SkillAgentSearch skills...

SAFTest

PoC for SAF

Install / Use

/learn @MlgmXyysd/SAFTest
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

SAF Test

The app uses a vulnerability of Storage Access Framework to create a file named MLGMXYYSD_SAFTEST.txt in <Internal Storage>/Android/data or <Internal Storage>/Android/obb.

This file lists all the files in the directory.

This kind of behavior will destroy Package visibility introduced in Android 11.

Initially, it was used for Accessing Android/data through SAF in Android R's PoC.

Prebuilt APK in app/release/app-release.apk.

Test

  • AVD x86_64: Google Play SPP1.210122.020.A3 Android 12 (S Developer Preview 1)
  • Pixel 4 XL: Material You SPB3.210618.016 Android 12 (Beta 3.1)
  • OnePlus 8T: Hydrogen OS 11.0.9.9.KB05 Android 11

Related Skills

View on GitHub
GitHub Stars13
CategoryDevelopment
Updated7mo ago
Forks2

Languages

Java

Security Score

77/100

Audited on Sep 8, 2025

No findings