, republished under its MIT licence (© zhaji2333). 648 words, ~3,293 tokens.

Download SKILL.mdSave it as .claude/skills/asc-fast-hunt/SKILL.md (or your agent's skills folder).
name
asc-fast-hunt
description
当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(>100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest 秒读),是 android-security-audit「密钥追踪→未授权接口」链的快速前置引擎,也是 apk-reversing 全量还原前的 triage 快筛。命中场景:大包快速 triage、搜 appkey/secret/sign/Authorization/RSA、按类名秒看实现逻辑、追字符串/方法/字段引用链、脱壳 dex 快速检索、Dex 分片全局搜索。注意本技能**不能替代 JADX**:它无资源层(res/ 全解不出)、DAD 输出类型不可信、无法搜共现模式,因此精读/数据流推理/资源审计/报告取证仍须走 apk-reversing 全量产物。加固壳识别与脱壳见 apk-reversing;组件安全深挖与漏洞验证见 android-security-audit;正式报告见 report。

asc-fast-hunt — APK 零预处理快速定位(Droid ASC)

定位:本技能是秒级定位引擎,解决"先全量反编译再搜索"的等待问题——把 APK 当只读数据库直接查询,不建全局索引、不落全量产物,命中即按需反编译单个类。它只负责快速定位与读实现,不负责脱壳、不负责漏洞定级与成稿。

三段式分工:asc-fast-hunt(秒级快筛定位)→ apk-reversing(加固壳脱壳 + 全量还原,仅当快筛命中值得深挖时)→ android-security-audit(组件安全/密钥追踪深挖 + 动态验证)→ report(DOCX 成稿)。

出处声明(必须保留)

  • 工具仓库:https://github.com/MG1937/ASC(Droid ASC,Black Hat Europe Arsenal 议题)
  • 本 SKILL 只是对该工具的封装与工作流编排,工具算法与实现版权归原作者所有,未做任何代码修改
  • 原仓库无 LICENSE 文件(默认保留所有权利):仅限本机自用与授权测试,不得对外分发、不得打包发布、不得声称自有
  • 本机已装位置:/Users/apple/Desktop/武器库/5.逆向/ASC/(与 jadx、ida-mcp-server 并列);如需重建见本文「环境安装与自检」

何时调用(触发条件)

  • 拿到 APK 想知道"有没有硬编码密钥/隐藏接口/调试后门",不想等 JADX 全量反编译(大包动辄几十分钟 + 数 GB 内存)
  • APK > 100MB(系统应用、游戏、大厂 App),全量反编译成本过高
  • 已有脱壳产物(裸 dex / dex 分片),需要快速检索而不是重新全量反编译
  • 只想先看 Manifest 的 exported 组件、权限、scheme 清单,再决定挖不挖
  • android-security-audit 一、密钥追踪专项需要快速找到签名类/密钥常量位置时(本技能负责定位,它负责还原算法与验证接口)
  • 不确定某个 APK 值不值得投入全量还原成本,需要先 triage

不适用:加固壳脱壳(→ apk-reversing)、漏洞定级与验证(→ android-security-audit)、需要跨类数据流/完整工程视图的静态审计(→ 全量反编译产物 + source-code-audit)


一、环境安装与自检

硬门槛:Python ≥ 3.11(工具用了原子分组正则 (?>(?:...)),3.9/3.10 会直接报 unknown extension ?>)。唯一第三方依赖 androguard(本机实测 4.1.4)。

bash
# 已装好(本机):直接自检
ASC=/Users/apple/Desktop/武器库/5.逆向/ASC
$ASC/asc 2>&1 | head -5                    # 打印用法 = 环境正常
$ASC/asc_manifest <任意.apk> | head -3     # Manifest 解析 = androguard 正常

# 从零重建(换机/环境损坏时)
git clone --depth 1 https://github.com/MG1937/ASC $ASC
cd $ASC && python3.11 -m venv .venv && ./.venv/bin/pip install androguard==4.1.4 loguru

