Back to skill

Security audit

Android Armor Breaker

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Android reverse-engineering skill, but it can use root and Frida to bypass app protections, read process memory, and save extracted code/data with limited runtime guardrails.

Install only if you are doing authorized Android security research on apps and devices you own or have written permission to assess. Use an isolated rooted test device or emulator, review and pin dependencies before installation, validate package names manually, and treat all extracted DEX files, reports, and memory dumps as sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/root_memory_extractor.py:74
Finding

Android Device Command Injection Through Unvalidated Package Names

Content
View full analysis
Optional[int]: self.log("getting_process_pid", package=package_name) try: result = subprocess.run( ["adb", "shell", f"pidof {package_name}"], capture_output=True, text=True, timeout=10 ) if result.returncode == 0 and result.stdout.strip(): pid_str = result.stdout.strip() if ' ' in pid_str: pid_str = pid_str.split()[0] try: pid = int(pid_str) self.log("pid_found", "SUCCESS", pid=pid) return pid except ValueError: self.log("pidof_invalid_output", "WARNING", output=pid_str) self.log("pidof_failed_trying_ps", "WARN") ps_result = subprocess.run( ["adb", "shell", f"ps -A | grep {package_name}"], capture_output=True, text=True, timeout=10 ) if ps_result.returncode == 0 and ps_result.stdout.strip(): lines = ps_result.stdout.strip().split('\n') for line in lines: parts = line.split() if len(parts) >= 9 and package_name in parts[-1]: try: pid = int(parts[1]) self.log("pid_found_via_ps", "SUCCESS", pid=pid) return pi ...[truncated 3912 chars]
Remediation
View remediation
str: if not PACKAGE_RE.fullmatch(value): raise ValueError("Invalid Android package name") return value ``` Call the validator immediately after argument parsing: ```python try: package_name = validate_package_name(args.package) except ValueError as exc: parser.error(str(exc)) ``` Where the Android command supports separate arguments, avoid constructing a shell command string: ```python subprocess.run( ["adb", "shell", "pidof", package_name], capture_output=True, text=True, timeout=10, check=False ) ``` Avoid remote pipelines entirely. Retrieve process data and filter it in Python: ```python result = subprocess.run( ["adb", "shell", "ps", "-A"], capture_output=True, text=True, timeout=10, check=False ) for line in result.stdout.splitlines(): fields = line.split() if fields and fields[-1] == package_name: # Parse the PID from the expected field. pass ``` For commands that cannot be expressed without an Android shell string: 1. Validate the package name with a strict allowlist. 2. Apply POSIX shell quoting as an additional defense. 3. Never rely on quoting alone for identifier validation. 4. Centralize all ADB execution in a helper that distinguishes structured arguments from shell commands. 5. Add tests containing `;`, `|`, `$()`, backticks, whitespace, newlines, redirections, and quote characters. 6. Reject package names that do not exactly match the expected Android identifier grammar. 7. Apply the same correction to every listed runner, including the enhanced extractor. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Automatically Installed PyPI Dependency Is Not Version-Pinned or Hash-Verified

