Patr1ck-S

iOS Reverse Engineering Skill — Documentation skill for Claude Code

Documentation community

Claude Code 的 iOS 授权静态逆向分析 Skill.

How to install iOS Reverse Engineering Skill

This entry records only its repository, not the path inside it, so there is no exact command to give. Open Patr1ck-S/ios-reverse-engineering-skill and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What iOS Reverse Engineering Skill does

Claude Code 的 iOS 授权静态逆向分析 Skill。支持分析 IPA、Mach-O、.framework、.dylib、.dSYM,提取 Info.plist、entitlements、URL Schemes、embedded frameworks、Mach-O 架构、load commands、Objective-C/Swift 符号、API 端点线索,并生成 Markdown 报告。可选接入 IDA Pro MCP 进行深度的函数/字符串/xref/调用链分析。

Alternatives in Documentation

  • 会话管理(Session Manager)需求文档(PRD / Markdown) — 目标:对 Codex / Claude Code 的本地会话记录进行可视化管理,并提供“一键复制 / 一键终端恢复”能力 31.7k ★
  • Repo Recap — Generate a structured recap of the repository state: open PRs, open issues, recent releases, and executive sum 11.9k ★
  • Ars Format Convert — ARS academic-paper format-convert mode — convert to LaTeX / DOCX / PDF / Markdown 4.5k ★

README

ios-reverse-engineering-skill

面向 Claude Code 的 iOS 授权静态逆向分析 Skill。

该 Skill 用于在授权场景下分析 IPA、`.app`、Mach-O、`.framework`、`.dylib`、`.dSYM` 等 iOS 产物,并输出结构化报告。基础分析不依赖 IDA Pro;IDA Pro MCP 只是可选增强能力,没有安装 IDA 或 `ida-pro-mcp` 时,基础静态分析仍然可以正常运行。

功能概览

  • 解包 IPA,并识别 .app 路径。
  • 提取 Info.plist、Bundle ID、可执行文件名、版本信息。
  • 提取 entitlements、URL schemes、associated domains。
  • 枚举 embedded frameworks、dylibs、app extensions。
  • 分析 Mach-O 架构、load commands、linked libraries、symbols、strings。
  • 扫描 Objective-C 类名、selector、Swift 符号和常见框架线索。
  • 提取 hardcoded URLs、domains、REST path、GraphQL、WebSocket、REST client 线索。
  • 生成 analysis-report.md 和 endpoints.json。
  • 可选接入 IDA Pro MCP,对 Mach-O 或 IDB 做函数、字符串、xref、caller/callee 和网络证据深度分析。

安全边界

本插件只用于授权分析。

不会实现或鼓励以下行为:

  • 绕过 FairPlay DRM 或应用商店加密。
  • 盗版解密或规避法律限制。
  • 窃取账号、密码、token、cookie、session 等凭证。
  • 越权访问、攻击、探测、重放或 fuzz 真实服务。
  • 绕过证书绑定、证书校验或其他运行时防护。

如果二进制疑似加密,插件只会报告分析限制,并提示使用授权的 debug、enterprise、decrypted build 或源码产物继续分析。

安装方式

从远程 marketplace 添加并安装:

/plugin marketplace add Patr1ck-S/ios-reverse-engineering-skill
/plugin install ios-reverse-engineering@patr1ck-iosrev-skills
/reload-plugins
/ios-reverse-engineering:ios-reverse-engineering ./target.ipa

本仓库的 marketplace manifest name 是 `patr1ck-iosrev-skills`。如果你的 Claude Code 按 `.claude-plugin/marketplace.json` 中的名称解析 marketplace,可以使用:

/plugin install ios-reverse-engineering@patr1ck-iosrev-skills

本地测试

在本仓库父目录执行:

/plugin marketplace add ./ios-reverse-engineering-skill
/plugin install ios-reverse-engineering@patr1ck-iosrev-skills
/reload-plugins
/ios-reverse-engineering:ios-reverse-engineering ./target.ipa

基础分析命令

分析 IPA、`.app`、Mach-O、framework、dylib 或 dSYM:

/ios-reverse-engineering:ios-reverse-engineering ./target.ipa

指定输出目录:

/ios-reverse-engineering:ios-reverse-engineering ./target.ipa ./ios_analysis_out

默认输出目录是:

ios_analysis_out

主要输出文件:

ios_analysis_out/analysis-report.md
ios_analysis_out/endpoints.json