Agent skill

Mobile Audit

by briiirussell in briiirussell/cybersecurity-skills

Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance.

MITAuto-check: warningsSecurity

Install Mobile Audit

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill mobile-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills mobile-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mobile-audit .claude/skills/mobile-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mobile-audit
GitHub stars
413
Token cost
~2.6k tokens
SKILL.md length
1,107 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance.

  • Works in 3 steps: The app is yours, or you have written… → You're operating in an environment you… → App store ToS — Apple and Google…
  • The user mentions mobile security
  • SKILL.md covers Authorization Check, Audit Checklist —…, Audit Checklist — MASVS-CRYPTO… and Audit Checklist —…, plus 9 more sections
  • Calls adb

What it does

Mobile Audit is an agent skill from briiirussell/cybersecurity-skills. Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. Use when the user mentions 'mobile security,' 'iOS security,' 'Android security,' 'mobile audit,' 'mobile pentest,' 'MASVS,' 'MASTG,' 'certificate pinning,' 'jailbreak detection,' 'root detection,' 'deeplink,' 'URL scheme,' 'app transport security,' 'keychain,' 'keystore,' 'mobile reverse engineering,' or has a mobile…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security and Reverse engineering and malware. It works with Android and iOS. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions mobile security
  • Android security
  • Certificate pinning
  • Jailbreak detection

Example prompts

  • “mobile security,”
  • “iOS security,”
  • “Android security,”
  • “/mobile-audit”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Write, Grep, Glob, WebSearch

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. The app is yours, or you have written authorization from the publisher
  2. You're operating in an environment you control (test device, emulator, dedicated sandbox)
  3. App store ToS — Apple and Google generally allow security research on apps you own; testing competitor apps without authorization is a…

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Grep
    • Glob
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mobile Audit loads about 2.6k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 1,107 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningContains instruction-override wording (e.g. “without asking the user”)SKILL.md:66
    m a WebView to trigger an in-app action without user consent is an XSS-to-action chain
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Grep, Glob, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,107 words, ~2,648 tokens.

Download SKILL.mdSave it as .claude/skills/mobile-audit/SKILL.md (or your agent's skills folder).
name
mobile-audit
description
Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. Use when the user mentions 'mobile security,' 'iOS security,' 'Android security,' 'mobile audit,' 'mobile pentest,' 'MASVS,' 'MASTG,' 'certificate pinning,' 'jailbreak detection,' 'root detection,' 'deeplink,' 'URL scheme,' 'app transport security,' 'keychain,' 'keystore,' 'mobile reverse engineering,' or has a mobile app to review.
allowed-tools
Bash, Read, Write, Grep, Glob, WebSearch

Mobile Audit — iOS & Android Application Security Review

Audit mobile apps against the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Application Security Testing Guide (MASTG). Covers source code review, static analysis of compiled binaries, and runtime testing.

Scope: this skill covers the app and its interaction with the device, the backend, and other apps. For backend API security, pair with api-audit. For dependency CVEs (CocoaPods, SPM, Gradle), pair with dependency-audit.

Authorization Check

Before reverse-engineering or runtime-testing a binary, confirm:

  1. The app is yours, or you have written authorization from the publisher
  2. You're operating in an environment you control (test device, emulator, dedicated sandbox)
  3. App store ToS — Apple and Google generally allow security research on apps you own; testing competitor apps without authorization is a fast path to legal exposure

If unclear, ask before proceeding.

Audit Checklist — MASVS-STORAGE (Sensitive Data Storage)

  • iOS: keychain items use the strongest available kSecAttrAccessible class — kSecAttrAccessibleWhenUnlockedThisDeviceOnly or kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly. Avoid Always and ThisDeviceOnly-less variants
  • iOS: no secrets in NSUserDefaults, plist, or app bundle — strings <app>.ipa should not reveal API keys or secrets
  • Android: secrets in EncryptedSharedPreferences / Keystore-backed encrypted storage, not raw SharedPreferences
  • Android: android:allowBackup="false" in the manifest (or backup rules carefully scoped) — otherwise adb backup extracts everything
  • Both: no PII / tokens written to logs that survive a crash (NSLog, Log.d, third-party crash reporters)
  • Both: Pasteboard / Clipboard access — sensitive fields don't auto-share to system clipboard (iOS pasteboard.expirationDate, Android ClipDescription.EXTRA_IS_SENSITIVE)
  • Both: the OS app-switcher screenshot doesn't capture sensitive screens — iOS applicationDidEnterBackground blur, Android FLAG_SECURE on the activity

Audit Checklist — MASVS-CRYPTO (Cryptography)

