CtrlK
BlogDocsLog inGet started
Tessl Logo

apk-reverse

在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content with a clear sequenced workflow and a completion checklist, but it is longer than lean due to redundant sections and its progressive disclosure is undermined by broken/orphaned reference links.

Suggestions

Link the existing bundle references from the body — replace the non-existent '../references/community-security-skills.md' with pointers to frida-bypass-kit.md / frida-cookbook.md / apk-security-checklist.md / android-advanced.md so the real material is discoverable.

Remove or merge the '快速命令备忘' section, since it duplicates the commands already listed under '工具分工'.

Verify the external paths ../field-journal/precedent-reverse.md and ../tool-index.md actually resolve in the deployment, or note them as out-of-skill context so the references are not mistaken for bundle files.

DimensionReasoningScore

Conciseness

Mostly efficient and command-driven rather than explaining concepts Claude knows, but the ~390-line body carries redundancy — '快速命令备忘' repeats commands already shown in '工具分工', and ACTION REQUIRED/routing/bootstrap sections pad length beyond what is lean.

2 / 3

Actionability

Fully executable commands throughout (jadx/apktool/frida/adb invocations) plus real script calls with concrete parameters (e.g. decode.ps1 -ApkPath, rebuild-sign-install.ps1 -ProjectDir -Install), making guidance copy-paste ready.

3 / 3

Workflow Clarity

A clear six-step sequence (Triage → Java → Smali → Rebuild → Hook → Native) with ordering cues, a '禁止事项' guard list, and a completion self-check checklist providing a feedback loop for the destructive rebuild/sign/install path.

3 / 3

Progressive Disclosure

Four real reference bundle files exist (android-advanced, apk-security-checklist, frida-bypass-kit, frida-cookbook) but the body never links to them; instead it cites ../references/community-security-skills.md which is not among the bundle files, plus external ../field-journal/precedent-reverse.md and ../tool-index.md — so reference signaling is broken and the real material is orphaned.

2 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that concretely names actions, trigger scenarios, and tools in third-person voice. It clearly answers both what the skill does and when to use it within a distinct niche.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析' — matching the 'lists multiple specific concrete actions' anchor, not the partial level-2 anchor.

3 / 3

Completeness

Clearly answers both what (the enumerated actions) and when ('适用于…' explicitly enumerates trigger scenarios); third-person voice is used throughout.

3 / 3

Trigger Term Quality

Natural terms a user would say appear — 'Android APK 逆向', 'APK 解包', 'smali', 'Frida 动态 Hook' — though ida-reverse/radare2 are tool names rather than natural triggers, overall keyword coverage is strong.

3 / 3

Distinctiveness Conflict Risk

A clear APK-reverse-CLI niche with named tools (jadx/apktool/frida/adb/ida-reverse/radare2) and distinct triggers, unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.