≈420 tokens on demand. Your agent reads this file only when SKILL.md points to it.
Troubleshooting
Frida
"Unable to find application"
ideviceinstaller -l | grep -i <name>
frida-ps -Uai
frida -U -f <exact.bundle.id> --no-pause
"Frida server not running"
ssh root@<device>
/usr/sbin/frida-server & # or: launchctl load /Library/LaunchDaemons/re.frida.server.plist
# Verify from host:
frida-ps -U
"Failed to spawn: unable to access process"
- Non-jailbroken: repackage IPA with Frida Gadget:
objection patchipa --source app.ipa --codesign-signature "Apple Development: you"
- Mount developer disk image:
ideviceimagemounter /path/DeveloperDiskImage.dmg.
Frida crashes target on spawn
- Try
--realm emulated (for apps with Swift-concurrency heavy init).
- Load a small anti-debug Frida snippet first that overrides
ptrace to return 0 (see references/frida_ios_snippets.md).
- Use attach (not spawn) once app is foregrounded.
SSL Pinning — Universal Bypass Fails
- Enumerate:
ios hooking search classes Trust|SSL|Certificate|Pin.
class-dump + grep -iE 'pin|trust' the binary.
- Write a targeted hook for the found class/method.
- Rare: statically linked BoringSSL — hook C symbols (
SSL_CTX_set_verify).
Jailbreak Detection
> ios jailbreak disable (Objection).
- Install Liberty Lite or Shadow; add app to hide list.
frida -l scripts/jailbreak_bypass.js.
- Custom hook of the specific method in the app's
SecurityChecker class.
Proxy Not Intercepting App Traffic
- Confirm Wi-Fi proxy set and Burp CA trusted in Certificate Trust Settings.
- QUIC/HTTP3 → block UDP/443.
- App uses IP literals to bypass DNS → DNS override or iptables on proxy host.