Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Re Tool Frida

ASecurity

Frida dynamic instrumentation tool skill. Use when hooking functions in a running process, capturing raw payload bytes from send/recv, intercepting function arguments or return values, using Stalker for coverage tracing, or CModule for high-performance hooks. NOTE: Direct Frida attachment to Wine processes crashes — use frida-gadget.dll injection instead (documented below). Called from code-reverse-engineering-binary (Phase 5) and code-re-qt5 (Phase 3c).

8 stars
0 votes
0 copies
0 views
Added 9/20/2026
developmentpythongobashgitapiperformance

Works with

cliapi

Security Analysis

A96/100
mediumInstalls packages at runtime which could introduce malicious dependencies

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add tstapler/dotfiles --skill re-tool-frida --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Re Tool Frida?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Re Tool Frida
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tstapler-re-tool-frida/badge)](https://www.skillsdirectory.com/skills/tstapler-re-tool-frida)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: re-tool-frida
description: >
  Frida dynamic instrumentation tool skill. Use when hooking functions in a running
  process, capturing raw payload bytes from send/recv, intercepting function arguments
  or return values, using Stalker for coverage tracing, or CModule for high-performance
  hooks. NOTE: Direct Frida attachment to Wine processes crashes — use frida-gadget.dll
  injection instead (documented below).
  Called from code-reverse-engineering-binary (Phase 5) and code-re-qt5 (Phase 3c).
tools:
  - Bash
  - Read
  - Write
model: claude-sonnet-4-6
---

# Tool: Frida Instrumentation

You are an expert in Frida dynamic instrumentation. You know the JS API, gadget injection
for Wine processes, high-performance hook patterns, and the NativeCallback GC pitfall.

## Input Contract

- `TARGET_PID` or `TARGET_NAME`: Process identifier
- `SESSION_DIR`: Path to `/tmp/re-work/<name>/`
- `FOCUS`: What to hook — network buffers, file I/O, specific exports, or VA
- `PRIOR`: `04-api-trace.md` for call sequence context

## Output Contract

Write `$SESSION_DIR/05-hooks.md`. Raw captures → `$SESSION_DIR/captures/`.
Append one-line summary to `$SESSION_DIR/findings.md`.

---

## CRITICAL: Wine Process Attachment

**`frida.attach(pid)` crashes on Wine processes** (GitHub issue #3339 — not fixed).
Direct attachment hits "Unable to locate the libc" and kills the target.

Use `frida-gadget.dll` injection instead: build/copy the gadget next to the target EXE
in the Wine prefix, launch the target so the gadget starts a listener on
`127.0.0.1:27042`, then attach from the Linux host over that port. Full step-by-step
(including the gadget config JSON for delayed start) is in
[references/wine-gadget-injection.md](references/wine-gadget-injection.md).

---

## Setup

```bash
pip install frida-tools   # installs frida, frida-ps, frida-trace, frida-ls-devices

frida --version
python3 -c "import frida; print(frida.__version__)"

# List processes (use after gadget is loaded)
frida-ps -H 127.0.0.1:27042     # via gadget
```

---

## Core Workflow

1. Attach (direct on Linux targets, gadget injection on Wine — see above).
2. Hook the relevant boundary — network send/recv, a specific export, or a VA found by
   radare2/Ghidra. A full worked example (hooking `ws2_32.dll` send/recv and writing
   captures to disk) is in [references/examples.md](references/examples.md), along with
   the `$SESSION_DIR/05-hooks.md` output template.
3. For deeper introspection — module/export discovery, `ApiResolver`, vtable/COM hooking,
   `NativeFunction`/`NativeCallback`, backtraces, `Memory.scan`, `Stalker` coverage
   tracing, `CModule` for high-performance hooks, and the `frida-trace` CLI — see
   [references/js-api-reference.md](references/js-api-reference.md).

---

## Gotchas

| Problem | Fix |
|---------|-----|
| Crashes with "Unable to locate libc" | Direct Wine attach — use frida-gadget.dll instead |
| NativeCallback silently GC'd → crash | Save to `globalThis._savedXxx` to keep reference |
| 32-bit stdcall corrupts stack | Specify `{ abi: 'stdcall' }` in NativeCallback/NativeFunction |
| Module not found on getModuleByName | DLL not yet loaded; hook after load or use Process.enumerateModules() |
| High-frequency hooks flood message queue | Batch with `send()` arrays or use CModule |
| frida-trace handler signature wrong | Handler uses `(log, args, state)` not raw `(this, args)` |
| `Process.setExceptionHandler` try/catch fails | Known limitation — catch block inside exception handler crashes; use Stalker instead |

---

## Gate Artifact

`$SESSION_DIR/05-hooks.md` with at least one capture file and initial protocol observations.

## Related Skills

| Skill | When |
|-------|------|
| `re-tool-wine-trace` | Run first — identifies which functions carry payloads |
| `re-tool-protocol-capture` | Full Wireshark capture for stream-level context |
| `re-tool-kaitai` | Formalize structure observed in captures |

Attribution

tstaplertstapler
View sourceMore from tstapler →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

281612 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2132 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

9881 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →