skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
rudra-ravi/frida-skills95 installs

frida-script-review

Review, harden, and simplify Frida scripts before running CodeShare snippets, universal bypasses, broad hooks, native pointer code, Java hooks, or ObjC hooks.

How do I install this agent skill?

npx skills add https://github.com/rudra-ravi/frida-skills --skill frida-script-review
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    This skill provides a set of instructional guidelines and best practices for reviewing, auditing, and hardening Frida scripts. It does not contain executable code, automated actions, or any identified security risks.

  • Socketwarn

    1 alert: gptAnomaly

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Frida Script Review

Use this skill before running public, generated, or mutation-heavy Frida scripts.

Review Pass

  1. Identify platform assumptions: Android, iOS, native, desktop, Gadget.
  2. Identify mutation points: return replacement, argument rewrite, file writes, process control, network changes.
  3. Check timing: spawn vs attach, module load, class loader, ObjC availability.
  4. Check safety: null pointers, overloads, string lifetimes, retval copies, recursion, noisy hooks.
  5. Reduce broad bundles to the hooks relevant to the target behavior.

Red Flags

  • Blind universal bypass without proof of which hook fired.
  • Native pointer reads without null or length checks.
  • String replacement into fixed buffers without proving buffer size.
  • Java method hook without explicit overload where overloads exist.
  • ObjC selector assumed without checking ObjC.available and class/method presence.
  • retval or argument wrappers stored for later use instead of copied.
  • Logs that print secrets unnecessarily.

Hardening Pattern

Before mutation:

console.log("hook fired", targetName);
console.log(Thread.backtrace(this.context, Backtracer.ACCURATE)
  .map(DebugSymbol.fromAddress).join("\n"));

After proof:

if (shouldPatchThisCall()) {
  retval.replace(1);
}

Output

Return:

  • Risk summary.
  • Exact lines or hook blocks to keep, remove, or change.
  • Safer reviewed script or patch.
  • Verification command and expected proof.

References

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/rudra-ravi/frida-skills/frida-script-review">View frida-script-review on skillZs</a>