Android APK Pentester
ptn1411/skill
Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.
当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…
$ npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zhaji2333/CkSKILLS asc-fast-hunt --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/asc-fast-hunt .claude/skills/asc-fast-hunt && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "asc-fast-hunt" agent skill from https://github.com/zhaji2333/CkSKILLS/tree/main/.agents/skills/asc-fast-hunt into .claude/skills/asc-fast-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "asc-fast-hunt", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zhaji2333/CkSKILLS/tree/main/.agents/skills/asc-fast-huntType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zhaji2333/CkSKILLS asc-fast-hunt --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/asc-fast-hunt .agents/skills/asc-fast-hunt && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "asc-fast-hunt" agent skill from https://github.com/zhaji2333/CkSKILLS/tree/main/.agents/skills/asc-fast-hunt into .agents/skills/asc-fast-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "asc-fast-hunt", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zhaji2333/CkSKILLS asc-fast-hunt --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/asc-fast-hunt .cursor/skills/asc-fast-hunt && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "asc-fast-hunt" agent skill from https://github.com/zhaji2333/CkSKILLS/tree/main/.agents/skills/asc-fast-hunt into .cursor/skills/asc-fast-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "asc-fast-hunt", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zhaji2333/CkSKILLS.git --path .agents/skills/asc-fast-hunt--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zhaji2333/CkSKILLS asc-fast-hunt --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/asc-fast-hunt .gemini/skills/asc-fast-hunt && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "asc-fast-hunt" agent skill from https://github.com/zhaji2333/CkSKILLS/tree/main/.agents/skills/asc-fast-hunt into .gemini/skills/asc-fast-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "asc-fast-hunt", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zhaji2333/CkSKILLS asc-fast-huntInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/asc-fast-hunt .github/skills/asc-fast-hunt && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "asc-fast-hunt" agent skill from https://github.com/zhaji2333/CkSKILLS/tree/main/.agents/skills/asc-fast-hunt into .github/skills/asc-fast-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "asc-fast-hunt", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zhaji2333/CkSKILLS asc-fast-hunt --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zhaji2333/CkSKILLS.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/asc-fast-hunt .opencode/skills/asc-fast-hunt && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "asc-fast-hunt" agent skill from https://github.com/zhaji2333/CkSKILLS/tree/main/.agents/skills/asc-fast-hunt into .opencode/skills/asc-fast-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "asc-fast-hunt", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
asc-fast-hunt当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…
Asc Fast Hunt is an agent skill from zhaji2333/CkSKILLS. 当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest 秒读),是 android-security-audit「密钥追踪→未授权接口」链的快速前置引擎,也是 apk-reversing 全量还原前的 triage 快筛。命中场景:大包快速 triage、搜 appkey/secret/sign/Authorization/RSA、按类名秒看实现逻辑、追字符串/方法/字段引用链、脱壳 dex 快速检索、Dex 分片全局搜索。注意本技能不能替代 JADX:它无资源层(res/ 全解不出)、DAD 输出类型不可信、无法搜共现模式,因此精读/数据流推理/资源审计/报告取证仍须走 apk-reversing 全量产物。加固壳识别与脱壳见 apk-reversing;组件安全深挖与漏洞验证见…
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Mobile application security. The repository describes itself as: 基于 Claude Code / Codex 的 SRC 漏洞挖掘 Agent 技能体系 —— 将顶尖安全研究员的方法论沉淀为可调度、可复用的 Skill 知识资产。 The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 482fe78. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitpipFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Asc Fast Hunt loads about 3.3k tokens when it runs. Until then it costs about 143 tokens; SKILL.md has 648 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zhaji2333/CkSKILLS at commit 482fe78, republished under its MIT licence (© zhaji2333). 648 words, ~3,293 tokens.
.claude/skills/asc-fast-hunt/SKILL.md (or your agent's skills folder).定位:本技能是秒级定位引擎,解决"先全量反编译再搜索"的等待问题——把 APK 当只读数据库直接查询,不建全局索引、不落全量产物,命中即按需反编译单个类。它只负责快速定位与读实现,不负责脱壳、不负责漏洞定级与成稿。
三段式分工:
asc-fast-hunt(秒级快筛定位)→apk-reversing(加固壳脱壳 + 全量还原,仅当快筛命中值得深挖时)→android-security-audit(组件安全/密钥追踪深挖 + 动态验证)→report(DOCX 成稿)。
/Users/apple/Desktop/武器库/5.逆向/ASC/(与 jadx、ida-mcp-server 并列);如需重建见本文「环境安装与自检」android-security-audit 一、密钥追踪专项需要快速找到签名类/密钥常量位置时(本技能负责定位,它负责还原算法与验证接口)不适用:加固壳脱壳(→ apk-reversing)、漏洞定级与验证(→ android-security-audit)、需要跨类数据流/完整工程视图的静态审计(→ 全量反编译产物 + source-code-audit)
硬门槛:Python ≥ 3.11(工具用了原子分组正则 (?>(?:...)),3.9/3.10 会直接报 unknown extension ?>)。唯一第三方依赖 androguard(本机实测 4.1.4)。
# 已装好(本机):直接自检
ASC=/Users/apple/Desktop/武器库/5.逆向/ASC
$ASC/asc 2>&1 | head -5 # 打印用法 = 环境正常
$ASC/asc_manifest <任意.apk> | head -3 # Manifest 解析 = androguard 正常
# 从零重建(换机/环境损坏时)
git clone --depth 1 https://github.com/MG1937/ASC $ASC
cd $ASC && python3.11 -m venv .venv && ./.venv/bin/pip install androguard==4.1.4 loguru自检三连(开工前 10 秒确认):
$ASC/asc findrefs <target.apk> string token | head -3 # 有无命中都要无报错
$ASC/asc_manifest <target.apk> | grep -c "uses-permission" # 权限条数 > 0 即解析成功ASC=/Users/apple/Desktop/武器库/5.逆向/ASC
# ① Manifest 秒读(组件面/权限/scheme 清单,零反编译)
$ASC/asc_manifest <apk> # 约 0.3s
$ASC/asc_manifest <apk> | grep -B2 -A6 'exported="true"' # 导出组件
$ASC/asc_manifest <apk> | grep 'android:scheme' # Deep Link scheme
# ② 全局交叉引用搜索(findrefs,四个维度)
$ASC/asc findrefs <apk> string <关键词> # 模糊搜字符串使用点
$ASC/asc findrefs <apk> type com.x.Y # 模糊搜类型引用点
$ASC/asc findrefs <apk> method <方法名> [--class <类>] [--fuzzy-class]
$ASC/asc findrefs <apk> field <字段名> [--class <类>] [--fuzzy-class]
$ASC/asc findrefs <apk> string appkey -o refs.txt # 输出存盘(便于通读)
$ASC/asc findrefs --debug <apk> string token # 耗时统计(--debug 必须在子命令前)
# ③ 按需反编译单个类(getclass)
$ASC/asc getclass <apk> Lcom/x/Y; -o Y.java # Dalvik 格式
$ASC/asc getclass <apk> com.x.Y -o Y.java # 点分格式(自动转换)findrefs 输出(一行一个命中点):
classes3.dex | LA8/m$a;->b | matched=(appkey)
↑ dex 名 ↑ 类->方法 ↑ 命中内容findrefs method onCreate 返回的是调用了 onCreate 的位置。看某个方法/字段自身的实现要配合 getclass。matched=(a; b; c) 里。所以本技能命中数少于 grep 的行计数(实测同一 4.4MB 包:exec 39 vs 95、startActivity 18 vs 23、getStringExtra 4 vs 9)——不是漏检,是聚合;grep 这边还会同时匹配方法定义、JADX 注释与子串,噪音更大。两者数字不可直接对比。string / type 是模糊匹配(substring);method / field 的 --class 默认精确匹配,加 --fuzzy-class 才模糊(如 --class miui --fuzzy-class 匹配所有 miui 命名空间)。-o 存盘后 grep/分页通读,不要一次性打印刷屏。| 命令 | 输出 | 耗时(实测) | 峰值内存 |
