Claude Code skill for Android APK reverse engineering — apktool, jadx, Frida workflows.
A skill bundle that teaches Claude how to do real Android reverse engineering: unpack APKs, decompile to Java with jadx, patch smali, hook with Frida. It chains the right tools instead of one-shotting jadx and giving up.
Wann einsetzen: You need to inspect a Flutter/OkHttp app's traffic and pinning blocks Burp.
Voraussetzungen
Server/skill installed and authenticated — See repo README
Ablauf
Identify pinning
Decompile target.apk and find all references to TrustManager / CertificatePinner / Flutter's HttpClient.✓ Kopiert
→ List of hooks to patch
Patch + Frida
Generate a Frida script that no-ops checkServerTrusted across both Java and Flutter paths.✓ Kopiert
→ Frida .js + run command
Ergebnis: Working MITM channel on a test target you own.
Fallstricke
Reversing apps you don't have rights to is illegal in most jurisdictions. The skill assumes you've documented authorization. — Reversing apps you don't have rights to is illegal in most jurisdictions. The skill assumes you've documented authorization.
Kosten & Limits
Was der Betrieb kostet
API-Kontingent
See provider docs for rate limits
Tokens pro Aufruf
Varies by tool
Kosten in €
See repo README for pricing details
Tipp
Cache tool results and avoid repeated identical calls.
Sicherheit
Rechte, Secrets, Reichweite
Credential-Speicherung: Use environment variables; never commit secrets
Datenabfluss: Tool calls go to the provider's API as documented
Fehlerbehebung
Häufige Fehler und Lösungen
apktool fails to unpack
Use the latest apktool (≥2.9). Older versions miss new resource tables.
Prüfen: apktool --version ≥ 2.9
repack signs but won't install
Use uber-apk-signer with --allow-resign and target the right SDK level.