Android application-layer traffic capture · AI Agent skill repository
Grab TLS plaintext at the SSL_read / SSL_write boundary with Frida and export standard PCAP. Loadable by Claude Code / Codex as a Skill, or installable into Claude Code as a Plugin via Marketplace.
This project is a fork/adaptation of r0ysue/r0capture — "安卓应用层抓包通杀脚本" (Android application-layer packet-capture universal script).
- Original author & upstream: r0ysue/r0capture (Apache License 2.0)
- Upstream license: Apache License 2.0
- This repository is a second development (二次开发) of the upstream code, rewritten to be AI-agent-friendly: it keeps the capture engine (
r0capture.py,script.js,myhexdump.py) and adds agent onboarding —SKILL.md,CLAUDE.md,.claude-plugin/,agents/openai.yaml— plus a 285+ page teaching docs site. - Original code belongs to its upstream author. Respect the upstream license when redistributing.
本项目为 r0ysue/r0capture 的复刻与二次开发,英文版见本文件,简体中文版见 README_zh.md。
Android application-layer traffic capture — Frida-based, grabs TLS plaintext at the SSL_read / SSL_write boundary (no CA trust changes, no pinning workarounds, hardening-agnostic) and exports hand-crafted PCAP for Wireshark.
This repository is a fork / second development of r0ysue/r0capture, reworked to be AI-agent-oriented. It is also an AI Agent skill repository: Claude Code / Codex can use it as a Skill, or it can be installed into Claude Code as a Plugin via Marketplace.
- Authorization required: for authorized Android security testing only. Captured traffic contains plaintext — treat it as sensitive data.
- Platform: Android 7–16 (rooted device + matching frida-server).
- License: Apache License 2.0 (same as upstream). Upstream: r0ysue/r0capture.
The repo ships a .claude-plugin/ manifest. Register the r0capture-android skill into Claude Code:
/plugin marketplace add android-security-engineer/r0capture-skills
/plugin install r0capture-android@r0capture-skills
Claude Code then auto-discovers the root SKILL.md (skill name r0capture-android) and agents run the capture workflow against the skill manual when triggered. You can also paste the marketplace into the Plugin panel ("Add").
After cloning (or cd-ing into) the repo, Claude Code automatically loads CLAUDE.md and SKILL.md. With authorization in place, an agent can:
- Read
SKILL.mdfor the complete manual — Attach / Spawn / remote-Hworkflow selection, prerequisites, limitations, safe-modification rules; - Install dependencies, push frida-server, run captures, analyze the resulting PCAP;
- Modify
r0capture.py/script.js/myhexdump.pyaccording toSKILL.md's contract.
agents/openai.yaml declares Codex-compatible metadata (display_name / short_description / default_prompt / allow_implicit_invocation: true). Point Codex's AGENTS config at this repo and it can implicitly invoke the skill to configure and run r0capture.
# 1. Host dependencies
python3 -m pip install -r requirements.txt
# 2. Device prep (rooted phone or cloud phone)
# Download a frida-server matching the host frida major version: https://github.com/frida/frida/releases
adb push frida-server /data/local/tmp/frida-server
adb shell "chmod 755 /data/local/tmp/frida-server"
adb shell "su -c 'nohup /data/local/tmp/frida-server -l 0.0.0.0:27042 >/data/local/tmp/frida.log 2>&1 &'"
# 3. Capture (attach to a running app)
python3 r0capture.py -U <process-name-or-pid> -v -p out.pcap
# Spawn mode: python3 r0capture.py -U -f <package-name> -v -p startup.pcap
# Self-check: python3 r0capture.py -U <target> --selftest -vOne command yields plaintext out of the box — at the
SSL_read/SSL_writeboundary, no cert-trust changes, no pinning handling:
python3 r0capture.py -U <app> -v -p out.pcap # then open out.pcap in WiresharkFull manual in SKILL.md; teaching docs site (285+ pages): https://android-security-engineer.github.io/r0capture-skills/docs/
| Path | Purpose |
|---|---|
SKILL.md |
Agent skill manual (skill name r0capture-android) |
agents/openai.yaml |
Codex-compatible declaration |
.claude-plugin/ |
Claude Code Plugin / Marketplace manifest |
CLAUDE.md |
Agent behavior guidance for this repo |
requirements.txt |
Host Python dependencies |
r0capture.py / script.js / myhexdump.py |
Capture implementation (from upstream) |
website/ |
VitePress teaching docs site (285+ pages) |
mo-website/ |
React landing page |
README_zh.md |
Simplified Chinese README |
README.legacy.zh.md |
Verbatim archive of the original (Chinese) README |
- Wide coverage: HTTP/HTTPS, WebSocket/WSS, FTP(S), XMPP, IMAP(S), SMTP(S), Protobuf and other application-layer protocols; OkHttp 1/3/4, HttpUrlConnection, Retrofit, Volley and other frameworks.
- Ignores: certificate validation/binding (pinning), hardening (whole-app shell, second-generation shell, VMP).
- Export: hand-crafted PCAP (LINKTYPE_IPV4 228), directly analyzable in Wireshark; also client certificate (
.p12) export and send/receive function location. - Limitations: private / statically-linked SSL stacks (WebView, Flutter, mini-programs, …) may expose no symbols; HTTP/2, HTTP/3 and multi-process child processes have limited support — see
SKILL.mdand the docs site.
The original human-facing feature announcement by the upstream author is archived verbatim in README.legacy.zh.md, mirrored on the docs site: https://android-security-engineer.github.io/r0capture-skills/docs/source/legacy-README.html
Apache License 2.0 — this is a second development of r0ysue/r0capture (also Apache-2.0). Respect the upstream license and attribution when redistributing.