Skip to content

feat: add /quark and /quark-rule-gen Claude Code skills - #947

Merged
haeter525 merged 5 commits into
masterfrom
add-quark-ai-plugin-skills
Jul 25, 2026
Merged

haeter525 merged 5 commits into
masterfrom
add-quark-ai-plugin-skills

Conversation

@haeter525

@haeter525 haeter525 commented Jul 5, 2026 •

Copy link
Copy Markdown
Member

Description

Adds two Claude Code skills that let AI drive Quark Engine directly — running analysis on APKs and generating detection rules — packaged as a Claude Code plugin for easy install.

  1. /quark:analysis — maps a natural-language request to the correct quark CLI flags, prints the command and raw output, then offers next steps
  2. /quark:rule-gen — guides the AI through reading decompiled code, formatting Dalvik descriptors, and validating a generated rule against a real APK before outputting it

Install

  1. Claude Code installed.
  2. Quark-Engine installed.
  3. Install the plugin by running these commands inside Claude Code:
    /plugin marketplace add ./
    /plugin install quark@quark-engine
    

How to use

/quark:analysis

  1. Open Claude Code
  2. Type /quark:analysis to start
    • Claude will ask for the APK path and the type of analysis, print the quark command being run, display the output, then offer follow-up options (detail report, call graph, JSON export, or rule generation)

Example: Ahmyth-quark-analysis.html


/quark:rule-gen

  1. Open Claude Code
  2. Type /quark:rule-gen to start
    • Claude will ask for the behavior description and a code snippet, generate a Quark rule, and validate it against a real APK.

Example: Ahmyth-quark-rule-gen.html

Key Changes

  • .claude/skills/quark/SKILL.md: the /quark:analysis skill — decision table for all automatable quark modes, 5-step workflow, prints command and raw output before analysis
  • .claude/skills/quark/scripts/run_analysis.sh: passthrough CLI wrapper that handles APK path quoting and stderr capture
  • .claude/skills/quark-rule-gen/SKILL.md: the /quark:rule-gen skill — Dalvik descriptor guide, score rubric keyed to the five detection stages, canonical label list, and a 3-attempt validation loop
  • .claude/skills/quark-rule-gen/scripts/validate_rule.sh: runs a candidate rule against an APK and checks for confidence != 0% (not just len(crimes) > 0 — every loaded rule appears in the output JSON regardless of match)
  • plugin.json / marketplace manifest: packages the two skills as a Claude Code plugin for distribution outside this repo

Tests

  • Run /quark:analysis on Ahmyth.apk — summary report produces correct raw output table
  • Run /quark:rule-gen on MicManager.smali from Ahmyth.apk — generated rule matches at 100% confidence on the first attempt

TODO

  • Update README.md with a "Quark-Engine Skills" section — install instructions and usage examples
  • Package the two skills as a Claude Code plugin (plugin.json manifest) for distribution outside this repo

@codecov

codecov Bot commented Jul 5, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 80.27%. Comparing base (cf35a66) to head (c1b002b).
⚠️ Report is 3 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #947      +/-   ##
==========================================
+ Coverage   78.89%   80.27%   +1.38%     
==========================================
  Files          81       82       +1     
  Lines        7131     7185      +54     
==========================================
+ Hits         5626     5768     +142     
+ Misses       1505     1417      -88     
Flag Coverage Δ
unittests 80.27% <ø> (+1.38%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Two skills that let AI drive Quark Engine directly:

- quark: maps user requests to the correct quark CLI flags, prints the
  command and raw output before any analysis, then offers next steps
- quark-rule-gen: guides AI through identifying an API pair from decompiled
  code, formatting Dalvik descriptors, and validating the generated rule
  against a real APK via validate_rule.sh before outputting it

Key implementation notes:
- validate_rule.sh uses -s <rule.json> (not -r) to load a single rule file;
  -r triggers os.walk() which yields nothing on a file path
- Call graph (-g) and web report (-w) require -s or -d to produce output
- -C (label comparison) is an interactive TUI and cannot be automated

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@haeter525
haeter525 force-pushed the add-quark-ai-plugin-skills branch from f63e173 to 8163b17 Compare July 5, 2026 08:42
@haeter525 haeter525 changed the title feat: add quark-analysis and quark-rule-gen Claude Code skills feat: add /quark and /quark-rule-gen Claude Code skills Jul 5, 2026
@haeter525
haeter525 marked this pull request as draft July 5, 2026 10:02
haeter525 and others added 4 commits July 10, 2026 13:03
Add a marketplace catalog and a quark-ai-plugin directory that bundle the
analysis and rule-gen skills. Users install the plugin from the marketplace
and call /quark:analysis and /quark:rule-gen in any project. Document the
install steps in the main README.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The analysis and rule-gen skills now ship in quark-ai-plugin. Delete the old
copies under .claude/skills to avoid loading them twice.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Correct the marketplace and plugin manifests: move the description to the
top level, add a version, and point URLs at the ev-flow repository.

Update the rule-gen skill to always set a new rule score to 1, since the
final score depends on how the behavior spreads across real malware
samples. Also clarify the method-listing commands and reference the
rule-gen skill by its slash-command name in the analysis skill.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@haeter525
haeter525 marked this pull request as ready for review July 10, 2026 14:04
@haeter525
haeter525 requested a review from pulorsok July 10, 2026 14:04

@pulorsok pulorsok left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@haeter525
haeter525 merged commit 5d619ce into master Jul 25, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants