Commit Graph

69 Commits

Author SHA1 Message Date
fatih.bulut b4072218fd test(clone-app): smoke coverage for design + Unity scripts and rubrics 2026-06-25 02:23:20 +03:00
fatih.bulut 31888303e2 docs(clone-app): explicit mono ilspycmd command + RE context spans Phase 8
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-25 02:22:14 +03:00
fatih.bulut 257d07c6d0 feat(clone-app): wire design capture, Unity branch, Phase 8 build spec into SKILL 2026-06-25 02:20:12 +03:00
fatih.bulut d5f47138ea docs(clone-app): accurate design-tokens schema + Unity screenshot note 2026-06-25 02:17:31 +03:00
fatih.bulut 5f7b29b6b9 docs(clone-app): design-capture, unity-re, build-spec rubrics + contract/report updates 2026-06-25 02:15:02 +03:00
fatih.bulut 3c9bb564ce feat(clone-app): Unity tool wrappers (Il2CppInspectorRedux, AssetRipper) 2026-06-25 02:11:55 +03:00
fatih.bulut aad064d220 feat(clone-app): scrape screenshots, feature graphic, description from Play 2026-06-25 02:09:33 +03:00
fatih.bulut e3a29974f4 feat(clone-app): detect-unity.sh — classify il2cpp/mono/none APKs 2026-06-25 02:07:10 +03:00
fatih.bulut 014c07c36e feat(clone-app): extract-design.py — design tokens from decompiled res/ 2026-06-25 02:04:03 +03:00
fatih.bulut 6737558d56 test(market-research): cover v2 scripts in smoke; update README
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-23 23:13:06 +03:00
fatih.bulut 81a92fbc6f docs(market-research): fix intro phase count 6->8 in SKILL.md 2026-06-23 23:08:35 +03:00
fatih.bulut 323af07183 feat(market-research): 8-phase flow — dual-store charts, numeric enrich, Play links 2026-06-23 23:07:36 +03:00
fatih.bulut a13100f75c docs(market-research): report template with Play links, citations, saturation 2026-06-23 23:05:14 +03:00
fatih.bulut e61f2f7bd5 docs(market-research): numeric, evidence-required scoring 2026-06-23 23:03:34 +03:00
fatih.bulut 07aff55770 docs(market-research): add numeric-sources rubric 2026-06-23 23:01:33 +03:00
fatih.bulut f705033061 feat(market-research): add best-effort Google Trends fetcher
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-23 22:58:09 +03:00
fatih.bulut 36f64a4419 feat(market-research): add play.py count (saturation density)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-23 22:53:53 +03:00
fatih.bulut cd4edf2ad8 fix(market-research): match K/M/B-suffixed Play install counts 2026-06-23 22:50:24 +03:00
fatih.bulut 73e39c40e2 feat(market-research): add play.py resolve (name -> Play link + stats)
Live: org.isoron.uhabits returned for "habit tracker" with rating + last_updated.
installs null on live (Play DOM varies); offline test all 7 PASS.
2026-06-23 22:47:31 +03:00
fatih.bulut fbfa3aece7 feat(market-research): add play.google.com charts scraper
Replaces the AppBrain scraper (Cloudflare-blocked 403, confirmed dead).
play.google.com server-rendered chart HTML works: live-validated, real
Android packages + names + ratings from both /store/apps/top and
/store/apps/category/<CAT>. CLI: <top|category> [--category CAT]
[--region R] [--limit N] [--html-file F]; output source:"google-play",
entries {rank,name,package,rating}. Package link is the stable field;
title (Epkrse class) and rating are best-effort.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 22:42:20 +03:00
fatih.bulut 4326bde33f feat(market-research): add AppBrain Play-charts scraper
NOTE: AppBrain returns a Cloudflare JS challenge (HTTP 403) for
automated requests; live fetch degrades gracefully to an error (the
skill falls back to Apple RSS + web search). Offline test passes
against synthetic fixture — that is the test gate per the brief.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-23 22:25:20 +03:00
fatih.bulut 67ac1e6322 test(market-research): add run-all.sh suite aggregator 2026-06-22 01:02:03 +03:00
fatih.bulut 0da572ca1f feat(market-research): add 6-phase SKILL.md orchestrator with clone-app handoff 2026-06-22 00:59:25 +03:00
fatih.bulut c18ed6ab09 feat(market-research): add research-angles, scoring, and report rubrics 2026-06-22 00:56:42 +03:00
fatih.bulut ae840beaa3 feat(market-research): add history.py non-repeat memory with offline test 2026-06-22 00:52:45 +03:00
fatih.bulut 5beb04b43d feat(market-research): add fetch-charts.py App Store RSS fetcher with offline test 2026-06-22 00:49:57 +03:00
fatih.bulut 31502b5bbe feat(market-research): scaffold plugin, command, README, marketplace entry 2026-06-22 00:46:09 +03:00
fatih.bulut 0864551bde feat(clone-app): enhance HTTP request handling and update test cases for Play Store scraping 2026-06-21 20:12:31 +03:00
fatih.bulut b34632ef3b feat(clone-app): download APKs via apkeep instead of APKCombo scraping
Replace the hand-rolled two-step APKCombo curl/grep flow with apkeep
(default source apk-pure): no auth, no JavaScript, handles XAPK split
bundling and retries itself, and the per-mirror HTML parsing is no longer
ours to maintain. The script still prints a stable app.apk/app.xapk path.