自检三连(开工前 10 秒确认):

bash
$ASC/asc findrefs <target.apk> string token | head -3      # 有无命中都要无报错
$ASC/asc_manifest <target.apk> | grep -c "uses-permission" # 权限条数 > 0 即解析成功

二、工具速查

2.1 四个核心命令
bash
ASC=/Users/apple/Desktop/武器库/5.逆向/ASC

# ① Manifest 秒读(组件面/权限/scheme 清单,零反编译)
$ASC/asc_manifest <apk>                                  # 约 0.3s
$ASC/asc_manifest <apk> | grep -B2 -A6 'exported="true"' # 导出组件
$ASC/asc_manifest <apk> | grep 'android:scheme'          # Deep Link scheme

# ② 全局交叉引用搜索(findrefs,四个维度)
$ASC/asc findrefs <apk> string <关键词>                   # 模糊搜字符串使用点
$ASC/asc findrefs <apk> type com.x.Y                     # 模糊搜类型引用点
$ASC/asc findrefs <apk> method <方法名> [--class <类>] [--fuzzy-class]
$ASC/asc findrefs <apk> field <字段名> [--class <类>] [--fuzzy-class]
$ASC/asc findrefs <apk> string appkey -o refs.txt        # 输出存盘(便于通读)
$ASC/asc findrefs --debug <apk> string token             # 耗时统计(--debug 必须在子命令前)

# ③ 按需反编译单个类(getclass)
$ASC/asc getclass <apk> Lcom/x/Y; -o Y.java              # Dalvik 格式
$ASC/asc getclass <apk> com.x.Y -o Y.java                # 点分格式(自动转换)
2.2 输出格式与语义(Agent 必读)

findrefs 输出(一行一个命中点):

classes3.dex | LA8/m$a;->b | matched=(appkey)
   ↑ dex 名    ↑ 类->方法     ↑ 命中内容
  • 搜的是"引用点"不是"定义":findrefs method onCreate 返回的是调用了 onCreate 的位置。看某个方法/字段自身的实现要配合 getclass。
  • 命中按"调用方方法"去重聚合:同一方法内多次调用同名 API 只输出一行,多个命中合并显示在 matched=(a; b; c) 里。所以本技能命中数少于 grep 的行计数(实测同一 4.4MB 包:exec 39 vs 95、startActivity 18 vs 23、getStringExtra 4 vs 9)——不是漏检,是聚合;grep 这边还会同时匹配方法定义、JADX 注释与子串,噪音更大。两者数字不可直接对比。
  • string / type 是模糊匹配(substring);method / field 的 --class 默认精确匹配,加 --fuzzy-class 才模糊(如 --class miui --fuzzy-class 匹配所有 miui 命名空间)。
  • 一个关键词常命中几十~几百行,用 -o 存盘后 grep/分页通读,不要一次性打印刷屏。
  • 搜索跨全部 dex 分片(classes.dex / classes2.dex / …),无需先合并。
命令输出耗时(实测)峰值内存
asc_manifest(68MB 包)可读 XML 全量权限/组件~0.3s~110MB
findrefs string/type(68MB)命中行列表~0.32s~108MB
findrefs string(175MB)命中行列表~0.33s—
getclass(单类)DAD 风格 Java~0.12s—
对照:JADX 全量反编译(68MB)17613 类 → 12677 java + 1629 res XML39.2s6.96GB
对照:JADX 全量反编译(4.4MB)2753 类5.87s—

同一 68MB 包上的对照实测:本技能 0.34s / 108MB vs JADX 全量 39.2s / 6.96GB —— 快约 115 倍、省约 66 倍内存。

2.3 输出质量边界(决定何时必须转全量反编译)

getclass 后端是 Androguard DAD:寄存器级变量名(v0_2、p9)、无类型推断、控制流较朴素。够做的事:读方法逻辑、看字符串常量、识别加密调用(MessageDigest.getInstance("MD5")、Cipher.getInstance("AES/..."))、看调用关系与参数来源。

⚠️ 类型不可信(实测,最危险的边界):DAD 会给出错误类型。同一个类、同一个方法,两个工具的输出:

java
// JADX 1.5.5(正确)
ByteBuffer outputBuffer = this.f2295b.getOutputBuffer(i3);

// ASC / DAD(错误:该方法真实返回 ByteBuffer,却被声明成 String)
String v0_1 = this.b.getOutputBuffer(p6);

因此本技能的输出不可用于数据流/污染推理("这个参数可不可控、会不会流到危险点"),也不适合作为报告取证截图。它只用于快速读懂大致逻辑、认出加密调用与字符串常量——一旦要做可达性推理或写报告,必须换 JADX 产物。

资源层为零:本技能只有 Manifest 解析(借 androguard),res/ 下的 file_paths.xml(FileProvider 路径暴露)、network_security_config.xml、strings.xml(硬编码密钥高发地)、layout(UI 注入点)一律看不到——同一 4.4MB 包 JADX 解出 1629 个 res/ XML。组件审计、Provider 审计必须走 apk-reversing 的 apktool/JADX 产物。

做不到的搜索形态:findrefs 查的是 DEX 引用表,无法表达"同一行两个 API 共现"的模式——android-security-audit Step 2 里的 grep -rE "startActivity.*getParcelable"(Intent 重定向)、grep -rE "setTitle.*getIntent"(弹窗欺骗)这类模式,本技能只能逐个 API 分别查再自己交叉。也没有项目级通读视图。

不够做的事:精读复杂混淆逻辑、跨类数据流追踪、函数调用图、写报告级源码引用、资源层分析、共现模式搜索。当需要这些时,转 apk-reversing 全量反编译用 JADX 读。


三、标准工作流(快筛循环)

Step 0:壳预检(30 秒,决定要不要转 apk-reversing)
bash
# 看 lib/ 壳特征 so 与入口类
unzip -l <apk> | grep -iE "libshella|libjiagu|libSecShell|libexec|libtprt|com/stub"
$ASC/asc_manifest <apk> | grep -oE 'android:name="[A-Za-z0-9._]*Application[A-Za-z0-9._]*"'
$ASC/asc getclass <apk> <上一步的入口类> | head -30     # 是 stub 包装类 = 有壳
  • 判定:lib/ 有壳 so、或入口类是 stub(com.stub.StubApp 等)、或 getclass 读到的 Application 是空壳 → 有壳,转 apk-reversing 脱壳,脱壳产物再回到本技能快筛
  • 无壳 → 直接进 Step 1,全程不需要全量反编译
Step 1:Manifest 秒读(攻击面清单)
bash
$ASC/asc_manifest <apk> > /tmp/manifest.xml
grep -B3 -A8 'exported="true"' /tmp/manifest.xml                     # 导出组件
grep -oE 'android:scheme="[^"]+"' /tmp/manifest.xml | sort -u        # Deep Link scheme
grep -oE 'android:name="android.permission.[^"]+"' /tmp/manifest.xml | sort -u  # 权限面
grep -iE 'android:process|sharedUserId|allowBackup|debuggable' /tmp/manifest.xml

产出:导出 Activity/Service/Receiver/Provider 清单 + scheme 清单 → 交棒 android-security-audit 二、静态分析(组件安全部分);本技能继续做密钥/接口定位。

Step 2:关键词矩阵搜索(核心,一波流)

按组批量搜索,每组存盘通读:

bash
ASC=/Users/apple/Desktop/武器库/5.逆向/ASC
APK=<target.apk>

# A 组|凭证与密钥(最高价值)
for kw in appkey appKey app_secret appSecret secret_key access_key api_key ak_sk client_secret; do
  echo "### $kw"; $ASC/asc findrefs $APK string $kw
done

# B 组|签名与加密
for kw in sign signature signKey md5 sha1 sha256 hmac RSA AES PUBLIC.CRYPTO_PUBLIC; do
  echo "### $kw"; $ASC/asc findrefs $APK string $kw
done

