Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/ShulkwiSEC/bb-hugenpx agentmods add skills/shulkwisec/bb-huge/ios-application-hooking-fridaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/shulkwisec/bb-huge/ios-application-hooking-frida)<a href="https://agentmods.dev/skills/shulkwisec/bb-huge/ios-application-hooking-frida"><img src="https://agentmods.dev/badge/skills/shulkwisec/bb-huge/ios-application-hooking-frida/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/shulkwisec/bb-huge/ios-application-hooking-frida"><img src="https://agentmods.dev/badge/skills/shulkwisec/bb-huge/ios-application-hooking-frida.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00057 | $0.02252 |
| Opus 5 | $0.00028 | $0.01126 |
| Sonnet 5 | $0.00011 | $0.00450 |
| Haiku 4.5 | $0.00006 | $0.00225 |
Grade A, and why
ios-application-hooking-frida scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- ios-application-hooking-frida — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 195 lines — stays where its author put it; the contents beside it link to each section on GitHub.
iOS Application Hooking (Frida)
When to Use
- When static analysis strings/binaries (via Hopper/Ghidra) are heavily obfuscated and you must observe exactly what the application is doing in memory dynamically.
- To bypass robust Jailbreak Detection mechanisms that force the target app to crash upon launch.
- To circumvent complex SSL Certificate Pinning, enabling you to intercept HTTPS traffic in Burp Suite without spending hours reverse-engineering native cryptographic functions.
Prerequisites
- Authorized scope and rules of engagement for the target environment
- Appropriate tools installed on the attack/analysis platform
- Understanding of the target technology stack and architecture
- Documentation template ready for findings and evidence capture
Workflow
Phase 1: Environment Setup (Jailbroken iOS)
# Concept: Frida operates via a client-server architecture. The Frida "Server" must be running
# as root on the target device, listening for commands from the attacker's "Client" (your PC).
# 1. On the Jailbroken iOS Device:
# Open Cydia/Sileo -> Add Source: `https://build.frida.re` -> Install "Frida!"
# 2. On the Attacker PC:
pip3 install frida-tools objection
# 3. Verify Connectivity via USB:
frida-ps -U
# Output: Lists all processes currently executing on the iPhone. Look for the target application (e.g., `TargetBankApp`).
Phase 2: Injecting Custom JavaScript Hooks (The Core Mechanics)
// Concept: We write JavaScript on our PC. Frida injects the Google V8 Engine into the
// iPhone's target application process, allowing our JS to seamlessly interact directly
// with the underlying Objective-C / Swift architecture.
// Scenario: The app calls `-(BOOL)isJailbroken;` which returns TRUE, crashing the app.
// We intercept that call right before it finishes and permanently overwrite the return value back to FALSE.
if (ObjC.available) {
// 1. Find the Class in the application memory
var JailbreakDetectionClass = ObjC.classes.JailbreakDetector;
// 2. Attach an Interceptor (Hook) to the specific method
Interceptor.attach(JailbreakDetectionClass['- isJailbroken'].implementation, {
onEnter: function(args) {
console.log("[+] Intercepted isJailbroken execution!");
},
onLeave: function(retval) {
console.log("[-] Original Return Value: " + retval);
// 3. The Override: Change the boolean `TRUE` (1) to `FALSE` (0)
var newRetval = ptr("0x0");
retval.replace(newRetval);
console.log("[+] Spofed Return Value: " + newRetval);
}
});
}
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 195 lines · 57 tokens per session scan A 7a9da873b8c0
ios-application-hooking-frida is a skill published in the GitHub repository ShulkwiSEC/bb-huge (22 stars, last pushed 1mo ago), licensed MIT. It adds 57 tokens to every session and 2,252 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
ios-application-hooking-frida
Execute dynamic instrumentation utilizing Frida to inject custom JavaScript into running iOS applications (IPAs) on jailbroken devices. Hook native functions, bypass SSL Pinning, bypass Jailbreak Detection, and manipulate in-memory data at runtime.
analyzing-ios-app-security-with-objection
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
Mobile Application Security
Android and iOS application security testing — static and dynamic analysis, APK/IPA inspection, OWASP MASVS/MASTG verification, secure-storage and transport review, and mobile malware triage for authorized assessments.
analyzing-ios-app-security-with-objection
Use when performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that enables security testers to interact with app internals without jailbreaking. Use when assessing iOS app security posture, bypassing client-side protections, dumping keychain items, inspecting…
analyzing-ios-app-security-with-objection
Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that enables security testers to interact with app internals without jailbreaking. Use when assessing iOS app security posture, bypassing client-side protections, dumping keychain items, inspecting filesystem…
analyzing-ios-app-security-with-objection
A security-testing guide for Objection, a tool that lets testers inspect and interact with an iOS app while it is running. It uses Frida and can work with jailbroken devices or specially prepared app packages.