- download-apk.sh: invoke apkeep, rename artifact to app.<ext>, clear error
  when the binary is missing; CLONE_APP_APKEEP (test stub) and
  CLONE_APP_APKEEP_SOURCE (mirror override) env hooks
- test-download-apk.sh: rewritten against an apkeep stub (xapk/apk/fail/
  missing-binary cases)
- SKILL.md Phase 1: prose updated for apkeep install + source override

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-21 19:19:54 +03:00
fatih.bulut 5adfa2a1ae docs(clone-app): tie Phase 2 fallback guard to probe RC==0
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-21 17:29:52 +03:00
fatih.bulut c8e5bb08a4 test(clone-app): register re-digest-contract in smoke structure check 2026-06-21 17:24:03 +03:00
fatih.bulut 567b512e32 feat(clone-app): run RE via isolated subagent with script fallback + payloads 2026-06-21 17:19:29 +03:00
fatih.bulut b6eca91d1d test(clone-app): add RE digest contract, fixtures, structural test 2026-06-21 17:12:58 +03:00
fatih.bulut b1135b82a2 fix(clone-app): switch APK source to APKCombo and guard bash version
The APKPure direct endpoint (d.apkpure.com/b/APK/<pkg>) now returns an HTTP
403 Cloudflare bot challenge for every package, so downloads always failed —
which also blocked the entire reverse-engineering chain downstream (it never
ran because Phase 1 produced no APK).

- download-apk.sh: fetch the APKCombo download page with a browser UA, extract
  the embedded /r2?u=<signed-url> link, and download that. No JS needed; the
  URL slug is ignored so a literal 'app' works for any package. Verified
  end-to-end against com.wonder (Elevate) -> 126MB xapk -> RE fingerprint.
- test-download-apk.sh: model the two-step flow and the page-without-link case.
- resolve-re-scripts.sh: warn (stderr) when bash < 4, since the upstream RE
  scripts use ${VAR,,} and fail with 'bad substitution' on macOS bash 3.2.
- SKILL.md / README.md / CLAUDE.md: document the APKCombo source and bash 4+ req.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-21 04:16:25 +03:00
fatih.bulut b7b62d5f14 chore(clone-app): rename marketplace to clone-app-skill and update repo URLs
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-21 03:48:55 +03:00
fatih.bulut e4703a28fe fix(clone-app): correct Phase 2 decompile output dir and tighten package regex 2026-06-21 02:23:34 +03:00
fatih.bulut 919a1fb6af test(clone-app): add structural smoke test 2026-06-21 02:19:07 +03:00
fatih.bulut 91abce60d4 feat(clone-app): add /clone-app command and README 2026-06-21 02:17:56 +03:00
fatih.bulut 42f5020f8b feat(clone-app): add orchestrator SKILL.md (phases 0-7) 2026-06-21 02:15:36 +03:00
fatih.bulut f88da4d2d9 docs(clone-app): add stack/effort/infra/report reference guides 2026-06-21 02:12:51 +03:00
fatih.bulut 10eb027efa test(clone-app): add aggregate test runner 2026-06-21 02:10:40 +03:00
fatih.bulut 87acf85d6f feat(clone-app): add check-appstore.py iTunes search with tests 2026-06-21 02:09:02 +03:00
fatih.bulut 4b010a665e feat(clone-app): add scrape-play-store.py with ld+json parsing and tests 2026-06-21 02:07:14 +03:00
fatih.bulut 052f0e5cad feat(clone-app): add download-apk.sh with retries and xapk/apk detection 2026-06-21 02:05:04 +03:00
fatih.bulut d2d74d02d3 feat(clone-app): add resolve-re-scripts.sh sibling-plugin locator with tests 2026-06-21 02:02:05 +03:00
fatih.bulut bc3066a890 feat(clone-app): add extract-package.sh URL parser with tests 2026-06-21 02:00:26 +03:00
fatih.bulut 9550dc0182 feat(clone-app): scaffold plugin manifest and marketplace entry 2026-06-21 01:58:03 +03:00
Simone Avogadro e8dde9d058 chore: bump plugin version to 1.5.0 2026-06-10 11:49:02 +02:00
Simone Avogadro f68d9ce3be feat: post-filter --urls to drop dictionary noise while keeping IPs and apex hosts
The hardening patch widened STRICT_URL to recover IPv4 literals, apex
2-label domains and internal hosts that the PR's strict-only regex
discarded as collateral while killing Kotlin-stdlib dictionary noise.
Widening alone reopened a narrow noise class: 'word.word' fragments such
as "www.this" / "this.introduction" pass as apex domains.

Keep extraction permissive and add a small awk pass that decides per host:
- IPv4 literal: always keep (dict fragments are words, never dotted-quads)
- >=3 labels: always keep (any TLD; same tolerance as the original regex)
- any host with a :port or /path: always keep (structured = high signal)
- bare 2-label apex: keep only when the TLD is a real one, matched as a
  whole field (so "introduction" != "in" — the prefix-match bug a single
  mega-regex would have)

Trade-off documented inline: a first-party host referenced bare with an
uncommon TLD (e.g. https://foo.store with no path) is dropped; a path or
port keeps it. awk is POSIX (sub/split/~/print) — more portable than the
bash>=4 'declare -A' already used in the summary header.

Verified: dictionary noise dropped; IPs, apex, internal and subdomain
hosts kept; --all on a zero-match tree still exits 0; host list and
full-URL list stay consistent (no orphan hosts).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 11:06:30 +02:00
Simone Avogadro 2047f99d01 fix: harden find-api-calls.sh and recover-kotlin-names.sh from PR #16 review
- find-api-calls.sh: add missing '|| true' on the --paths inventory and
  --urls extraction pipelines; with set -euo pipefail a zero-match grep
  aborted the whole script (including the default --all run) with exit 1.
- find-api-calls.sh: widen STRICT_URL to also match IPv4 literals, apex
  2-label domains and bare single-label hosts followed by :port or /path
  (localhost, internal backends) while still rejecting dictionary-fragment
  noise from the Kotlin stdlib.
- recover-kotlin-names.sh: sanitize the by_package/ filename with
  os.path.basename; a crafted absolute path in untrusted @DebugMetadata
  package names could otherwise escape the output directory.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-10 10:22:16 +02:00