Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Iphone Malware Scan

ASecurity

End-to-end iOS malware/spyware forensic assessment of a non-jailbroken iPhone from a Mac. Installs tooling (libimobiledevice + Mobile Verification Toolkit), pulls crash logs, creates a full ENCRYPTED device backup (auto-resuming on lock/disconnect), decrypts it, runs MVT against every spyware IOC feed (Pegasus, Predator, Candiru, Cellebrite, Intellexa, stalkerware, ...), sweeps every file in the backup manifest, analyzes crash logs for injected dylibs, and produces an assessment report. Use w...

2 stars
0 votes
0 copies
1 views
Added 9/19/2026
developmentpythonrustgitsecurity

Security Analysis

A100/100

Pro scans all 11 files and shows the line behind each finding

Scanned 9/19/2026

$npx -y skills add lordx64/iphone-malware-assessment --skill iphone-malware-scan --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Iphone Malware Scan?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Iphone Malware Scan
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lordx64-iphone-malware-scan/badge)](https://www.skillsdirectory.com/skills/lordx64-iphone-malware-scan)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: iphone-malware-scan
description: >-
  End-to-end iOS malware/spyware forensic assessment of a non-jailbroken iPhone
  from a Mac. Installs tooling (libimobiledevice + Mobile Verification Toolkit),
  pulls crash logs, creates a full ENCRYPTED device backup (auto-resuming on
  lock/disconnect), decrypts it, runs MVT against every spyware IOC feed
  (Pegasus, Predator, Candiru, Cellebrite, Intellexa, stalkerware, ...), sweeps
  every file in the backup manifest, analyzes crash logs for injected dylibs,
  and produces an assessment report. Use when the user suspects their iPhone is
  compromised, asks to check for spyware/Pegasus/stalkerware, or wants a full
  forensic health check of an iPhone connected over USB.
version: 1.0.0
metadata:
  openclaw:
    emoji: "🛡️"
    homepage: https://github.com/lordx64/iphone-malware-assessment
    os:
      - macos
    requires:
      bins:
        - brew
        - python3
    install:
      - brew: libimobiledevice
      - brew: pipx
    primaryEnv: BACKUP_PASSWORD
    envVars:
      - name: BACKUP_PASSWORD
        required: true
        description: >-
          Password used to enable and open the encrypted iPhone backup. Cannot
          be recovered if lost. Required for the backup/decrypt steps.
      - name: WORKDIR
        required: false
        description: >-
          Directory for all output (crash logs, backup, decrypted data,
          results). Defaults to ./iphone-assessment.
---

# iPhone malware/spyware assessment

This skill performs a full forensic assessment of a **non-jailbroken iPhone**
connected to a **Mac** over USB. It is defensive/diagnostic: the user owns the
device. All scripts live in `scripts/` next to this file.

## What it can and cannot do (state this to the user)

- iOS sandboxing means **no app can read another app's memory**, and mandatory
  code signing means a foreign dylib **cannot be injected into an app without a
  jailbreak**. So "build an app to inspect WhatsApp" is not possible — the
  real check is a forensic backup scan, which this skill automates.
- MVT matches against **known** spyware indicators. A clean result is strong
  evidence but cannot prove the absence of an unknown zero-day. Say this.

## Prerequisites

- macOS with Homebrew installed.
- An iPhone + USB cable. The user must **unlock the phone**, tap **Trust**, and
  keep it **unlocked and awake** during the backup (Auto-Lock → Never).
- A backup password. If backup encryption is not already enabled, this skill
  turns it on with a password the user provides — capture it and warn them it
  cannot be recovered if lost.

## How to run it

Prefer the orchestrator, driven from this skill folder (`scripts/` is alongside
this file):

```sh
BACKUP_PASSWORD='<user-chosen-password>' \
WORKDIR="$PWD/iphone-assessment" \
  zsh scripts/run-all.sh
```

The backup and decrypt steps can each take a long time and produce tens of GB.
Run long steps in the background and monitor for completion (watch for
`Manifest.db` appearing under `WORKDIR/backup/<UDID>/`).

## Running step by step (when you need control or a step fails)

1. `zsh scripts/01-preflight.sh` — install/upgrade libimobiledevice + MVT, fetch latest IOCs.
2. `zsh scripts/02-pull-crashlogs.sh "$WORKDIR"` — pull `.ips` crash logs (non-destructive).
3. `BACKUP_PASSWORD=... zsh scripts/03-backup.sh "$WORKDIR"` — full encrypted backup, auto-resumes on lock/disconnect.
4. `BACKUP_PASSWORD=... zsh scripts/04-decrypt.sh "$WORKDIR"` — decrypt for scanning.
5. `zsh scripts/05-scan.sh "$WORKDIR"` — MVT check-backup + explicit check-iocs across all feeds.
6. `python3 scripts/06-analyze-crashes.py "$WORKDIR/crashlogs" WhatsApp` — foreign-dylib / abnormal-kill scan.
7. `python3 scripts/07-assess.py "$WORKDIR/mvt-results" --json "$WORKDIR/assessment-summary.json"` — final report.

## Handling the common failures

- **`Error Code 208: Device locked`** during backup → the phone locked. Tell the
  user to unlock it and set Auto-Lock → Never; step 3 retries automatically.
- **`Could not receive from mobilebackup2 (-4)`** → USB dropped / device slept.
  Reconnect; step 3 resumes from what was already transferred.
- **Backup has no `Manifest.db`** → it did not finish; it is unusable for
  scanning. Re-run step 3 to completion.

## Interpreting results (how to report to the user)

- **Real IOC match** = an entry in a `*_detected.json` with a non-null
  `matched_indicator`. This is the only thing that indicates known spyware.
  Treat any as serious; direct the user to Amnesty's Security Lab.
- **Heuristic notes** (e.g. "Lockdown mode disabled") have
  `matched_indicator: null` — these are context/hardening advice, NOT detections.
- The assessment (step 7) separates these automatically and prints a verdict,
  plus the full-manifest file sweep (unknown domains, jailbreak/hook artifacts,
  dylibs outside app bundles) and a coverage table proving what was examined.

## Cleanup

`WORKDIR/backup` and `WORKDIR/decrypted` hold the user's personal data and can be
very large. Offer to delete them when finished; never delete without asking.
The `mvt-results/` JSON is small and safe to keep for review.

Attribution

lordx64lordx64
View sourceSee grades on GitHubMore from lordx64 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

285172 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10341 votes
View all in development →