SkillAgentSearch skills...

mobile-pentest

Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 CA injection, exported-component/content-provider abuse, deep-link/WebView chains, biometric bypass, Flutter/React-Native RE

Install / Use

npx skills add hypnguyen1209/offensive-claude --skill mobile-pentest

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

86/100

Category

Security

Supported Platforms

Universal

Our assessment of mobile-pentest

mobile-pentest scores 86/100 on our quality scale, 720th of 1,096 Security skills we index.

Its SKILL.md is 11 KB long, well organised into 14 sections with 1 code example: a thorough specification that gives an agent plenty to work with.

It has 377 GitHub stars, a meaningful sign that others use it.

Substance
29/30
Structure
17/20
Description
15/15
Adoption
11/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 14 days ago, so mobile-pentest is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

mobile-pentest compared with similar skills

All 4 of these similar skills score higher than mobile-pentest; compare them before choosing.

SkillScoreStarsUpdatedFormat
mobile-pentest (this skill)by hypnguyen12098637714d agoSKILL.md
algorithmic-artby anthropics100177.9k12d agoSKILL.md
pptxby anthropics100177.9k12d agoSKILL.md
designby nextlevelbuilder100130.2k13d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k13d agoSKILL.md

Frequently asked questions

How do I install mobile-pentest?
Run npx skills add hypnguyen1209/offensive-claude --skill mobile-pentest. The install tabs above show the steps for each supported agent.
Which AI agents does mobile-pentest work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is mobile-pentest safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is mobile-pentest still maintained?
The repository was last updated 14 days ago, so mobile-pentest is actively maintained.

name: mobile-pentest description: Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 CA injection, exported-component/content-provider abuse, deep-link/WebView chains, biometric bypass, Flutter/React-Native RE metadata: type: offensive phase: exploitation tools: frida, frida-tools, objection, jadx, apktool, reflutter, hermes-dec, hbctool, mitmproxy, burp, palera1n, dopamine, frida-ios-dump, bagbak, mobsf, drozer, nuclei mitre: TA0001 kill_chain: phase: [recon, exploit] step: [1, 4] attck_tactics: [TA0043, TA0001, TA0009, TA0006, TA0005] attck_techniques: [T1626, T1626.001, T1517, T1409, T1517, T1577, T1631, T1407, T1635, T1521, T1521.001, T1417, T1417.001, T1660, T1644, T1623] depends_on: [recon-osint, reverse-engineering] feeds_into: [exploit-development, web-pentest] inputs: [apk_file, ipa_file, mobile_endpoint, app_package_id] outputs: [finding_record, mobile_vulnerability_list, intercepted_traffic, extracted_secrets] references:

  • references/environment-interception.md
  • references/android-component-attacks.md
  • references/webview-deeplink-exploitation.md
  • references/insecure-storage-crypto.md
  • references/ios-offensive.md
  • references/crossplatform-re-instrumentation.md scripts:
  • scripts/universal_unpin.js
  • scripts/android_ca_inject.sh
  • scripts/manifest_attack_surface.py
  • scripts/component_fuzz.sh
  • scripts/ios_bypass_suite.js
  • scripts/hermes_triage.py

Mobile Application Penetration Testing

When to Activate

  • Android/iOS application security assessment, bug-bounty mobile triage, or app-store reconnaissance
  • Need to intercept TLS traffic (SSL/cert pinning, Android 14/15 Conscrypt-APEX trust store, Flutter/RN stacks)
  • Bypass root/jailbreak or biometric-gating controls during dynamic analysis
  • Enumerate and exploit exported components, content providers, deep links, and WebViews
  • Extract secrets from insecure storage (SharedPrefs, SQLite, Keychain, Keystore) and reverse hybrid apps

