skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
rudra-ravi/frida-skills96 installs

frida-tls-pinning

Analyze and bypass TLS or SSL pinning with Frida on Android, iOS, Flutter, React Native, native BoringSSL/OpenSSL, Conscrypt, OkHttp, NSURLSession, SecTrust, and app-specific trust code.

How do I install this agent skill?

npx skills add https://github.com/rudra-ravi/frida-skills --skill frida-tls-pinning
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    This skill provides a methodology and diagnostic Frida scripts for analyzing and bypassing TLS/SSL pinning in mobile applications. It includes probes for Android, iOS, and native modules to identify networking stacks and provides links to reputable security resources.

  • Socketwarn

    1 alert: gptSecurity

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Frida TLS Pinning

Use this skill when HTTPS traffic is blocked by certificate pinning or custom trust validation.

Identify The Stack First

  • Android Java: OkHttp, TrustManager, Conscrypt, WebView, network security config.
  • Android native: BoringSSL, OpenSSL, Cronet, proxygen, Flutter engine.
  • iOS: NSURLSession, delegate trust challenges, SecTrustEvaluate*, native BoringSSL.
  • Cross-platform: React Native, Flutter, Unity, custom native networking.

Do not start with a universal bypass as the final answer. Use public scripts to discover which hook fires, then keep only the needed hooks.

Android Probe

Java.perform(() => {
  for (const name of [
    "okhttp3.CertificatePinner",
    "com.android.org.conscrypt.TrustManagerImpl",
    "javax.net.ssl.SSLContext"
  ]) {
    try { console.log("found", name, Java.use(name)); } catch (_) {}
  }
});

iOS Probe

if (ObjC.available) {
  for (const name of Object.keys(ObjC.classes).filter(n => n.includes("Trust") || n.includes("Session"))) {
    console.log(name);
  }
}

Native Probe

for (const m of Process.enumerateModules()) {
  if (/ssl|crypto|boring|cronet|liger/i.test(m.name)) console.log(m.name, m.base, m.path);
}

Verification

  • Proxy is trusted by the device or app profile.
  • The hook logs during the exact request that was blocked.
  • The same request succeeds after mutation.
  • Traffic is visible or the app behavior proves trust validation was bypassed.
  • The final script documents app version, platform, library, and rollback command.

References

Read references/tls-patterns.md for framework-specific hook options.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/rudra-ravi/frida-skills/frida-tls-pinning">View frida-tls-pinning on skillZs</a>