Generate Frida hook scripts using modern Frida API. Activate when the user wants to write Frida scripts, hook functions at runtime, trace calls or arguments or return values, intercept native or ObjC or Java methods, dump memory or exports, or handle native module load timing for Android and other targets.
Detected risks:
This skill generates Frida instrumentation scripts for dynamic analysis, runtime hooking, and inspection of running processes, using the modern Frida API. It targets reverse-engineering and mobile/native security research tasks: hooking native exports, intercepting Java and Objective-C methods, tracing calls, capturing arguments and return values, dumping memory, and handling native module load timing on Android and other platforms. It emphasizes current API idioms (Process.getModuleByName, mod.getExportByName, avoiding the deprecated --no-pause flag) and load-event-driven hooking over polling.
The reference covers module and symbol lookup, Interceptor.attach and Interceptor.replace, NativeFunction and NativeCallback, memory read/write and scanning, ObjC and Java hooking blocks, and a robust hookModuleLoad helper that hooks android_dlopen_ext or dlopen to install instrumentation exactly when a target library loads, deduplicating by module base. It includes careful practitioner guidance — wrap risky hooks in try/catch, print pointers and buffers readably, and specifically warns against blindly hooking .init/.init_array/JNI_OnLoad constructors because early hooks can crash the process or hide the behavior under study.
Target users are reverse engineers, malware analysts, and mobile security researchers. The capability set is genuinely dual-use: runtime memory read/write, replacing function implementations, and hooking primitives like SSL_read enable legitimate analysis but also traffic interception, protection bypass, and app tampering. Because the skill's core output is dynamic-instrumentation tooling that manipulates process memory and intercepts security-relevant functions, its score sits in the elevated-risk band even though the guidance itself is analytical and non-malicious.
Frida JavaScript instrumentation scripts for dynamic analysis: hooking native exports, intercepting Java and Objective-C methods, tracing arguments and return values, dumping memory, and installing hooks when a target native library loads.
It covers native code (via modules and exports), Java on Android, and Objective-C, with explicit handling of native module load timing through android_dlopen_ext or dlopen, and helpers for hooking now-or-on-load and polling as a fallback.
A working Frida installation and CLI, plus a device or process to attach to. The skill uses modern Frida CLI invocations such as spawning with frida -U -f, attaching by name, or attaching by PID with -l to load the script.
It advises preferring load-event-driven hooking over polling, wrapping risky hooks in try/catch, deduplicating hooks by module base, and specifically not blindly hooking .init/.init_array constructors or JNI_OnLoad, which can crash the process or hide the target behavior.
Frida is a legitimate dynamic-analysis framework used widely for reverse engineering, malware analysis, and mobile security research. However, its capabilities — memory read/write, replacing function implementations, and intercepting functions like SSL_read — are dual-use and can also enable traffic interception or protection bypass, so it should be used only against targets you are authorized to analyze.
Quick Setup:
.claude/skills/Repository
p4nda0s/reverse-skills