# How reverse-skill Handles APK and Binary Security Targets: A Complete Routing Guide

> Discover how reverse-skill routes APKs and binaries using its three-axis matrix. This guide explains the automatic dispatching to specific workflows for efficient reverse engineering.

- Repository: [ZhaoXu/reverse-skill](https://github.com/zhaoxuya520/reverse-skill)
- Tags: how-to-guide
- Published: 2026-08-29

---

**`reverse-skill` routes security targets through a three-axis matrix that matches target type, user intent, and toolchain against entries in [`config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/config/routing.json), automatically dispatching APKs to the `apk-reverse/` skill and generic binaries to `ida-reverse/` or `radare2/` workflows.**

The `zhaoxuya520/reverse-skill` repository provides a structured framework for reverse engineering that eliminates guesswork when approaching different artifacts. Instead of forcing analysts to manually select tools, the system employs a strictly enforced routing mechanism defined in [`routing.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md) and implemented by `master-route.ps1` (or [`master-route.sh`](https://github.com/zhaoxuya520/reverse-skill/blob/main/master-route.sh)). This ensures that Android applications follow a dedicated mobile workflow while ELF binaries, DLLs, and executables route through traditional static and dynamic analysis pipelines.

## The Three-Axis Routing Matrix

At the heart of `reverse-skill` is a decision matrix that lives in [`routing.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md) and [`config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/config/routing.json). The master script reads this configuration to determine which submodule handles a given target.

The matrix evaluates three dimensions:

- **Target type**: APK, ELF, PE, Mach-O, or language-specific variants (Go/Rust)
- **User intent**: Static analysis, dynamic instrumentation, decompilation, or patching
- **Toolchain**: Availability of IDA Pro, Ghidra, radare2, or Frida

If the matrix finds a match, the corresponding [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md) file loads before any action executes. When no match exists, the system proposes creating a new skill rather than applying an inappropriate workflow.

## APK Analysis Workflow

Android packages follow the most complex route in the repository. According to [line 22 of [`routing.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md)](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md#L22), APKs dispatch to the `apk-reverse/` skill, which orchestrates a multi-stage CLI pipeline.

### Decoding and Extraction

The workflow begins by decompiling the APK to recover Java source and Smali bytecode. The `decode.ps1` script automates this by invoking `jadx` for high-level Java reconstruction and `apktool` to extract [`AndroidManifest.xml`](https://github.com/zhaoxuya520/reverse-skill/blob/main/AndroidManifest.xml) and resources.

```powershell

# Decode APK and extract Java + smali

pwsh -File "<skill-root>\apk-reverse\scripts\decode.ps1" -ApkPath "C:\Downloads\target.apk" -Clean

# Summarize manifest permissions and components

pwsh -File "<skill-root>\apk-reverse\scripts\manifest-summary.ps1" -ManifestPath "apktool_out\AndroidManifest.xml"

```

### Native Library Handling

When an APK contains `.so` libraries in `lib/` directories, the routing logic can pivot to native analysis. The workflow jumps to either `ida-reverse/` for deep static analysis or `radare2/` for quick command-line inspection of the extracted shared objects.

```bash

# Quick triage of native library after APK extraction

r2 -A apktool_out\lib\armeabi-v7a\libnative.so

```

### Dynamic Instrumentation

For runtime analysis, the `frida-run.ps1` helper standardizes device communication and script injection. This handles USB device selection, process spawning, and JavaScript hook attachment uniformly across different APK targets.

```powershell

# Hook Java methods at runtime with Frida

pwsh -File "<skill-root>\apk-reverse\scripts\frida-run.ps1" -Usb -Spawn -Package com.example.app -ScriptPath "hooks\login.js"

```

### Repackaging and Signing

After modification, `rebuild-sign-install.ps1` handles the complete rebuild pipeline: it reconstructs the APK, aligns resources with `zipalign`, applies cryptographic signing, and optionally pushes to a connected device for immediate testing.

## Generic Binary Analysis

Executables, DLLs, and ELF files route differently than APKs. As documented in [line 23 of [`routing.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md)](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md#L23), these targets default to the `ida-reverse/` skill with `radare2/` serving as the command-line alternative.