# C 组|网络与接口(拿出接口域名/路径)
for kw in https:// http:// /api/ /v1/ /v2/ Authorization Bearer Cookie userToken; do
  echo "### $kw"; $ASC/asc findrefs $APK string $kw -o /tmp/refs_$(echo $kw|tr -d '/:.').txt
done

# D 组|后门与调试(隐藏功能)
for kw in debug test internal backdoor admin bypass __dev__ mock; do
  echo "### $kw"; $ASC/asc findrefs $APK string $kw
done

# E 组|云服务与第三方(appid/key 泄露高发区)
for kw in appId appid AK SK push_key map_key accessKeyId endpoint bucket; do
  echo "### $kw"; $ASC/asc findrefs $APK string $kw
done

关键技巧:

  • 命中收敛不了(如 secret 几百条)→ 换更长的特征串(app_secret、client_secret)或加限定词(secret_key)
  • 关注方法名异常的命中:LA8/m$a;->b 这种混淆单字母类 + 命中 appkey = 签名工具类,直接进 Step 3
  • URL 类命中最有价值:拿到接口域名/路径清单后,recon-js-analysis 测绘资产、api-protocol-security 打接口
  • 命中即存档:-o /tmp/refs_xxx.txt,后续可反复通读,避免重复搜索
Step 3:按需读实现(getclass)
bash
# 对 Step 2 命中的类逐个读(一个类约 0.1s,可放心多读)
$ASC/asc getclass $APK LA8/m\$a\; -o /tmp/A8_m_a.java

读的时候盯四件事:

  1. 加密调用:MessageDigest.getInstance("MD5"/"SHA-1")、Cipher.getInstance("AES/ECB"...)、java.security.Signature、KeyGenerator
  2. 拼接顺序:md5(appId + appKey + ts) 这类参数拼接 → 直接决定能否 Python 重写
  3. 常量来源:密钥是硬编码字符串常量、还是从 Build/SharedPreferences/native 取(后者要转 SO 层追踪)
  4. 参数来源:是否为外部可控(Intent extra / Deep Link 参数 / 网络响应)

⚠️ 第 4 点要克制:DAD 会给出错误类型(见 2.3),别拿这里的类型声明确认"这个值是什么、从哪来"。此步只建立"疑似外部可控"的假设,确认可达性与数据流必须用 JADX 产物复核。

⚠️ shell 转义:Dalvik 类名含 $(内部类)时必须转义或加引号——LA8/m\$a\; 或 'LA8/m$a;'。

Step 4:追引用链(找调用方与数据流)
bash
# 谁调用了这个签名方法 → 定位业务接口调用点
$ASC/asc findrefs $APK method <方法名> --class <类> --fuzzy-class

# 谁使用了这个密钥字段 → 定位全部加密场景
$ASC/asc findrefs $APK field <字段名>

# 哪些地方引用了这个类(如 Retrofit 接口定义)→ 定位完整 API 面
$ASC/asc findrefs $APK type com.x.net.ApiService

沿"密钥常量 → 签名方法 → 业务接口调用"三跳走完,就能拼出完整攻击链。每一跳都记录 dex | 类->方法,这是后续复现与报告的证据。

Step 5:出链归档与交棒
1. 线索写入 CLUEBOARD:hunts/<目标>/CLUEBOARD.md(调用 hunt-clueboard)
   - 记录: APK 路径与版本、包名、命中类/方法、命中关键词、dex 分片名
   - 否定证据也要写("搜 appkey 无硬编码命中,疑为动态下发")
2. 拿到「密钥 + 签名算法 + 接口」→ 交棒 android-security-audit 一、密钥追踪专项:
   - Python 重写签名 → curl 未授权调接口 → 拉真实业务数据 = 成洞
3. 拿到「接口域名清单」→ 交棒 recon-js-analysis(资产测绘)+ api-protocol-security(接口测试)
4. 命中「命令执行/文件读取/JSBridge」类字符串与类 → 交棒 android-security-audit 二/三 深挖验证
5. 需要精读混淆逻辑或跨类数据流 → 交棒 apk-reversing 全量反编译