Content
View full analysis
Remediation
View remediation
", "bins": ["frida", "frida-dexdump"], "label": "Install Reviewed Frida Tools Suite" } ``` Use a hash-locked requirements file where supported: ```text frida-tools== \ --hash=sha256: ``` Install with hash enforcement: ```bash python3 -m pip install \ --require-hashes \ --only-binary=:all: \ -r requirements.lock ``` Additional hardening should include: 1. Install Python dependencies in a dedicated virtual environment. 2. Use an explicitly approved package index rather than inheriting an arbitrary user configuration. 3. Review and record the exact transitive dependency set. 4. Prefer prebuilt, verified wheels to avoid executing unreviewed build backends. 5. Generate and retain a software bill of materials. 6. Add automated dependency vulnerability and provenance checks. 7. Update the manual instructions so they use the same locked dependency specification. 8. Re-audit dependency updates before changing the pinned version. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (109)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a substantive Android protection-breaking and unpacking tool. However, the supplied code chunk does not itself implement any of those capabilities. Its actual function is a compatibility wrapper around an external Bash script, with argument forwarding and logging. Because the evaluation is based on the supplied code chunk, the described core behavior is not represented here. While the wrapper may be part of a larger tool, this chunk alone materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code materially under-delivers relative to the declared description. While the description emphasizes APK脱壳/unpacking, DEX extraction, memory dump, and analysis of commercial packers, the supplied code only performs anti-debug bypass via Frida script generation and process injection. It hooks debugger checks, ptrace, /proc access, file operations, timing checks, and Frida-detection-related behavior, then verifies app stability. Anti-debug bypass is indeed mentioned in the declared purpose, but it is presented there as one component of a broader unpacking/extraction tool. In this code chunk, anti-debug bypass is the sole substantive function. There is no implementation for dumping memory, extracting DEX, unpacking APKs, or root-based extraction, so the actual behavior does not accurately represent the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description advertises an active dynamic unpacking and anti-protection tool using Frida, with capabilities such as bypassing anti-debug, extracting DEX from protected apps, and performing root memory dumps. The supplied code does none of those things. Instead, it statically analyzes the APK archive contents by matching file names against known protection signatures and produces a classification report and recommendations. While the vendors mentioned overlap with the description, the implemented behavior is materially different: detection/analysis rather than unpacking/cracking/extraction. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a broader Android unpacking tool whose core value is extracting DEX and dumping memory from protected APKs across several commercial protectors. The supplied code chunk instead implements a narrow operational runner for Bangcle bypass: it creates a Frida script that disables/debug-detection-related checks, injects it into a running app, and verifies whether the process survives. While anti-debug/anti-Frida bypass is consistent with part of the description, the primary advertised capabilities of unpacking, DEX extraction, and memory dumping are absent from this code. The code is also specifically focused on Bangcle rather than the full multi-protector support claimed in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code chunk does not perform APK unpacking, Frida instrumentation, anti-debug bypass, DEX extraction, root memory dumping, or Android reverse-engineering actions. Its primary purpose is a reusable i18n logging helper for other scripts. While such a logger could be a supporting component within a larger unpacking tool, this specific chunk’s behavior is materially different from the declared purpose and exposes capabilities not mentioned in the description, namely localization, message-file loading, and structured console logging. Therefore, this code chunk does not accurately represent the declared skill functionality on its own.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a functional Android unpacking/anti-protection tool for protected APKs. The supplied code chunk is instead an internal maintenance/QA shell script that validates whether certain project files and feature markers exist. Its primary behavior is repository inspection and reporting, not Frida-based unpacking, DEX extraction, anti-debug bypass execution, memory dumping, or APK analysis. While some checked filenames/strings relate to the declared domain, this script only verifies implementation artifacts and documentation, which is materially different from the declared end-user capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script serializes raw memory-derived bytes to Base64 and transmits them via Frida messaging as files, which is a direct exfiltration path for in-memory data. In this skill’s context, the stated purpose is APK unpacking, anti-debug bypass, and DEX extraction from protected apps, so the data transfer is not incidental diagnostics but core functionality for extracting proprietary code and potentially any other sensitive memory-resident material.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code performs broad enumeration of readable memory regions and reads up to 1 MB from each region while searching for DEX signatures, which creates access to arbitrary in-memory secrets well beyond the minimum needed for safe operation. Given the tool’s explicit focus on defeating commercial protections and dumping protected APK contents, this broad memory access materially increases the risk of harvesting credentials, tokens, user data, and proprietary code from target processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script performs privileged memory capture from app processes and searches that memory for DEX payloads without any explicit warning, confirmation, or authorization check. This is dangerous because memory snapshots can contain secrets, tokens, personal data, and proprietary code, and the skill is explicitly designed for unpacking and bypassing protections, which increases misuse risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file-level description explicitly frames the capability as bypassing commercial protections and anti-debugging to extract protected DEX content. That is not merely descriptive reverse-engineering support; it advertises protection circumvention without any embedded authorization boundaries, making abuse against third-party apps straightforward. The skill context makes this especially dangerous because the entire toolchain is centered on defeating security controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code reads another process's memory via root and saves extracted contents to disk without any explicit warning, authorization check, or data-minimization control. This can expose secrets, proprietary code, credentials, and personal data, and creates durable artifacts that increase the harm of misuse. Given the skill's stated purpose of unpacking and bypassing protections, this is a core offensive capability rather than an incidental debugging feature.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script saves raw process memory dumps and extracted DEX artifacts to disk, which can contain proprietary code, credentials, tokens, PII, or other highly sensitive runtime data. In the context of a root-based unpacker designed to bypass protections, silent persistence of this data materially increases exposure if the host system is shared, compromised, or logs/artifacts are redistributed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code can automatically invoke a root memory extraction workflow without any explicit warning, confirmation, or authorization check beyond CLI selection/strategy logic. In the context of a tool explicitly designed for APK unpacking, anti-debug bypass, and memory dumping, this is especially dangerous because it enables privileged extraction of sensitive app memory and may be triggered automatically for certain protection types.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The memory snapshot strategy performs sensitive memory access but does not present an explicit warning or require confirmation before execution. Given the skill’s context—commercial protection bypass, dumping, and reverse-engineering automation—this omission materially increases the risk of unauthorized extraction of secrets, user data, or protected code from a target app.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quick-start materially facilitates APK unpacking, anti-debug bypass, root memory extraction, and DEX dumping, which are dual-use reverse-engineering techniques commonly used to defeat commercial protections and extract proprietary code. The danger is increased because the document provides operational steps but no legal, authorization, privacy, or device-safety guardrails, making misuse easier for unauthorized analysis or IP theft.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · QUICK_START.md (reported line 71)May include surrounding context.