### Static Decompilation with IDA Pro

The primary workflow leverages IDA Pro for deep static analysis, including cross-reference graphs and symbolic inspection. When IDA is unavailable, the system falls back to Ghidra. The [`ida-reverse/scripts/analyze.py`](https://github.com/zhaoxuya520/reverse-skill/blob/main/ida-reverse/scripts/analyze.py) script enables headless automation for batch processing.

```bash

# Headless IDA analysis

idapython -S /path/to/ida-reverse/scripts/analyze.py -A /tmp/sample.bin

```

### Rapid CLI Triage with radare2

For environments without commercial tools or for quick preliminary analysis, `radare2` provides immediate value. The routing matrix recognizes this toolchain for string extraction, disassembly, and basic debugging capabilities described in [[`reverse-engineering/tools.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/reverse-engineering/tools.md)](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/reverse-engineering/tools.md).

```bash

# Automated analysis and disassembly at entry point

r2 -A -c "aaa; pdf @ entry0" /tmp/sample.bin

# Extract strings for keyword hunting

rabin2 -z /tmp/sample.bin
strings /tmp/sample.bin | grep -iE "flag|secret"

```

### Dynamic Binary Instrumentation

While static analysis handles code structure, dynamic inspection uses Frida, GDB, or specialized frameworks. The [`tools-dynamic.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/tools-dynamic.md) reference details how to apply these across both APKs and standalone binaries for behavior observation.

## Stripped Go and Rust Binaries

A special subtype exists for binaries compiled from Go or Rust that have been stripped of symbols. Rather than treating these as generic binaries, [line 41 of [`routing.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md)](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md#L41) routes them to `go-rust-reverse/`.

This skill applies language-specific recovery tools before standard analysis. **GoReSym** reconstructs Go symbol tables, panic strings, and runtime metadata that stripping removes. Only after this recovery phase does the workflow hand off to IDA Pro or Ghidra for normal disassembly.

```bash

# Recover Go symbols before IDA analysis

gorec -i /tmp/go_binary -o symbols.txt

# Load with Go plugin support

idat -S/go-plugin/load_gosymbols.py /tmp/go_binary

```

For Rust binaries, similar helpers parse panic handlers and standard library patterns to restore meaningful function names and structure definitions lost during compilation.

## Summary

- **`reverse-skill` uses a strict routing matrix** defined in [`config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/config/routing.json) and [`routing.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/routing.md) to match targets with appropriate analysis skills.
- **APKs route to `apk-reverse/`**, which automates `jadx`, `apktool`, Frida, and signing workflows through PowerShell scripts like `decode.ps1` and `frida-run.ps1`.
- **Generic binaries route to `ida-reverse/`** or `radare2/` for static analysis, with dynamic options available through Frida and GDB.
- **Stripped Go/Rust binaries receive special handling** via `go-rust-reverse/` and tools like GoReSym before entering standard decompilation workflows.
- **The master script enforces this routing** through `master-route.ps1`/[`master-route.sh`](https://github.com/zhaoxuya520/reverse-skill/blob/main/master-route.sh), ensuring analysts never apply inappropriate tools to a target format.

## Frequently Asked Questions

### How does reverse-skill decide which analysis tools to use for a specific file?

The system consults [`config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/config/routing.json), which maps file signatures and target types to specific skill directories. For APKs, it checks for the ZIP signature and [`AndroidManifest.xml`](https://github.com/zhaoxuya520/reverse-skill/blob/main/AndroidManifest.xml); for ELF files, it examines the magic bytes and optionally detects Go/Rust metadata. The `master-route.ps1` script then loads the corresponding [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md) file before executing any commands.

### Can reverse-skill handle APKs that contain both Java and native code?

Yes. The `apk-reverse/` workflow first extracts all components including `.so` files from the `lib/` directory. After initial decompilation with `jadx` and `apktool`, analysts can pivot to `ida-reverse/` or `radare2/` workflows for the native libraries while maintaining the context of the Java layer. The `frida-run.ps1` script supports hooking both Java methods via the JVM and native functions via the embedded libraries.

### What happens if a binary type isn't listed in the routing matrix?

If `master-route.ps1` cannot find a matching entry in [`config/routing.json`](https://github.com/zhaoxuya520/reverse-skill/blob/main/config/routing.json), it halts execution and prompts the user to define a new skill module rather than forcing a mismatched analysis workflow. This prevents analysts from accidentally running Android-specific tools on Windows PE files or applying generic binary analysis to specialized firmware formats.

### Does reverse-skill require commercial tools like IDA Pro?

No. While the `ida-reverse/` skill provides advanced workflows for IDA Pro and Ghidra, the routing matrix explicitly supports `radare2` as a full alternative for command-line environments. The [`reverse-engineering/tools.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/reverse-engineering/tools.md) file documents equivalent open-source commands for strings analysis, disassembly, and debugging that function without proprietary software.