apk-reverse
What this skill does
Android APK逆向分析工具,用于APK解包、Java反编译、smali修改、重打包、Frida动态Hook等
github/zhaoxuya520 - Security Misconfiguration - 23.3k stars
Threat analysis
Skill info
pkg:github/zhaoxuya520/reverse-skill@cf745b8?skill=apk-reverseAssessments (2)
Security Misconfiguration
Security Misconfiguration via local-llm-review
scripts/rebuild-sign-install.sh
使用默认的debug.keystore进行签名,且密码为'android',这可能导致签名密钥泄露,影响APK的完整性验证Security Misconfiguration via local-llm-review
scripts/decode.ps1
脚本中使用了PowerShell的远程执行功能,但未对输入参数进行充分的验证和过滤,可能存在命令注入风险Badge
Add the Anomity scan badge for apk-reverse to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of apk-reverse? Report an issue or request a rescan.