Show full SKILL.md (315 more words)Show less

四、分工矩阵(什么时候用哪个)

场景用什么原因
大包想知道有没有硬编码密钥/接口本技能 findrefs秒级,零预处理
只想看组件面/权限/scheme本技能 asc_manifest0.3s 出全量 XML
已知类名,想看实现本技能 getclass0.1s,够读逻辑
小包(<20MB)任何环节直接 JADX 全量4.4MB 包 JADX 仅 5.87s,本技能省不下时间,白折腾
加固壳(stub/壳 so)apk-reversing真代码不在 DEX,本技能搜不到
脱壳后的 dex 要检索本技能(打包成 zip 后)见"坑"第 2 条
混淆严重、需跨类数据流/调用图apk-reversing 全量反编译 + JADXDAD 类型不可信,推理会歪
要查 res/(file_paths.xml、network_security_config、strings.xml)apk-reversing apktool/JADX本技能资源层为零
共现模式搜索(startActivity.*getParcelable 等)JADX 产物 + grep -rE引用表查询无法表达
报告取证截图apk-reversing JADX 产物DAD 输出寄存器级 + 类型错误,不能当证据
组件安全深挖 + 动态验证 + PoCandroid-security-audit本技能只定位不验证
漏洞定级与 DOCX 成稿report—

成本对比(同一 68MB 包实测):本技能 findrefs 0.34s / 108MB;JADX 全量反编译 39.2s / 6.96GB(17613 个类)——快约 115 倍、省约 66 倍内存。本技能全流程(Manifest + 5 组关键词 + 读 10 个类)通常 1 分钟内跑完。

但这不是"替代 JADX":本技能回答**"在哪里",JADX 回答"是什么、怎么流、能不能用"**。实用阈值——

  • 小包(<20MB):直接 JADX 全量,快筛没有收益(4.4MB 只要 5.87s)
  • 大包(>100MB):先本技能秒级定位,命中后再让 JADX 只精读相关部分——68MB 就要 39s + 7GB,175MB 级极易 OOM
  • 任何需要资源层/数据流/报告取证的环节:无论包大小都回 apk-reversing 全量产物

五、边界与坑(实测记录)

  1. Python ≥ 3.11 硬门槛:报 unknown extension ?> 就是 Python 版本不够(原子分组正则),换 3.11+ 重建 venv。
  2. 裸 .dex 不能直接喂:报 EOCD not found(只认 zip/APK 容器)。脱壳产物(frida-dexdump 出的 dex)先打包:
    bash
    cd <dex目录> && zip -q dumped.zip classes*.dex && cp dumped.zip dumped.zip.apk
    $ASC/asc findrefs dumped.zip.apk string appkey
  3. split APK / XAPK:工具按 zip 内的 .dex 条目扫描,split_config.*.apk 这类分片需先用 apkeditor 合并,或用 base.apk(业务 dex 通常在 base)。
  4. 加固壳包搜不到东西是正常现象:DEX 里只有壳的 stub 类,命中无意义 → 转 apk-reversing 脱壳,不要误判为"没有密钥"。
  5. --debug 位置:属于 findrefs 层,必须写在子命令前(findrefs --debug <apk> string kw),写在末尾会报 unrecognized arguments。
  6. $ 转义:Dalvik 内部类名 LA8/m$a; 在 shell 里要转义或用单引号包裹。
  7. findrefs 搜引用点非定义(见 2.2),别把它当"方法列表"用。
  8. 别猜类名:R8 会重命名/裁剪类,猜 com.x.y.R 这类名字大概率报 Class ... not found in APK.(报错本身是正常信号)。正确姿势永远是 findrefs 反查命中类名 → 再 getclass;类名不存在即说明该类被裁剪(常是资源类/构建期类)。
  9. 无 LICENSE,不可分发:详见「出处声明」。工具更新用 cd $ASC && git pull(本机保留 .git)。
  10. GUI 用不上:工具自带 tkinter GUI,Agent 工作流一律走 CLI,不要启动 GUI。

