Many thanks for the reply

In fact, I'm not trying to write a rootkit or spy on anyone, I don't care the tiniest bit about user data. On the contrary, I'm an anti-malware developer with a long record of working against the type of software you describe. If you need some kind of proof, just specify.
I know roughly what jailbroken means, having jailbroken since iOS 1.03. But I didn't went further than changing my SSH password and installing PMP, Firewall iP and Adblocker, my attempts at own code are dated back to the inofficial iPhone SDK 2.0 Windows toolchain and didn't go deeper into the system back then. My assumption is that on a jailbroken device, I can let UI apps run as root instead of mobile, I think that's what iFile does.
Point is: our windows anti-malware software is taking up most resources, and I'm trying to evaluate how difficult it would be to wrap something together that does at least flag some standard Cydia repository monitoring apps (conversion of Cydia package name to rules for our signature language is about done) as a start to persuade my team to invest more time in this direction. Not a commercial route (our Windows anti-malware is free for personal use as well), but because I can't stand the spying crap on the iPhone I use.
So... if you have more information you could share with one of the "good guys" (perhaps by PM since it's probably sensible to not post instructions how to write rootkits in FPC in the public, I agree on that), I would be thankful, but I'm already thankful for giving me a few more hints for asking a search engine
