smali-dex-patching

Installation
SKILL.md

Smali / DEX Patching

Patch the managed-code side of an Android APK: locate the check, edit the smali, rebuild, re-sign, install. Pair with mobile-technique for triage and target identification, offensive-tools/rev/jadx for the readable Java view, android-jni-ndk when the check lives in a native .so, and reversing-technique for deep obfuscated / packed samples.

Use only against APKs you are authorized to test.


When to activate

  • Confirmed pentest scope on an Android APK you can extract from a device or ship a build of.
  • Frida hook exists in theory but the target detects Frida (ptrace, /proc/self/status, TracerPid) — static patching is a resilient alternative.
  • Bug bounty writeup requires PoC via a rebuilt APK.
  • CTF challenge distributes a single .apk file with the flag or a check to defeat.
  • Confirming a vulnerability class ("this crypto key is embedded") by editing the check-in-place.

Not for: dynamic-only findings, native-code-only checks (use JNI/NDK skill + Frida + Ghidra), or app resigning without authorization on Play-distributed software.


Installs
5
GitHub Stars
22
First Seen
Sep 15, 2026
smali-dex-patching — aeondave/malskill