六、证据纪律(防幻觉,强制)

  • 命中 ≠ 漏洞:findrefs 返回的字符串命中只是入口线索,必须 getclass 读到真实代码,才能说"这是密钥/这是签名函数"。
  • ⚠️ getclass 只能确认"逻辑与常量",不能确认"类型与可达性":DAD 输出有类型错误(见 2.3 的 ByteBuffer→String 实证)。所以用本技能读加密调用、字符串常量、分支逻辑是可靠的;一旦要推理"这个参数可不可控、会不会流到危险点",必须换 JADX 产物,不要拿 DAD 的类型下结论。
  • 输出不可直接作报告证据:报告里的代码截图与行号引用一律取自 apk-reversing 的 JADX 产物;本技能的行只用于线索板上的"定位记录"。
  • 不编造类名、方法名、dex 名:报告与线索板里写的每个 dex | 类->方法 都必须来自实际命令输出,禁止推测补全。
  • 否定证据同样要写:搜过什么关键词、没命中,是判断"密钥是否动态下发"的关键依据,必须如实入板。
  • 区分静态位置与可执行性:类里存在 MD5 调用 ≠ 该路径被调用;要沿 Step 4 的引用链确认可达,或交棒 android-security-audit 动态验证。
  • 不越权定级:本技能只输出"定位结论 + 证据行",漏洞等级由 android-security-audit 的验证门与 report 的分层验证门裁定。

七、验证要点

  • 自检三连通过(asc 打印用法、asc_manifest 出权限条数、findrefs 无报错)
  • 壳预检已做:无壳 or 已脱壳(有壳时确认已转 apk-reversing,不硬编结论)
  • 关键词矩阵 A~E 五组全部跑过,未命中的组也在线索板记录
  • 每个"发现"都有 getclass 读到的代码佐证(方法名 + 关键调用行)
  • 引用链至少追一跳(谁调用/谁引用),不只停在命中行
  • 线索(含否定证据)已写入 hunts/<目标>/CLUEBOARD.md
  • 命中密钥/接口/命令执行点已交棒对应技能,未在本技能内直接定级

联动

  • 上游输入:APK 获取与壳识别/脱壳 → apk-reversing(有壳必走)
  • 下游挖洞:密钥追踪→未授权接口、组件安全深挖、动态验证 → android-security-audit
  • 接口域名清单 → recon-js-analysis(资产测绘)、api-protocol-security(API 测试)
  • 云服务凭证(AK/SK/bucket)→ cloud-infra-supply-chain
  • SO 层密钥(native 取密钥时)→ apk-reversing 五、Ghidra 路径 + android-security-audit 1.3
  • 跨轮线索留存 → hunt-clueboard(hunts/<目标>/CLUEBOARD.md)
  • 正式报告 → report

© zhaji2333, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/asc-fast-hunt of zhaji2333/CkSKILLS.

Open the folder on GitHubat commit 482fe78

Compare with similar skills

Asc Fast Hunt next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Asc Fast Hunt compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Asc Fast Hunt this skillzhaji2333/CkSKILLS115—~3.3kAutomated safety check: PassMIT
Android APK Pentesterptn1411/skill219—~917Automated safety check: PassNone
Frida Mobile Securityindex-login/MobileRE-Skill158—~3kAutomated safety check: PassMIT
Mobile Security Experts7safe/android-h1211—~631Automated safety check: PassNone
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
Rev Unicorn Debugindex-login/MobileRE-Skill158—~1.9kAutomated safety check: PassMIT

Similar skills

  • Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

    219 GitHub stars~917 tokensUpdated 19 days ago
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Mobile Security Expert

    s7safe/android-h1

    移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

    211 GitHub stars~631 tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    158 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.