  • No hardcoded keys in the app bundle — strings, class-dump, apktool reveal embedded constants
  • Modern algorithms only — AES-GCM, ChaCha20-Poly1305; reject AES-ECB, DES, RC4, MD5, SHA-1
  • Random number generation uses SecRandomCopyBytes (iOS) / SecureRandom (Android) — not arc4random() for crypto, never Math.random()
  • Key derivation from passwords uses PBKDF2 with ≥ 600,000 iterations (OWASP 2024) or Argon2id
  • IVs / nonces are not reused — if you see iv = "0000000000000000", that's worse than no encryption (reveals plaintext patterns)
  • Don't roll your own crypto — flag any custom encryption scheme; bias toward libsodium / Tink

Audit Checklist — MASVS-NETWORK (Network Communication)

  • iOS: App Transport Security enabled — no global NSAllowsArbitraryLoads = true. If exceptions exist, they're specific domains, justified, and documented
  • Android: network_security_config.xml exists and enforces cleartext-traffic refusal — <base-config cleartextTrafficPermitted="false">
  • Both: Certificate pinning for high-trust backends — public-key pinning preferred over certificate pinning (survives cert rotation). For iOS: URLSessionDelegate + URLAuthenticationChallenge; Android: NetworkSecurityConfig <pin-set> or OkHttp CertificatePinner
  • Both: Pinning has a backup pin — pinning to a single cert means the next rotation breaks the app for all users
  • WebView usage — WKWebView only (iOS, not UIWebView); JavaScript bridge audited; setJavaScriptEnabled(false) if the WebView doesn't need JS
  • WebView loadUrl with user-controlled URL — open redirect, intent-spoofing, phishing surface

Audit Checklist — MASVS-AUTH (Authentication & Session)

  • Biometric prompts use LAContext.evaluatePolicy (iOS) / BiometricPrompt (Android) — not the deprecated FingerprintManager
  • Biometric auth is bound to keychain/keystore access, not just a UI check (SecAccessControl.biometryAny, Android KeyGenParameterSpec.setUserAuthenticationRequired(true))
  • Session tokens stored in keychain/keystore (not SharedPreferences/NSUserDefaults)
  • Refresh-token flow — short-lived access token, refresh token revocable server-side
  • OAuth flows use the platform browser (ASWebAuthenticationSession on iOS, Custom Tabs on Android) — never a WebView (steals credentials trivially)
  • App-level passcode independent of device unlock if the app holds sensitive data

Audit Checklist — MASVS-PLATFORM (Platform Interaction)

  • Every exported activity (android:exported="true") reviewed for parameter handling
  • Universal Links (iOS) and App Links (Android) use HTTPS + verified domain — not custom schemes (myapp://) which any app can register
  • Deeplinks that trigger sensitive actions (purchase, share, change account) require user confirmation in-app
  • WebView-loaded URLs filtered — opening myapp:// from a WebView to trigger an in-app action without user consent is an XSS-to-action chain
Inter-process communication (Android)
  • Content providers — android:exported="false" unless explicitly intended for cross-app access; if exported, every URI path validated
  • Services — exported services have permission strings; exposed without android:permission is callable by any app
  • Broadcast receivers — LocalBroadcastManager for in-app broadcasts; system broadcasts validated
Inter-process communication (iOS)
  • App groups configured only when sharing is genuinely required
  • Keychain access groups limited to your own apps (no shared keychain group with unrelated bundles)
  • URL scheme handlers validate the source app (UIApplication.openURL options include UIApplicationOpenURLOptionsSourceApplicationKey)
Show full SKILL.md (432 more words)Show less

Audit Checklist — MASVS-CODE (Code Quality)

  • Native libraries — modern compilers, no stack canaries disabled, PIE enabled (otool -hv on iOS, readelf -h on Android .so)
  • Symbols stripped from release builds (strip, ProGuard/R8)
  • No debug builds in production (DEBUG flag, isDebuggable in manifest)
  • No reflection-based hidden APIs (Android non-SDK interfaces) — break on OS upgrades
  • Updates: in-app update prompt that forces upgrade past known-vulnerable versions

Audit Checklist — MASVS-RESILIENCE (Anti-Reverse-Engineering)

This category is rated optional in MASVS — only required for high-risk apps (banking, DRM, government). For most apps, don't waste effort here; ship secure crypto and a proper backend.

If required:

  • Jailbreak / root detection — not bulletproof (every detection technique has a public bypass) but raises the cost
  • Code obfuscation — DexGuard / Arxan for high-value apps; standard ProGuard / R8 minimally for everyone
  • Anti-debugging — ptrace self-attach (iOS / Linux), Debug.isDebuggerConnected (Android)
  • SSL pinning resistant to Frida-style bypass — pin in native code, not Swift / Kotlin

Note: every resilience control will be bypassed by a determined attacker with physical device access. They buy time, they don't prevent.