Technique Map

| Technique | ATT&CK | CWE | Reference | Script | |-----------|--------|-----|-----------|--------| | Lab build + Frida 17 server/gadget | T1635 | CWE-1188 | references/environment-interception.md | - | | Android 14/15 Conscrypt-APEX CA injection | T1521.001 | CWE-295 | references/environment-interception.md | scripts/android_ca_inject.sh | | SSL/cert-pinning bypass (Java TM/OkHttp/native) | T1521.001 | CWE-295 | references/environment-interception.md | scripts/universal_unpin.js | | Root detection bypass (RootBeer/native stat) | T1633.001 | CWE-693 | references/environment-interception.md | scripts/universal_unpin.js | | Exported activity/service/receiver abuse | T1626.001 | CWE-926 | references/android-component-attacks.md | scripts/manifest_attack_surface.py | | Content-provider SQLi / path traversal (CVE-2025-48609) | T1409 | CWE-22, CWE-89 | references/android-component-attacks.md | scripts/component_fuzz.sh | | Task hijacking / StrandHogg / TapTrap (USENIX '25) | T1517 | CWE-1021 | references/android-component-attacks.md | scripts/manifest_attack_surface.py | | Deep-link / intent-redirect / scheme hijack | T1635, T1577 | CWE-939 | references/webview-deeplink-exploitation.md | scripts/component_fuzz.sh | | WebView JS-interface RCE + file:// theft | T1577 | CWE-749 | references/webview-deeplink-exploitation.md | scripts/component_fuzz.sh | | OAuth custom-scheme callback interception | T1635 | CWE-940 | references/webview-deeplink-exploitation.md | - | | Insecure storage (SharedPrefs/SQLite/external) | T1409 | CWE-312 | references/insecure-storage-crypto.md | scripts/manifest_attack_surface.py | | Keystore/Keychain misuse + dumping | T1634 | CWE-522 | references/insecure-storage-crypto.md | scripts/ios_bypass_suite.js | | Biometric bypass (BiometricPrompt/LAContext) | T1634 | CWE-287 | references/insecure-storage-crypto.md | scripts/ios_bypass_suite.js | | iOS jailbreak + JB-detection bypass | T1635 | CWE-693 | references/ios-offensive.md | scripts/ios_bypass_suite.js | | IPA decrypt / class-dump / URL-scheme abuse | T1409, T1635 | CWE-200 | references/ios-offensive.md | scripts/ios_bypass_suite.js | | Flutter RE / reFlutter pinning bypass | T1521.001 | CWE-295 | references/crossplatform-re-instrumentation.md | scripts/hermes_triage.py | | React Native Hermes bytecode decompile | T1640 | CWE-656 | references/crossplatform-re-instrumentation.md | scripts/hermes_triage.py |

Quick Start

# ---- ANDROID ----
# 0. Pull + statically triage the APK (manifest, secrets, exported surface, framework ID)
adb shell pm path com.target.app                              # locate split APKs
adb pull /data/app/.../base.apk .
python3 scripts/manifest_attack_surface.py base.apk -o surface.json
jadx -d src base.apk &  apktool d base.apk -o decoded

# 1. Frida 17: match server to host tools; push + run
frida --version                                              # e.g. 17.x  -> use matching server
adb push frida-server-17.x-android-arm64 /data/local/tmp/frida-server
adb shell "su -c 'chmod 755 /data/local/tmp/frida-server && /data/local/tmp/frida-server &'"

# 2. Trust Burp CA on Android 14/15 (APEX is immutable -> Zygote namespace bind-mount)
bash scripts/android_ca_inject.sh 9a5ba575.0 cacert.pem      # see reference for cert hashing

# 3. Spawn target with universal unpinning + root-detection bypass
frida -U -f com.target.app -l scripts/universal_unpin.js --no-pause

# 4. Hit the exported attack surface from surface.json
bash scripts/component_fuzz.sh com.target.app surface.json

# ---- iOS ----
frida-ios-dump -o app.ipa com.target.app                     # decrypt + pull (jailbroken)
frida -U -f com.target.app -l scripts/ios_bypass_suite.js --no-pause   # JB + pinning + biometric + keychain

# ---- HYBRID ----
file decoded/assets/index.android.bundle                     # "Hermes JavaScript bytecode" => RN
python3 scripts/hermes_triage.py base.apk                    # detect Flutter/RN, drive reFlutter/hermes-dec

OPSEC & Detection (summary)