|---|---|---|---|
asc_manifest(68MB 包) | 可读 XML 全量权限/组件 | ~0.3s | ~110MB |
findrefs string/type(68MB) | 命中行列表 | ~0.32s | ~108MB |
findrefs string(175MB) | 命中行列表 | ~0.33s | — |
getclass(单类) | DAD 风格 Java | ~0.12s | — |
| 对照:JADX 全量反编译(68MB) | 17613 类 → 12677 java + 1629 res XML | 39.2s | 6.96GB |
| 对照:JADX 全量反编译(4.4MB) | 2753 类 | 5.87s | — |
同一 68MB 包上的对照实测:本技能 0.34s / 108MB vs JADX 全量 39.2s / 6.96GB —— 快约 115 倍、省约 66 倍内存。
getclass 后端是 Androguard DAD:寄存器级变量名(v0_2、p9)、无类型推断、控制流较朴素。够做的事:读方法逻辑、看字符串常量、识别加密调用(MessageDigest.getInstance("MD5")、Cipher.getInstance("AES/..."))、看调用关系与参数来源。
⚠️ 类型不可信(实测,最危险的边界):DAD 会给出错误类型。同一个类、同一个方法,两个工具的输出:
// JADX 1.5.5(正确)
ByteBuffer outputBuffer = this.f2295b.getOutputBuffer(i3);
// ASC / DAD(错误:该方法真实返回 ByteBuffer,却被声明成 String)
String v0_1 = this.b.getOutputBuffer(p6);因此本技能的输出不可用于数据流/污染推理("这个参数可不可控、会不会流到危险点"),也不适合作为报告取证截图。它只用于快速读懂大致逻辑、认出加密调用与字符串常量——一旦要做可达性推理或写报告,必须换 JADX 产物。
资源层为零:本技能只有 Manifest 解析(借 androguard),res/ 下的 file_paths.xml(FileProvider 路径暴露)、network_security_config.xml、strings.xml(硬编码密钥高发地)、layout(UI 注入点)一律看不到——同一 4.4MB 包 JADX 解出 1629 个 res/ XML。组件审计、Provider 审计必须走 apk-reversing 的 apktool/JADX 产物。
做不到的搜索形态:findrefs 查的是 DEX 引用表,无法表达"同一行两个 API 共现"的模式——android-security-audit Step 2 里的 grep -rE "startActivity.*getParcelable"(Intent 重定向)、grep -rE "setTitle.*getIntent"(弹窗欺骗)这类模式,本技能只能逐个 API 分别查再自己交叉。也没有项目级通读视图。
不够做的事:精读复杂混淆逻辑、跨类数据流追踪、函数调用图、写报告级源码引用、资源层分析、共现模式搜索。当需要这些时,转 apk-reversing 全量反编译用 JADX 读。
# 看 lib/ 壳特征 so 与入口类
unzip -l <apk> | grep -iE "libshella|libjiagu|libSecShell|libexec|libtprt|com/stub"
$ASC/asc_manifest <apk> | grep -oE 'android:name="[A-Za-z0-9._]*Application[A-Za-z0-9._]*"'
$ASC/asc getclass <apk> <上一步的入口类> | head -30 # 是 stub 包装类 = 有壳lib/ 有壳 so、或入口类是 stub(com.stub.StubApp 等)、或 getclass 读到的 Application 是空壳 → 有壳,转 apk-reversing 脱壳,脱壳产物再回到本技能快筛$ASC/asc_manifest <apk> > /tmp/manifest.xml
grep -B3 -A8 'exported="true"' /tmp/manifest.xml # 导出组件
grep -oE 'android:scheme="[^"]+"' /tmp/manifest.xml | sort -u # Deep Link scheme
grep -oE 'android:name="android.permission.[^"]+"' /tmp/manifest.xml | sort -u # 权限面
grep -iE 'android:process|sharedUserId|allowBackup|debuggable' /tmp/manifest.xml产出:导出 Activity/Service/Receiver/Provider 清单 + scheme 清单 → 交棒 android-security-audit 二、静态分析(组件安全部分);本技能继续做密钥/接口定位。
