Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
yfe404 avatar

Frida 17

  • 1.7k installs
  • 5 repo stars
  • Updated December 26, 2025
  • yfe404/frida-17-skill

frida-17 is an agent skill that frida 17 javascript api compatibility checker and fixer. use when writing, reviewing, or fixing frida scripts, especially when migrating from older frida versions. detects deprecated apis

About

frida-17 is an agent skill from yfe404/frida-17-skill that frida 17 javascript api compatibility checker and fixer. use when writing, reviewing, or fixing frida scripts, especially when migrating from older frida versions. detects deprecated apis removed in f. # Frida 17 Scripting Guide This skill helps write and fix Frida scripts compatible with Frida 17.0.0 (released May 2025). ## Breaking Changes in Frida 17 ### 1. Static Module Methods - REMOVED ```javascript // OLD - No longer works in Frida 17 Module.findBaseAddress('libriver.so') Module.getBaseAddress('libriver.so') Module.findExportByName(nul Developers invoke frida-17 during ship/security work for security tasks. The skill documents triggers, prerequisites, and step-by-step workflows grounded in SKILL.md. Compatible with Claude Code, Cursor, and Codex agent runtimes that load marketplace skills. Review the Security Audits panel on this listing before installing in production environments.

  • This skill helps write and fix Frida scripts compatible with Frida 17.0.0 (released May 2025).
  • Breaking Changes in Frida 17
  • 1. Static Module Methods - REMOVED
  • // OLD - No longer works in Frida 17
  • Module.findBaseAddress('libriver.so')

Frida 17 by the numbers

  • 1,670 all-time installs (skills.sh)
  • +70 installs in the week ending Aug 5, 2026 (Skillselion tracking)
  • Ranked #315 of 2,203 Security skills by installs in the Skillselion catalog
  • Security screen: CRITICAL risk (skills.sh audit)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
At a glance

frida-17 capabilities & compatibility

Capabilities
this skill helps write and fix frida scripts com · breaking changes in frida 17 · 1. static module methods removed · // old no longer works in frida 17 · module.findbaseaddress('libriver.so')
Use cases
orchestration
From the docs

What frida-17 says it does

This skill helps write and fix Frida scripts compatible with Frida 17.0.0 (released May 2025).
SKILL.md
Module.findExportByName('libc.so', 'open')
SKILL.md
// NEW - Use Process and instance methods instead
SKILL.md
npx skills add https://github.com/yfe404/frida-17-skill --skill frida-17

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1.7k
repo stars5
Security audit2 / 3 scanners passed
Last updatedDecember 26, 2025
Repositoryyfe404/frida-17-skill

What it does

Frida 17 JavaScript API compatibility checker and fixer. Use when writing, reviewing, or fixing Frida scripts, especially when migrating from older Frida versions. Detects deprecated APIs removed in F

Who is it for?

Developers working on security during ship tasks.

Skip if: Tasks outside Security scope described in SKILL.md.

When should I use this skill?

Frida 17 JavaScript API compatibility checker and fixer. Use when writing, reviewing, or fixing Frida scripts, especially when migrating from older Frida versions. Detects deprecated APIs removed in F

What you get

Completed security workflow aligned with SKILL.md steps.

  • Frida 17-compatible hook scripts
  • deprecated API replacement map

By the numbers

  • Targets Frida 17.0.0 released May 2025
  • Covers 3 API areas: Module, Memory, and Process

Files

SKILL.mdMarkdownGitHub ↗

Frida 17 Scripting Guide

This skill helps write and fix Frida scripts compatible with Frida 17.0.0 (released May 2025).

Breaking Changes in Frida 17

1. Static Module Methods - REMOVED

// OLD - No longer works in Frida 17
Module.findBaseAddress('libriver.so')
Module.getBaseAddress('libriver.so')
Module.findExportByName(null, 'open')
Module.findExportByName('libc.so', 'open')
Module.getExportByName(null, 'open')
Module.ensureInitialized('libc.so')
Module.enumerateExports('libc.so')
Module.enumerateSymbols('libc.so')

// NEW - Use Process and instance methods instead
var lib = Process.findModuleByName('libriver.so');  // returns Module or null
var lib = Process.getModuleByName('libriver.so');   // throws if not found
lib.base                                             // module base address
lib.findExportByName('open')                        // returns address or null
lib.getExportByName('open')                         // throws if not found
lib.enumerateExports()                              // returns array
lib.enumerateSymbols()                              // returns array

2. Static Memory Methods - REMOVED

// OLD - No longer works
Memory.readU32(ptr)
Memory.writeU32(ptr, value)

// NEW - Use NativePointer instance methods
ptr.readU32()
ptr.writeU32(value)

3. Legacy Enumeration APIs - REMOVED

// OLD - Callback style removed
Process.enumerateModules({ onMatch: fn, onComplete: fn })
Process.enumerateModulesSync()

// NEW - Returns array directly
Process.enumerateModules()