| Technique | Telemetry / IOC | Detection (Sigma / app-side) | OPSEC note | |-----------|-----------------|------------------------------|------------| | Frida instrumentation | frida-server/gadget ports (27042), re.frida.server, suspicious maps regions, named pipes linjector | App scans /proc/self/maps for frida, checks D-Bus port, thread gum-js-loop; Play Integrity | Use frida-gadget renamed lib, custom port frida-server -l 0.0.0.0:1337, magisk-hide / Shamiko | | CA injection (APEX) | New trust anchor in process trust store; cert CN mismatch on pinned hosts | Network Security Config <trust-anchors> excludes user store; pinning catches it | Mount lives only in Zygote ns, vanishes on Zygote crash — re-inject; nothing written to /system | | SSL-pinning bypass | TLS handshake to proxy IP; cert chain not app-pinned cert | App-side pin failure callbacks fire (if logged); telemetry SDK sees proxy cert | Hook before first request; for Flutter prefer reFlutter patch over runtime to avoid crash loops | | Root/JB bypass | getprop ro.debuggable, su binaries, magisk paths queried | RootBeer/iXGuard SDK reports; SafetyNet/Play Integrity attestation server-side | Bypass client checks only; server-side attestation (Play Integrity / DeviceCheck) is unaffected | | Exported component abuse | am start/startservice/broadcast from adb; foreign UID intent | App logs unexpected caller UID; Binder.getCallingUid() checks | Use on-device malicious app for realism; adb leaves shell history | | Content-provider traversal | content query with ../; openFile on out-of-dir path | FileProvider canonical-path check; CVE-2025-48609 patched Mar 2026 SPL | URL-encode ..%2f to dodge naive filters; read-only first | | TapTrap / task hijack | Transparent activity transition, taskAffinity overlap, animationScale abuse | TapTrap fixed Dec 2025 SPL; check targetSdk, taskAffinity="" | Zero-permission; works <Dec-2025 patch; user study: 100% missed at least one variant | | Keychain/Keystore dump | keychain_dumper, frida memory scrape, SecItemCopyMatching hooks | Keychain items with .biometryCurrentSet resist hooking; SE-backed keys unextractable | JB device dumps keychain plaintext regardless of ACL; flag SE vs SW keys in report | | Biometric bypass | LAContext evaluatePolicy / BiometricPrompt callback hook | Only works on boolean-result pattern, NOT SecAccessControl-gated crypto | Report root cause: auth result not bound to a crypto/keychain operation |

Deep Dives

  • references/environment-interception.md — Rooted/jailbroken lab, Genymotion/AVD, Magisk+Shamiko, Frida 17 breaking changes (bridge removal, frida-pm, frida-compile), gadget mode for non-root, Android 14/15 Conscrypt-APEX CA injection via Zygote namespace bind-mount, universal SSL-pinning bypass (Java TrustManager/OkHttp/Network Security Config/native BoringSSL), root-detection bypass.
  • references/android-component-attacks.md — Manifest attack-surface enumeration, exported activity/service/broadcast/provider exploitation, content-provider SQLi & path traversal (CVE-2025-48609 MmsProvider), intent:// redirection to non-exported components, task hijacking (StrandHogg 1.0/2.0 CVE-2020-0096) and TapTrap animation-driven tapjacking (USENIX Security '25), drozer + adb workflows.
  • references/webview-deeplink-exploitation.md — addJavascriptInterface RCE, setAllowUniversalAccessFromFileURLs/file:// local-file theft, deep-link → WebView open-redirect/XSS chains, intent:// browsable-activity pivots, OAuth custom-scheme callback hijack (RFC 8252), iOS URL-scheme & Universal Link abuse, one-click browser-to-WebView exploitation.
  • references/insecure-storage-crypto.md — Android SharedPreferences/SQLite/internal+external storage, Android Keystore misuse (non-hardware-backed keys, no setUserAuthenticationRequired), iOS Keychain ACLs & keychain_dumper, NSUserDefaults/plist leaks, biometric bypass (BiometricPrompt CryptoObject vs result-only, LAContext evaluatePolicy), hardcoded secrets & Firebase/S3 misconfig, MASVS-STORAGE mapping.
  • references/ios-offensive.md — Jailbreak tooling matrix (palera1n checkm8 A8–A11/T2 iOS 15–18.x, Dopamine A8–A16 iOS 15–16.6.1, Dopamine HideJailbreak), JB-detection bypass (Frida stat/fopen/dlopen hooks + Shadow), IPA decryption (frida-ios-dump/bagbak), class-dump/Swift demangling, entitlements & URL-scheme analysis, Frida-version pinning gotchas.
  • references/crossplatform-re-instrumentation.md — Flutter Dart-stack interception (reFlutter libflutter.so patch of ssl_crypto_x509_session_verify_cert_chain, iptables/proxydroid fallback), React Native Hermes bytecode RE (hermes-dec, hbctool patch/reassemble, hermes-decomp, CatalystInstanceImpl.loadScriptFromAssets Frida hook), native .so JNI/JNI_OnLoad analysis in Ghidra/IDA.

Related Skills

View on GitHub
GitHub Stars377
CategorySecurity
Updated14d ago
Forks65

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions