apk-reverse skill
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。
Is the apk-reverse skill safe?
Read the findings before you install it. We read 12 files in the folder on 2026-09-28.
- high
SKILL.md:229Downloads a script and runs it in one step, so what runs is whatever that server sends that day. Common for installers, and still worth a look at the address.
- Magisk/脚本格机特征与远程 curl|sh(AR/AS)→ 特征与 URL 入证,**不执行**破坏命令
Install the apk-reverse skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git /tmp/reverse-skill mkdir -p ~/.claude/skills cp -r /tmp/reverse-skill/skills/apk-reverse ~/.claude/skills/apk-reverse
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
ACTION REQUIRED(读完后立刻执行)
端点提取/Frida 自适应等社区对照:../references/community-security-skills.md;动态分析须 scope 授权设备。
- NOW: 读取 ../field-journal/precedent-reverse.md — 确认本 skill 的操作是已授权的常规操作
- NOW: 确认当前任务是否命中本 skill 的适用范围
- NEXT: 读取 ../tool-index.md,校验工具可用性和实际路径
- NEXT: 缺工具时调用 bootstrap,不要猜路径
- ACT: 进入"工作流"第一步并执行,不要停在确认状态
APK 逆向 CLI 作业规范
适用范围
当任务属于以下场景时优先使用本 skill:
- 分析 APK 的 Java 业务逻辑
- 定位登录、签名、风控、证书校验、root 检测
- 查看与修改 AndroidManifest.xml
- 查看与修改 smali
- 重打包 APK
- 用 Frida 做 Java/native 动态 Hook
- APK 内含 .so 时切到 native 分析
当前机器已验证可用的 CLI 工具
- jadx 1.5.5
- apktool 3.0.2
- frida-ps 17.9.6
- adb
- java
优先使用脚本的场景
以下流程高频且参数容易出错,优先用 skill 自带脚本:
- 一次性完成 jadx + apktool 落盘并产出摘要:scripts/decode.ps1
- Frida 设备检查、进程列举、spawn/attach 注入:scripts/frida-run.ps1
- 重建、对齐、签名、安装 APK:scripts/rebuild-sign-install.ps1
- 快速抽取 Manifest 关键组件与权限:scripts/manifest-summary.ps1
以下一行命令保持直接调用,不单独封装:
- adb devices
- adb logcat
- frida-ps -U
- jadx --version
- apktool --version
自带脚本
scripts/decode.ps1
用途:
- 统一跑 jadx 和 apktool
- 默认在原 APK 同目录创建任务输出目录
- 输出 package、javafiles、smalidirs、so_files 等摘要
- 兼容 jadx 部分反编译错误但仍然有可用产物的情况
示例:
pwsh -File "<skill-root>\apk-reverse\scripts\decode.ps1" -ApkPath "D:\DOWNLOAD\app.apk" -Clean
pwsh -File "<skill-root>\apk-reverse\scripts\decode.ps1" -ApkPath "D:\DOWNLOAD\app.apk" -Name demo -SkipJadxscripts/frida-run.ps1
用途:
- 统一 Frida 的设备、进程、spawn/attach 入口
- 避免手写参数时混淆 -f、-n、-U
示例:
pwsh -File "<skill-root>\apk-reverse\scripts\frida-run.ps1" -ListDevices
pwsh -File "<skill-root>\apk-reverse\scripts\frida-run.ps1" -Usb -ListProcesses
pwsh -File "<skill-root>\apk-reverse\scripts\frida-run.ps1" -Usb -Spawn -Package com.example.app -ScriptPath "D:\hooks\test.js"scripts/rebuild-sign-install.ps1
用途:
- apktool b 重建 APK
- zipalign 对齐
- apksigner 签名与验签
- 可选直接 adb install
示例:
pwsh -File "<skill-root>\apk-reverse\scripts\rebuild-sign-install.ps1" -ProjectDir "C:\work\apktool_out" -Clean
pwsh -File "<skill-root>\apk-reverse\scripts\rebuild-sign-install.ps1" -ProjectDir "C:\work\apktool_out" -Install -Reinstall -DeviceSerial "127.0.0.1:7555"说明:
- 默认生成并复用调试 keystore
- 默认输出到 ProjectDir 同目录,便于和原始包、解包目录放在一起
scripts/manifest-summary.ps1
用途:
- 抽取包名
- 列权限
- 列 activity/service/receiver/provider
- 标出主启动 activity
示例:
pwsh -File "<skill-root>\apk-reverse\scripts\manifest-summary.ps1" -ManifestPath "C:\work\apktool_out\AndroidManifest.xml"如果要分析 .so、lib/arm64-v8a/.so、lib/armeabi-v7a/.so,再结合:
