AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Analyzing Android Malware With Apktool

skill-killvxk-cybersecurity-skills-zh-analyzing-android-malware-with-apktool · by killvxk

使用 apktool 进行反编译、jadx 恢复 Java 源码、androguard 进行权限分析,对 Android APK 恶意软件样本执行静态分析,包括清单检查和可疑 API 调用检测。

No reviews yet
0 installs
34 views
0.0% view→install

Install

$ agentstack add skill-killvxk-cybersecurity-skills-zh-analyzing-android-malware-with-apktool

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-killvxk-cybersecurity-skills-zh-analyzing-android-malware-with-apktool)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Analyzing Android Malware With Apktool? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

使用 Apktool 分析 Android 恶意软件

概述

以 APK 文件形式分发的 Android 恶意软件可通过静态分析提取权限、Activity、Service、广播接收器和可疑 API 调用,无需执行样本。本技能使用 androguard 进行编程化 APK 分析,识别危险权限组合、混淆代码模式、动态代码加载、基于反射的 API 调用以及网络通信指标。

前置条件

  • Python 3.9+,安装 androguard
  • apktool(用于资源反编译)
  • jadx(用于 Java 源码恢复,可选)
  • 隔离分析环境(虚拟机或沙箱)
  • 待分析的 APK 样本文件

工作流程

  1. 使用 androguard 解析 APK,提取清单元数据
  2. 枚举所请求的权限,标记危险权限组合
  3. 从清单中列出 Activity、Service、Receiver 和 Provider
  4. 扫描可疑 API 调用(反射、加密、短信、电话)
  5. 检测动态代码加载模式(DexClassLoader、Runtime.exec)
  6. 从字符串中提取硬编码 URL、IP 和 C2 指标
  7. 生成包含 MITRE ATT&CK 移动端映射的风险评估报告

输出格式

  • JSON 报告,包含权限分析、组件列表、可疑 API 调用、网络指标和风险评分
  • 从 APK 中提取的字符串和潜在 IOC

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.