Frida android hooks
Create and debug Frida hooks for Android apps, including Java.perform, overloads, constructors, class loaders, Kotlin, JNI, pinning, spawn, and Gadget.From its SKILL.md
npx -y skills add Rudra-ravi/frida-skills --skill frida-android-hooksAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
- runs commandsInstructs the agent to run 5 commands, including `frida --version` and 4 more.
SKILL.md
3.4 KB, 753 tokens by cl100k_base, as published. Nobody here has run it
Frida Android Hooks
Use this skill when instrumenting Android Java/Kotlin/JNI behavior.
Setup Checks
- Verify host and device versions match:
frida --version adb shell /data/local/tmp/frida-server --version frida-ps -Uai - Use spawn for early initialization:
frida -U -f com.example.app -l agent.js --no-pause - Use attach for behavior reachable after app startup:
frida -U -n com.example.app -l agent.js
Java Hook Pattern
Java.perform(() => {
const Target = Java.use("com.example.Target");
Target.method.overload("java.lang.String").implementation = function (value) {
console.log("[Target.method]", value);
const result = this.method(value);
console.log("[Target.method] ->", result);
return result;
};
});
Android Rules
- Always hook inside
Java.perform()unless only native APIs are used. - Resolve overloads explicitly. Do not rely on ambiguous method names.
- Hook constructors through
$init. - For Kotlin, expect companion classes, synthetic methods, default-argument helpers, and obfuscated names.
- If a class is not found, inspect class loaders and set
Java.classFactory.loaderto the app loader that can see it. - For native methods, bridge to
frida-native-hooksafter identifying the loaded.soand JNI symbol.
Practitioner Patterns
- For obfuscated code, hook meaningful platform boundaries first: URL/request builders, JSON parsers, Base64, crypto, SharedPreferences, keystore, file I/O, WebView, class loading, and native library loading.
- Log Java stack traces on high-signal hooks to find the app-owned caller before writing app-specific hooks.
- Convert byte arrays deliberately. Print both hex and UTF-8/ASCII only when valid; binary crypto material is often not text.
- Hook reflection and dynamic loading when classes appear late:
Class.forName,ClassLoader.loadClass,DexClassLoader,PathClassLoader, andRuntime.loadLibrary*. - For TLS/pinning, identify the actual stack before bypassing: OkHttp/CertificatePinner, TrustManager, Conscrypt, WebView, Flutter/BoringSSL, or native custom validation.
- For root/emulator/integrity bypasses, avoid blind mega-scripts as the final answer. Use them to reveal checks, then keep the smallest hooks that change the target behavior.
Discovery Snippets
Java.perform(() => {
const groups = Java.enumerateMethods("*crypto*!*/isu");
console.log(JSON.stringify(groups, null, 2));
});
Java.perform(() => {
Java.enumerateClassLoaders({
onMatch(loader) {
try {
Java.classFactory.loader = loader;
Java.use("com.example.Target");
console.log("loader:", loader);
} catch (_) {}
},
onComplete() {}
});
});
Pinning and Auth Work
- Treat public bypass snippets as reconnaissance, not final proof.
- Identify the actual trust path: platform trust manager, OkHttp, Conscrypt, WebView, native TLS, custom signature, or backend challenge.
- Log inputs/outputs before replacing trust decisions.
- Preserve evidence: hooked class, stack trace, endpoint, certificate or hash material observed, and app version.
References
Read references/android-patterns.md for overload, constructor, class-loader, JNI, OkHttp, WebView, and spawn timing patterns.
What ships with it: 2 files
1.5 KB alongside SKILL.md
agents/
- openai.yaml188 B
references/
- android-patterns.md1.3 KB