Static analysis tools

ToolPlatformUse
MobSFiOS + AndroidAutomated static + dynamic scanner; first-pass triage
nuclei + mobile templatesBothPattern-based scanner
semgrep + mobile rulesBothAST-based rules
jadxAndroidDecompile APK to Java
apktoolAndroidDisassemble APK
Hopper / Ghidra / IDAiOSDisassemble Mach-O
class-dump / nm / otooliOSSymbol and structure inspection
stringsBothFirst check — secrets, URLs, debug strings
Frida + objectionBothRuntime instrumentation, SSL-pinning bypass, method tracing

Runtime testing

For grey/black-box assessment, use a non-personal device:

  • Burp Suite / mitmproxy as system proxy on the test device — observe API traffic
  • Bypass SSL pinning with Frida + objection if you need to see encrypted traffic during testing
  • Modify requests, replay them, look for IDOR / BFLA (see api-audit)
  • Force background → resume to test session handling and screenshot blur
  • Force-quit → relaunch to test session persistence and auto-login
  • Install a malicious sibling app and test IPC paths (Android Intent fuzzing)

Output Format

markdown
# Mobile Application Security Audit
## App: [name + version]
## Platform: iOS / Android / both
## MASVS profile: L1 / L2 / R (resilience required)
## Date: [date]

### Executive summary
[2-3 paragraphs]

### MASVS category findings
| Category | Findings | Severity high-water mark |
|---|---|---|
| STORAGE | N | |
| CRYPTO | N | |
| NETWORK | N | |
| AUTH | N | |
| PLATFORM | N | |
| CODE | N | |
| RESILIENCE | N | (only if R-profile) |

### Per-finding detail
[Title, MASVS-ID, severity, description, location, evidence, remediation, verification]

### Backend API findings
[Cross-link to api-audit / owasp-audit output]

### Recommendations
[Prioritized 30/60/90 day fixes]

Boundaries

  • Audit only apps you own or have written authorization to test
  • Reverse-engineering a competitor's app is a legal risk — refuse unless the user can show authorization
  • Frida / Objection / SSL-pinning bypass are for your own apps in test environments — they are not "test in production" tools
  • Refuse to help build malware, surveillance apps, or stalkerware
  • If the audit surfaces evidence of an active backdoor in someone else's code, escalate; don't quietly fix and forget

References

  • OWASP MASVS (Mobile Application Security Verification Standard)
  • OWASP MASTG (Mobile Application Security Testing Guide)
  • OWASP Mobile Top 10
  • Apple Security: Apple Platform Security Guide
  • Android Security: Android Security Best Practices
  • iOS App Programming Guide — Security
  • "iOS Application Security" — David Thiel
  • "Android Hacker's Handbook"

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/mobile-audit of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Mobile Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mobile Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mobile Audit this skillbriiirussell/cybersecurity-skills413—~2.6kAutomated safety check: WarnMIT
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Frida Mobile Securityindex-login/MobileRE-Skill158—~3kAutomated safety check: PassMIT
Mobile Security Experts7safe/android-h1211—~631Automated safety check: PassNone
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
APK Static Analysisdslsdzc/rev-skills135—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Mobile Security Expert

    s7safe/android-h1

    移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

    211 GitHub stars~631 tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • APK Static Analysis

    dslsdzc/rev-skills

    Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

    135 GitHub stars~2k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    312 GitHub stars~1.2k tokensUpdated 21 days ago
    SecurityAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Works with

Categories

Questions about Mobile Audit

What does Mobile Audit do?

Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. Mobile Audit is an agent skill from briiirussell/cybersecurity-skills. Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance.

When should I use Mobile Audit?

Mobile Audit fits situations like: the user mentions mobile security; android security; certificate pinning; jailbreak detection.

How do I install Mobile Audit in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill mobile-audit -a claude-code`. Or copy the skill folder (skills/mobile-audit in briiirussell/cybersecurity-skills) into .claude/skills/mobile-audit in your project. Claude Code loads it when a task matches its description.

How do I install Mobile Audit in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill mobile-audit -a codex`. Or copy the skill folder (skills/mobile-audit in briiirussell/cybersecurity-skills) into .agents/skills/mobile-audit in your project. Codex loads it when a task matches its description.

Can I use Mobile Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill mobile-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mobile-audit, .gemini/skills/mobile-audit, .github/skills/mobile-audit and .opencode/skills/mobile-audit in your project.

What does Mobile Audit need to run?

Going by SKILL.md and its folder, Mobile Audit needs the command-line tools its instructions call (adb). Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebSearch.

Does Mobile Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mobile Audit safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Mobile Audit use?

Mobile Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mobile Audit use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mobile Audit?

Skills that share tags, products or a category with Mobile Audit: Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Frida Mobile Security (index-login/MobileRE-Skill, 158 stars), Mobile Security Expert (s7safe/android-h1, 211 stars) and Mira Risk Collect (vw2x/Mira, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mobile Audit?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.