    105 GitHub stars~637 tokensUpdated 6 days ago
    SecurityAuto-check passed

More from zhaji2333/CkSKILLS

All 15 skills in this repo
  • Apk Reversing

    zhaji2333/CkSKILLS

    当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

    115 GitHub stars~1.7k tokensUpdated 26 days ago
    Auto-check passed
  • Business Logic Race

    zhaji2333/CkSKILLS

    当目标存在支付/下单/退款/提现/转账/优惠券/积分/红包/会员/订阅/审批/库存/抽奖等业务功能,或发现状态可跳变、金额参数可控、并发可重放时调用。负责业务状态机建模、金额篡改、订单状态跳变、竞态条件与重放攻击深度挖掘。

    115 GitHub stars~466 tokensUpdated 26 days ago
    Auto-check passed
  • AI LLM Agent Security

    zhaji2333/CkSKILLS

    当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…

    115 GitHub stars~4.7k tokensUpdated 26 days ago
    Auto-check: warnings
  • Hunt Clueboard

    zhaji2333/CkSKILLS

    当开始挖新目标、换会话/压缩后续挖、用户说线索板/写板/读板/建板,或信息收集、反编译、JS/接口线索需要跨轮保留时调用。负责为当前系统维护一份 Markdown 线索板(读→挖→写回),不负责拆 webpack、打越权或成稿。模板见同目录 CLUEBOARD.template.md。

    115 GitHub stars~606 tokensUpdated 26 days ago
    Auto-check passed
  • Cloud Infra Supply Chain

    zhaji2333/CkSKILLS

    当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。

    115 GitHub stars~688 tokensUpdated 26 days ago
    Auto-check: warnings
  • Injection Vulns

    zhaji2333/CkSKILLS

    当发现参数拼接SQL、动态排序/筛选、JSON查询条件可控、模板渲染、命令执行点、搜索/统计/自动补全接口时调用,进行SQL/NoSQL/命令/SSTI/表达式注入的深度挖掘。命中场景:搜索框、排序参数、登录绕过、导出条件、文件名参数、模板/报表生成、爬虫URL参数。

    115 GitHub stars~579 tokensUpdated 26 days ago
    Auto-check passed

Categories

Questions about Asc Fast Hunt

What does Asc Fast Hunt do?

当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…. Asc Fast Hunt is an agent skill from zhaji2333/CkSKILLS.

When should I use Asc Fast Hunt?

Asc Fast Hunt fits situations like: tasks that involve Mobile application security.

How do I install Asc Fast Hunt in Claude Code?

Run `npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a claude-code`. Or copy the skill folder (.agents/skills/asc-fast-hunt in zhaji2333/CkSKILLS) into .claude/skills/asc-fast-hunt in your project. Claude Code loads it when a task matches its description.

How do I install Asc Fast Hunt in Codex?

Run `npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a codex`. Or copy the skill folder (.agents/skills/asc-fast-hunt in zhaji2333/CkSKILLS) into .agents/skills/asc-fast-hunt in your project. Codex loads it when a task matches its description.

Can I use Asc Fast Hunt in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/asc-fast-hunt, .gemini/skills/asc-fast-hunt, .github/skills/asc-fast-hunt and .opencode/skills/asc-fast-hunt in your project.

What does Asc Fast Hunt need to run?

Going by SKILL.md and its folder, Asc Fast Hunt needs the command-line tools its instructions call (git and pip). Our summary lists: Python 3.

Does Asc Fast Hunt access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Asc Fast Hunt safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Asc Fast Hunt use?

Asc Fast Hunt is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Asc Fast Hunt use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Asc Fast Hunt?

Skills that share tags, products or a category with Asc Fast Hunt: Android APK Pentester (ptn1411/skill, 219 stars), Frida Mobile Security (index-login/MobileRE-Skill, 158 stars), Mobile Security Expert (s7safe/android-h1, 211 stars) and Mira Risk Collect (vw2x/Mira, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Asc Fast Hunt?

zhaji2333 (a GitHub user) maintains it in zhaji2333/CkSKILLS, which has 115 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on September 15, 2026.

Source: zhaji2333/CkSKILLS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.