4. Reserved Function Names - DO NOT OVERRIDE

The following are built-in Frida functions. Defining custom functions with these names causes: TypeError: cannot define variable 'hexdump'

Reserved names:

  • hexdump - Use dumpHex instead for custom hex dump functions
  • ptr - pointer constructor shorthand
  • NULL - null pointer constant
// BAD - conflicts with built-in
function hexdump(ptr, len) { ... }

// GOOD - use different name
function dumpHex(ptr, len) { ... }

NativePointer Methods (Valid in Frida 17)

Conversion:

  • toInt32() - cast to signed 32-bit integer
  • toNumber() - convert to JavaScript number
  • toString([radix]) - convert to string

NOT available:

  • toUInt32() - DOES NOT EXIST, use toInt32() for sizes < 2^31

Memory reading:

  • readU8(), readS8(), readU16(), readS16()
  • readU32(), readS32(), readU64(), readS64()
  • readByteArray(length) - returns ArrayBuffer
  • readPointer(), readCString(), readUtf8String()

Memory writing:

  • writeU8(value), writeS8(value), etc.
  • writeByteArray(bytes) - bytes must be ArrayBuffer or JS array
  • writePointer(ptr), writeUtf8String(str)

Pointer arithmetic:

  • add(rhs), sub(rhs), and(rhs), or(rhs), xor(rhs)
  • shr(n), shl(n), not()
  • isNull(), equals(rhs), compare(rhs)

Java Bridge API (Unchanged in Frida 17)

Java.perform(function() {
    var MyClass = Java.use('com.example.MyClass');

    // Hook with overload
    MyClass.myMethod.overload('int', 'java.lang.String').implementation = function(a, b) {
        console.log('Called with: ' + a + ', ' + b);
        // Call original
        return this.myMethod.overload('int', 'java.lang.String').call(this, a, b);
    };

    // Hook all overloads
    MyClass.myMethod.overloads.forEach(function(overload) {
        overload.implementation = function() {
            return overload.apply(this, arguments);
        };
    });
});

Java byte[] handling: Java byte arrays cannot be passed directly to Memory.alloc().writeByteArray(). Convert manually:

// BAD - throws "expected a buffer-like object"
var hex = dumpHex(Memory.alloc(javaByteArray.length).writeByteArray(javaByteArray), len);

// GOOD - iterate and convert
var hex = "";
for (var i = 0; i < javaByteArray.length; i++) {
    hex += ("0" + (javaByteArray[i] & 0xff).toString(16)).slice(-2);
}

Common Patterns for Frida 17

Waiting for a library to load

function waitForLibrary(libName, callback) {
    var lib = Process.findModuleByName(libName);
    if (lib) {
        callback(lib.base);
        return;
    }
    var pollInterval = setInterval(function() {
        var lib = Process.findModuleByName(libName);
        if (lib) {
            clearInterval(pollInterval);
            callback(lib.base);
        }
    }, 500);
}

Hooking libc functions

var libc = Process.findModuleByName('libc.so');
var open = libc ? libc.findExportByName('open') : null;
if (open) {
    Interceptor.attach(open, {
        onEnter: function(args) {
            console.log('open(' + args[0].readCString() + ')');
        }
    });
}

Custom hex dump function

function dumpHex(ptr, len) {
    if (!ptr || ptr.isNull()) return 'null';
    try {
        var bytes = ptr.readByteArray(len);
        if (!bytes) return 'null';
        var arr = new Uint8Array(bytes);
        var hex = '';
        for (var i = 0; i < arr.length; i++) {
            hex += ('0' + arr[i].toString(16)).slice(-2);
        }
        return hex;
    } catch (e) {
        return 'error: ' + e;
    }
}

Checklist for Frida 17 Compatibility

When reviewing a Frida script, check for:

1. [ ] Module.findBaseAddress() -> Process.findModuleByName().base 2. [ ] Module.getBaseAddress() -> Process.getModuleByName().base 3. [ ] Module.findExportByName(null, name) -> Process.findModuleByName('libc.so').findExportByName(name) 4. [ ] Module.findExportByName(lib, name) -> Process.findModuleByName(lib).findExportByName(name) 5. [ ] Module.enumerateExports(lib) -> Process.getModuleByName(lib).enumerateExports() 6. [ ] Module.enumerateSymbols(lib) -> Process.getModuleByName(lib).enumerateSymbols() 7. [ ] Memory.readU32(ptr) -> ptr.readU32() 8. [ ] toUInt32() -> toInt32() (toUInt32 never existed) 9. [ ] function hexdump() -> function dumpHex() (name conflict) 10. [ ] Java byte[] with writeByteArray() -> manual hex conversion

References

Related skills

FAQ

What does frida-17 do?

Frida 17 JavaScript API compatibility checker and fixer. Use when writing, reviewing, or fixing Frida scripts, especially when migrating from older Frida versions. Detects deprecated APIs removed in F

When should I use frida-17?

During ship security work for security.

Is frida-17 safe to install?

Review the Security Audits panel on this listing before production use.

Securityappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.