md
## 🔧 环境要求

### 必需组件
- **Python 3.8+**: `sudo apt install python3`
- **ADB**: `sudo apt install adb`
- **Android设备**: 已连接并启用USB调试

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · QUICK_START.md (reported line 72)May include surrounding context.

md
## 🔧 环境要求

### 必需组件
- **Python 3.8+**: `sudo apt install python3`
- **ADB**: `sudo apt install adb`
- **Android设备**: 已连接并启用USB调试

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installation and quick-start instructions tell users how to set up and run a Frida-based unpacker without warning that operation may require rooted devices, debugging access, altered app behavior, or interaction with protected memory. For a tool whose purpose is anti-debug bypass and extraction from protected apps, missing operational warnings can lead to unsafe system changes and unintentional misuse.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

安装依赖

bash
pip install frida-tools
sudo apt-get install adb

基本使用

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly promotes APK unpacking, anti-debug bypass, and memory extraction but does not include any warning about legal authorization, privacy exposure, device instability, or the risk of handling third-party intellectual property. In the context of a tool designed to defeat commercial protections, omission of these warnings materially increases the likelihood of misuse and unsafe operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The release notes advertise concrete anti-debug bypass, Frida injection, root memory extraction, and DEX dumping capabilities without any safety, authorization, or legal-use warning. In the context of an APK de-shelling and protection-bypass tool, this materially increases misuse risk because it normalizes offensive execution against third-party apps and devices while omitting prerequisites and potential harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage examples provide ready-to-run commands for unpacking and live instrumentation of target packages, including root and Frida strategies, but omit warnings about root privilege, anti-debug interference, device/app instability, and authorization requirements. Because the skill is explicitly designed to bypass protections on Android apps, operational examples without guardrails lower the barrier to misuse and unsafe deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The release notes prominently advertise memory extraction, direct reads from /proc//mem, dynamic unpacking, and anti-debug bypass capabilities, but they do not include any warning, authorization requirement, legal/ethical-use restriction, or safety disclosure. In the context of a skill explicitly designed to defeat Android protections and extract protected code from apps, this omission materially lowers friction for misuse and normalizes offensive use against third-party applications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The usage examples and surrounding release-note content explicitly describe anti-debug bypass, root memory extraction, and dynamic unpacking workflows without placing an immediate inline warning at the point of use. In a dual-use reverse-engineering skill, that omission increases the chance of unsafe or unauthorized use because users can copy commands directly from the usage section without seeing legal, authorization, and containment constraints.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SECURITY.md (reported line 88)May include surrounding context.

md
1. **Unauthorized Application Analysis**: Analyzing apps without permission
2. **Intellectual Property Theft**: Extracting proprietary code or assets
3. **Piracy**: Bypassing licensing or digital rights management
4. **Privacy Violation**: Extracting user data without consent
5. **Malware Development**: Creating or enhancing malicious software

## ⚖️ Compliance with ClawHub Policies

Static analysis

Detected: suspicious.obfuscated_code

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
scripts/root_memory_extractor_enhanced.py:50