按组批量搜索,每组存盘通读:
ASC=/Users/apple/Desktop/武器库/5.逆向/ASC
APK=<target.apk>
# A 组|凭证与密钥(最高价值)
for kw in appkey appKey app_secret appSecret secret_key access_key api_key ak_sk client_secret; do
echo "### $kw"; $ASC/asc findrefs $APK string $kw
done
# B 组|签名与加密
for kw in sign signature signKey md5 sha1 sha256 hmac RSA AES PUBLIC.CRYPTO_PUBLIC; do
echo "### $kw"; $ASC/asc findrefs $APK string $kw
done
# C 组|网络与接口(拿出接口域名/路径)
for kw in https:// http:// /api/ /v1/ /v2/ Authorization Bearer Cookie userToken; do
echo "### $kw"; $ASC/asc findrefs $APK string $kw -o /tmp/refs_$(echo $kw|tr -d '/:.').txt
done
# D 组|后门与调试(隐藏功能)
for kw in debug test internal backdoor admin bypass __dev__ mock; do
echo "### $kw"; $ASC/asc findrefs $APK string $kw
done
# E 组|云服务与第三方(appid/key 泄露高发区)
for kw in appId appid AK SK push_key map_key accessKeyId endpoint bucket; do
echo "### $kw"; $ASC/asc findrefs $APK string $kw
done关键技巧:
secret 几百条)→ 换更长的特征串(app_secret、client_secret)或加限定词(secret_key)LA8/m$a;->b 这种混淆单字母类 + 命中 appkey = 签名工具类,直接进 Step 3recon-js-analysis 测绘资产、api-protocol-security 打接口-o /tmp/refs_xxx.txt,后续可反复通读,避免重复搜索# 对 Step 2 命中的类逐个读(一个类约 0.1s,可放心多读)
$ASC/asc getclass $APK LA8/m\$a\; -o /tmp/A8_m_a.java读的时候盯四件事:
MessageDigest.getInstance("MD5"/"SHA-1")、Cipher.getInstance("AES/ECB"...)、java.security.Signature、KeyGeneratormd5(appId + appKey + ts) 这类参数拼接 → 直接决定能否 Python 重写Build/SharedPreferences/native 取(后者要转 SO 层追踪)⚠️ 第 4 点要克制:DAD 会给出错误类型(见 2.3),别拿这里的类型声明确认"这个值是什么、从哪来"。此步只建立"疑似外部可控"的假设,确认可达性与数据流必须用 JADX 产物复核。
⚠️ shell 转义:Dalvik 类名含 $(内部类)时必须转义或加引号——LA8/m\$a\; 或 'LA8/m$a;'。
# 谁调用了这个签名方法 → 定位业务接口调用点
$ASC/asc findrefs $APK method <方法名> --class <类> --fuzzy-class
# 谁使用了这个密钥字段 → 定位全部加密场景
$ASC/asc findrefs $APK field <字段名>
# 哪些地方引用了这个类(如 Retrofit 接口定义)→ 定位完整 API 面
$ASC/asc findrefs $APK type com.x.net.ApiService沿"密钥常量 → 签名方法 → 业务接口调用"三跳走完,就能拼出完整攻击链。每一跳都记录 dex | 类->方法,这是后续复现与报告的证据。
1. 线索写入 CLUEBOARD:hunts/<目标>/CLUEBOARD.md(调用 hunt-clueboard)
- 记录: APK 路径与版本、包名、命中类/方法、命中关键词、dex 分片名
- 否定证据也要写("搜 appkey 无硬编码命中,疑为动态下发")
2. 拿到「密钥 + 签名算法 + 接口」→ 交棒 android-security-audit 一、密钥追踪专项:
- Python 重写签名 → curl 未授权调接口 → 拉真实业务数据 = 成洞
3. 拿到「接口域名清单」→ 交棒 recon-js-analysis(资产测绘)+ api-protocol-security(接口测试)
4. 命中「命令执行/文件读取/JSBridge」类字符串与类 → 交棒 android-security-audit 二/三 深挖验证
5. 需要精读混淆逻辑或跨类数据流 → 交棒 apk-reversing 全量反编译| 场景 | 用什么 | 原因 |
|---|---|---|
| 大包想知道有没有硬编码密钥/接口 | 本技能 findrefs | 秒级,零预处理 |
| 只想看组件面/权限/scheme | 本技能 asc_manifest | 0.3s 出全量 XML |
| 已知类名,想看实现 | 本技能 getclass | 0.1s,够读逻辑 |
| 小包(<20MB)任何环节 | 直接 JADX 全量 | 4.4MB 包 JADX 仅 5.87s,本技能省不下时间,白折腾 |
| 加固壳(stub/壳 so) | apk-reversing | 真代码不在 DEX,本技能搜不到 |
| 脱壳后的 dex 要检索 | 本技能(打包成 zip 后) | 见"坑"第 2 条 |
| 混淆严重、需跨类数据流/调用图 | apk-reversing 全量反编译 + JADX | DAD 类型不可信,推理会歪 |
| 要查 res/(file_paths.xml、network_security_config、strings.xml) | apk-reversing apktool/JADX | 本技能资源层为零 |
共现模式搜索(startActivity.*getParcelable 等) | JADX 产物 + grep -rE | 引用表查询无法表达 |
| 报告取证截图 | apk-reversing JADX 产物 | DAD 输出寄存器级 + 类型错误,不能当证据 |
| 组件安全深挖 + 动态验证 + PoC | android-security-audit | 本技能只定位不验证 |
| 漏洞定级与 DOCX 成稿 | report | — |
成本对比(同一 68MB 包实测):本技能 findrefs 0.34s / 108MB;JADX 全量反编译 39.2s / 6.96GB(17613 个类)——快约 115 倍、省约 66 倍内存。本技能全流程(Manifest + 5 组关键词 + 读 10 个类)通常 1 分钟内跑完。
但这不是"替代 JADX":本技能回答**"在哪里",JADX 回答"是什么、怎么流、能不能用"**。实用阈值——
apk-reversing 全量产物unknown extension ?> 就是 Python 版本不够(原子分组正则),换 3.11+ 重建 venv。.dex 不能直接喂:报 EOCD not found(只认 zip/APK 容器)。脱壳产物(frida-dexdump 出的 dex)先打包:cd <dex目录> && zip -q dumped.zip classes*.dex && cp dumped.zip dumped.zip.apk
$ASC/asc findrefs dumped.zip.apk string appkey.dex 条目扫描,split_config.*.apk 这类分片需先用 apkeditor 合并,或用 base.apk(业务 dex 通常在 base)。apk-reversing 脱壳,不要误判为"没有密钥"。--debug 位置:属于 findrefs 层,必须写在子命令前(findrefs --debug <apk> string kw),写在末尾会报 unrecognized arguments。$ 转义:Dalvik 内部类名 LA8/m$a; 在 shell 里要转义或用单引号包裹。com.x.y.R 这类名字大概率报 Class ... not found in APK.(报错本身是正常信号)。正确姿势永远是 findrefs 反查命中类名 → 再 getclass;类名不存在即说明该类被裁剪(常是资源类/构建期类)。cd $ASC && git pull(本机保留 .git)。findrefs 返回的字符串命中只是入口线索,必须 getclass 读到真实代码,才能说"这是密钥/这是签名函数"。getclass 只能确认"逻辑与常量",不能确认"类型与可达性":DAD 输出有类型错误(见 2.3 的 ByteBuffer→String 实证)。所以用本技能读加密调用、字符串常量、分支逻辑是可靠的;一旦要推理"这个参数可不可控、会不会流到危险点",必须换 JADX 产物,不要拿 DAD 的类型下结论。apk-reversing 的 JADX 产物;本技能的行只用于线索板上的"定位记录"。dex | 类->方法 都必须来自实际命令输出,禁止推测补全。android-security-audit 动态验证。android-security-audit 的验证门与 report 的分层验证门裁定。asc 打印用法、asc_manifest 出权限条数、findrefs 无报错)apk-reversing,不硬编结论)getclass 读到的代码佐证(方法名 + 关键调用行)hunts/<目标>/CLUEBOARD.mdapk-reversing(有壳必走)android-security-auditrecon-js-analysis(资产测绘)、api-protocol-security(API 测试)cloud-infra-supply-chainapk-reversing 五、Ghidra 路径 + android-security-audit 1.3hunt-clueboard(hunts/<目标>/CLUEBOARD.md)report© zhaji2333, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/asc-fast-hunt of zhaji2333/CkSKILLS.
