Open-source project
NobyDa/Script avatar
NobyDa/Script

NobyDa/Script: iOS Proxy Scripting Tools for Surge, Quantumult X, Loon, and Stash

This project is based on the scripting capabilities of several excellent iOS proxy tools (e.g. Surge, Quantumult X)

8,448 stars2,989 forksJavaScriptGPL-3.0

At a glance

What is it?
NobyDa/Script is a GPL-licensed JavaScript repository of automation scripts for iOS proxy tools. It provides daily bonus automation, functionality-enhancing scripts, and rewrite rules organized by proxy tool, with most scripts requiring MITM decryption to intercept app traffic.
Who is it for?
Engineers building iOS proxy automations will find NobyDa/Script a reference for how to write scripts against Surge, Quantumult X, Loon, and Stash. The GPL-3.0 license applies to the collection.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 49 days ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What This Repository Provides and Who Uses It

NobyDa/Script is a collection of JavaScript scripts designed to run inside iOS proxy tools that support scripting engines. The three supported tools are Surge, Quantumult X, Loon, and Stash. These are iOS apps that intercept network traffic and can run JavaScript against requests and responses.

The repository serves iOS users who want to automate repetitive tasks that apps normally require manual interaction to complete, such as daily check-in bonuses, and developers learning how to write scripts for these proxy environments. The README is organized into three sections: Daily-Bonus Script, Functionality-enhancing Script, and Other Script.

Each script targets a specific application: JD (Jingdong), Bilibili, iQIYI, TestFlight, and others. Scripts are plain JavaScript files stored in directories named after the target application. Configuration files for each proxy tool (Surge, QuantumultX, Loon, Stash) are stored in their own top-level directories.

The repository is not a framework or a library. It is a collection of ready-to-use scripts. There is no installation command; users copy script URLs into their proxy tool's script configuration.

How iOS Proxy Scripting Works: MITM and Script Engines

iOS proxy tools like Surge and Quantumult X act as local VPN proxies that route device traffic through their own engine. This gives them access to HTTP and HTTPS requests in transit. For HTTPS traffic, they perform a man-in-the-middle (MITM) interception: the proxy presents its own certificate to the app and decrypts the traffic before it leaves the device.

The README prominently states at the top: the scripts or rewrite rules described below may require enabling MITM. Additionally, the generated root certificate must be installed and trusted manually in the system. This is a prerequisite for any script that works on HTTPS traffic, which covers most of the apps in the repository.

Once MITM is configured and the certificate is trusted, the proxy tool can execute JavaScript against matched requests or responses. Scripts run inside the proxy tool's engine, not in a standard Node.js environment. They have access to the request and response objects and can modify headers, redirect requests, or trigger custom logic based on timing or content.

For Surge, the relevant script directory is Surge/JS/. For Quantumult X, scripts are in QuantumultX/. The Loon/ and Stash/ directories contain configuration files for those tools.

Repository Structure: Organized by App and Tool

The top-level directory structure separates scripts by the application they target and configuration files by the proxy tool that uses them. For example, JD-DailyBonus/ contains JD_DailyBonus.js, which is the Jingdong daily bonus script. Bilibili-DailyBonus/ contains Manga.js and ExchangePoints.js. iQIYI-DailyBonus/ contains the iQIYI daily bonus script.

Functionality-enhancing scripts live in specific tool directories. For example, Bili_Auto_Regions.js (Bilibili anime auto-switch region script) is in Surge/JS/. Membership-unlocking scripts like vsco.js are referenced from the QuantumultX/File/ path.

The TestFlight/ directory contains TestFlightAccount.js, which merges and shares TestFlight accounts. The Time-based-One-Time-Password/ directory contains a TOTP implementation. The Shortcuts/ directory contains PolicySwitch.js, which switches policy groups in Surge, Quantumult X, and Loon using iOS Shortcuts.

The Sub-store-parser/ directory contains DataQuery.js, which queries server traffic through Sub-Store, a subscription management tool for proxy rules.

This organization means that to use a specific script, you navigate to its directory, copy the raw GitHub URL, and add it to your proxy tool's script configuration.

Maintenance Status of Individual Scripts

The README displays a maintenance column for each script. The meanings are not explicitly defined, but the table shows checkmark symbols (indicating available and maintained), X symbols (indicating not available or not maintained), and warning symbols. Not all scripts are current.

The JD_DailyBonus.js script for Jingdong is marked as not available and the maintenance indicator shows a warning. The 52pojie.js daily bonus script for the 52pojie security forum is marked as not available and not maintained. TieBa.js (Baidu Tieba) is available as of 2023/08/17 but marked as not maintained.

In contrast, iQIYI.js, KKMH.js (Kuaikan Manga), Manga.js (Bilibili Comics), and BahamutDailyBonus.js are marked as available and maintained.

This matters for engineers who want to rely on these scripts. An unmaintained script may stop working when the target app updates its API or authentication mechanism. The functionality-enhancing scripts (Bili_Auto_Regions.js, ExchangePoints.js, TestFlightAccount.js) are listed without explicit maintenance indicators.

The last push to the repository was on 2026-08-12.

Legal and Ethical Boundaries

The README includes a disclaimer section covering several categories: Decrypt, Privacy, Commercial, Infringement, and Liability.

MITM decryption of third-party app traffic is a legally and ethically sensitive operation. Apps transmit private user data over HTTPS. Enabling MITM on that traffic means the proxy tool can read and modify that data. The repository's disclaimer section addresses this directly.

Some of the scripts in the Other Script category unlock membership features or in-app purchases in third-party applications. This type of functionality operates in a grey area that may violate the terms of service of the affected applications.

The GPL-3.0 license governs the code in this repository. Using GPL-licensed code in a proprietary project requires understanding the copyleft implications: modifications to GPL code that you distribute must also be made available under the GPL.

Limitations: Script Fragility and No Formal Release Mechanism

Scripts written against specific app APIs are inherently fragile. When an app updates its backend, changes its authentication flow, or modifies the data structures its API returns, the script may break silently or produce errors. The maintenance column in the README reflects this reality: several scripts that were once functional are now marked as unavailable.

The repository has no GitHub releases. Scripts are updated directly to the master branch. There is no version pinning mechanism for users who want to use a specific working version of a script. If a working script is updated and the update breaks it, you would need to use git history to find a previous version.

The BoxJs configuration file (NobyDa_BoxJs.json) is included, which suggests some scripts are designed to work with BoxJs for configuration management, but this dependency is not explicitly documented in the README.

There is no test suite in the repository. Script correctness is verified by running the script against a live app.

NobyDa/Script vs. Writing iOS Proxy Scripts from Scratch

Writing a Surge or Quantumult X script from scratch requires understanding the proxy tool's scripting API, the structure of the target app's HTTP requests, and how to set up MITM correctly. This is a non-trivial starting point for engineers unfamiliar with iOS proxy tools.

NobyDa/Script provides working examples of all of these elements. Reading JD_DailyBonus.js or Bilibili's Manga.js shows the actual API calls that the scripts intercept and the response structures they parse. For developers learning to write scripts for these environments, the repository is a reference for patterns and idioms rather than a tool to run as-is.

The Functionality-enhancing Script section contains scripts with clearer long-term utility than the daily bonus scripts: PolicySwitch.js for automating policy group changes and Bili_Auto_Regions.js for automating regional content switching. These are less susceptible to backend changes than scripts that depend on app-specific authentication flows.

Editorial conclusion

Engineers building iOS proxy automations will find NobyDa/Script a reference for how to write scripts against Surge, Quantumult X, Loon, and Stash. The GPL-3.0 license applies to the collection. Check each individual script's maintenance column in the README before relying on it, since several daily-bonus scripts are marked as no longer functional. The last push to the repository was on 2026-08-12.

Frequently asked questions

What proxy tools does NobyDa/Script support?

The repository includes scripts and configuration files for Surge, Quantumult X, Loon, and Stash. Each tool has its own top-level directory in the repository. Surge scripts are in Surge/JS/ and Quantumult X scripts are in QuantumultX/File/.

Do NobyDa scripts require MITM to be enabled?

Most scripts do. The README states at the top that scripts and rewrite rules may require enabling MITM, and that the generated root certificate must be installed and trusted manually in the system. Scripts that intercept HTTPS traffic require this setup.

How do I use a script from NobyDa/Script in Surge or Quantumult X?

Copy the raw GitHub URL of the script file into your proxy tool's script configuration. For Surge, scripts go under the [Script] section of the configuration file. For Quantumult X, they are added in the rewrite or task sections. The README does not provide step-by-step configuration instructions for each tool.

Official sources

  1. Issues
  2. License: GPL-3.0
  3. NobyDa/Script on GitHub
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/nobyda-script.svg)](https://hysenlabs.com/projects/nobyda-script)