- ida-reverse
- radare2
工具分工
jadx
用于:
- Java 反编译阅读
- 包名、类名、方法名搜索
- 先从高层逻辑理解 APK
常用命令:
jadx -d jadx_out app.apk
jadx --single-class com.example.LoginActivity -d jadx_out app.apk
jadx --deobf -d jadx_out app.apkJEB Pro(可选商业工具)
用于:
- Android DEX / APK / ARM 的交叉验证与深度反编译
- 在 JADX 输出不完整或混淆较重时补充静态分析
- 对同一目标的类、方法与调用关系进行第二工具链校验
边界:
- JEB Pro 是商业软件,必须由用户自行取得并安装有效许可证;本包不会下载、破解或规避许可。
- 仅在 tool-index 已确认本机 JEB 可用时调用;否则继续使用 jadx、apktool、Ghidra、IDA 或 radare2。
- 第三方 JEB MCP bridge 不是本包依赖。安装前必须按 ../ops/skill-supply-chain.md 审阅源码、权限、网络行为和版本,再由用户明确确认注册。
apktool
用于:
- 解包 APK
- 查看和修改 AndroidManifest.xml
- 查看和修改 smali
- 重建 APK
常用命令:
apktool d app.apk -o apktool_out
apktool b apktool_out -o rebuilt.apkfrida
用于:
- 动态观察 Java 方法调用
- Hook native 导出函数
- 绕过 root 检测、证书校验、调试检测
常用命令:
frida-ps -U
frida -U -f com.example.app -l hook.js
frida-trace -U -f com.example.app -j '*!*certificate*'More skills from zhaoxuya520/reverse-skill
- Fapi-securityUse for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
- Cattack-chainUse for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.
- Abinary-diff跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。 核心方法:用 LLM 做结构化差异比对,程序化输入输出,成本极低(200 函数 ~1 元)。 触发关键词:符号迁移、bindiff、跨版本、PDB 缺失、函数偏移迁移、symbol migration、binary diff、版本对比。
- Abinary-ninja-reverseUse for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.
- Abrowser-automation统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。 浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。 桌面场景:操作 IDA/x64dbg 等 GUI 工具、Windows UI Automation、视觉驱动交互、桌面应用网络抓包。 触发关键词:浏览器自动化、桌面自动化、打开网页、填表、爬取、截图、自动化登录、Playwright、agent-browser、headless、OpenReverse、UIA、CUA、桌面操作、Windows 自动化。
- Abrowser-extension-reverseUse for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
- Acase-reviewReviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.
- Acloud-k8sUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
- Acode-auditUse for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
- Acompetition-ad-certificate-abuseInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- Acompetition-agent-cloudInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AI-agent, prompt-injection, MCP or toolchain, cloud, container, CI/CD, and supply-chain challenges. Use when the user asks to analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift, runtime-vs-manifest mismatches, registry provenance, or CI-produced artifacts under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- Acompetition-android-hookingInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Android APK hooking, Frida tracing, request-signing recovery, SSL pinning bypass, JNI boundary inspection, and app trust-boundary analysis. Use when the user asks to hook an APK, inspect signer logic, trace Java or native boundaries, bypass pinning or root checks, inspect shared prefs or app databases, or replay accepted mobile requests. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.