Open the folder on GitHubat commit 482fe78
Asc Fast Hunt next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Asc Fast Hunt this skillzhaji2333/CkSKILLS | 115 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Android APK Pentesterptn1411/skill | 219 | — | ~917 | Automated safety check: Pass | None | |
| Frida Mobile Securityindex-login/MobileRE-Skill | 158 | — | ~3k | Automated safety check: Pass | MIT | |
| Mobile Security Experts7safe/android-h1 | 211 | — | ~631 | Automated safety check: Pass | None | |
| Mira Risk Collectvw2x/Mira | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | |
| Rev Unicorn Debugindex-login/MobileRE-Skill | 158 | — | ~1.9k | Automated safety check: Pass | MIT |
ptn1411/skill
Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
s7safe/android-h1
移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
index-login/MobileRE-Skill
Debug and emulate specific code fragments or functions using the Unicorn engine.
vw2x/Mira
Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.
zhaji2333/CkSKILLS
当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…
zhaji2333/CkSKILLS
当目标存在支付/下单/退款/提现/转账/优惠券/积分/红包/会员/订阅/审批/库存/抽奖等业务功能,或发现状态可跳变、金额参数可控、并发可重放时调用。负责业务状态机建模、金额篡改、订单状态跳变、竞态条件与重放攻击深度挖掘。
zhaji2333/CkSKILLS
当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…
zhaji2333/CkSKILLS
当开始挖新目标、换会话/压缩后续挖、用户说线索板/写板/读板/建板,或信息收集、反编译、JS/接口线索需要跨轮保留时调用。负责为当前系统维护一份 Markdown 线索板(读→挖→写回),不负责拆 webpack、打越权或成稿。模板见同目录 CLUEBOARD.template.md。
zhaji2333/CkSKILLS
当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。
zhaji2333/CkSKILLS
当发现参数拼接SQL、动态排序/筛选、JSON查询条件可控、模板渲染、命令执行点、搜索/统计/自动补全接口时调用,进行SQL/NoSQL/命令/SSTI/表达式注入的深度挖掘。命中场景:搜索框、排序参数、登录绕过、导出条件、文件名参数、模板/报表生成、爬虫URL参数。
Categories
当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…. Asc Fast Hunt is an agent skill from zhaji2333/CkSKILLS.
Asc Fast Hunt fits situations like: tasks that involve Mobile application security.
Run `npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a claude-code`. Or copy the skill folder (.agents/skills/asc-fast-hunt in zhaji2333/CkSKILLS) into .claude/skills/asc-fast-hunt in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a codex`. Or copy the skill folder (.agents/skills/asc-fast-hunt in zhaji2333/CkSKILLS) into .agents/skills/asc-fast-hunt in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhaji2333/CkSKILLS --skill asc-fast-hunt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/asc-fast-hunt, .gemini/skills/asc-fast-hunt, .github/skills/asc-fast-hunt and .opencode/skills/asc-fast-hunt in your project.
Going by SKILL.md and its folder, Asc Fast Hunt needs the command-line tools its instructions call (git and pip). Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Asc Fast Hunt is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Asc Fast Hunt: Android APK Pentester (ptn1411/skill, 219 stars), Frida Mobile Security (index-login/MobileRE-Skill, 158 stars), Mobile Security Expert (s7safe/android-h1, 211 stars) and Mira Risk Collect (vw2x/Mira, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zhaji2333 (a GitHub user) maintains it in zhaji2333/CkSKILLS, which has 115 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on September 15, 2026.
Source: zhaji2333/CkSKILLS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.