Agent skill

Mobile Security Engineer

by FerroxLabs in FerroxLabs/wayland

Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile…

Apache-2.0Auto-check passedSecurity

Install Mobile Security Engineer

skills CLI
$ npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FerroxLabs/wayland mobile-security-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer .claude/skills/mobile-security-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mobile-security-engineer
GitHub stars
608
Token cost
~4.8k tokens
SKILL.md length
320 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0

At a glance

Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile…

  • The user asks about mobile security engineer
  • SKILL.md covers Overview, OWASP MASVS Security Levels, Certificate Pinning and Secure Storage, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Mobile security engineer best practices

What it does

Mobile Security Engineer is an agent skill from FerroxLabs/wayland. Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile clients, biometric authentication, secure key management, network security, reverse engineering defense, and compliance with OWASP MASVS. Use when the user asks about mobile security engineer, mobile security engineer best practices, or needs guidance on mobile security engineer implementation. Do NOT use when the user…

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security, Cryptography and Web application vulnerabilities. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.

When your agent uses it

  • The user asks about mobile security engineer
  • Mobile security engineer best practices
  • Needs guidance on mobile security engineer implementation
  • The user needs a different specialized skill

Example prompts

  • “/mobile-security-engineer”

What it can do on your machine

Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are kotlin, swift and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mobile Security Engineer loads about 4.8k tokens when it runs. Until then it costs about 157 tokens; SKILL.md has 320 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~157
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 320 words, ~4,750 tokens.

Download SKILL.mdSave it as .claude/skills/mobile-security-engineer/SKILL.md (or your agent's skills folder).
name
mobile-security-engineer
description
Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile clients, biometric authentication, secure key management, network security, reverse engineering defense, and compliance with OWASP MASVS. Use when the user asks about mobile security engineer, mobile security engineer best practices, or needs guidance on mobile security engineer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
mobile best-practices security
metadata.category
software-engineering
metadata.subcategory
mobile-development
metadata.disclaimer
none
metadata.difficulty
intermediate

Mobile Security Engineer

Overview

Mobile security engineering protects applications from reverse engineering, data theft, man-in-the-middle attacks, and runtime tampering. Mobile apps operate in hostile environments where attackers have physical device access, can decompile code, intercept network traffic, and modify app behavior at runtime. This skill covers defense-in-depth strategies aligned with OWASP Mobile Application Security Verification Standard (MASVS).

OWASP MASVS Security Levels

Level        Target Apps              Key Requirements
---------------------------------------------------------------------
MASVS-L1     All apps                 Basic security hygiene: secure
                                      storage, network security, auth

MASVS-L2     Sensitive data apps      Defense against targeted attacks:
             (banking, health, PII)   certificate pinning, obfuscation,
                                      tampering detection

MASVS-R      Highest risk apps        Resilience against reverse
             (payments, DRM)          engineering: root detection,
                                      integrity checks, anti-debug

Certificate Pinning

iOS Certificate Pinning
swift
// URLSession delegate for certificate pinning
class PinnedSessionDelegate: NSObject, URLSessionDelegate {
    // SHA-256 hash of the server's public key (SubjectPublicKeyInfo)
    private let pinnedHashes: Set<String> = [
        "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=",  // Primary cert
        "BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=",  // Backup cert
    ]

    func urlSession(
        _ session: URLSession,
        didReceive challenge: URLAuthenticationChallenge,
        completionHandler: @escaping (URLSession.AuthChallengeDisposition, URLCredential?) -> Void
    ) {
        guard let serverTrust = challenge.protectionSpace.serverTrust,
              let certificate = SecTrustGetCertificateAtIndex(serverTrust, 0) else {
            completionHandler(.cancelAuthenticationChallenge, nil)
            return
        }

        // Extract public key and compute hash
        let publicKey = SecCertificateCopyKey(certificate)
        let publicKeyData = SecKeyCopyExternalRepresentation(publicKey!, nil)! as Data
        let hash = SHA256.hash(data: publicKeyData)
        let hashString = Data(hash).base64EncodedString()

        if pinnedHashes.contains(hashString) {
            completionHandler(.useCredential, URLCredential(trust: serverTrust))
        } else {
            // Pin validation failed - possible MITM
            reportPinningFailure(host: challenge.protectionSpace.host)
            completionHandler(.cancelAuthenticationChallenge, nil)
        }
    }
}

// TrustKit integration (recommended for production)
// Info.plist configuration:
// TSKConfiguration:
//   TSKSwizzleNetworkDelegates: true
//   TSKPinnedDomains:
//     api.myapp.com:
//       TSKPublicKeyHashes: [hash1, hash2]
//       TSKEnforcePinning: true
//       TSKReportUris: [[reference URL]]
Android Certificate Pinning
kotlin
// OkHttp certificate pinning
val client = OkHttpClient.Builder()
    .certificatePinner(
        CertificatePinner.Builder()
            .add("api.myapp.com",
                "sha256/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=")
            .add("api.myapp.com",
                "sha256/BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=")
            .build()
    )
    .build()

// Network Security Config (Android 7.0+)
// res/xml/network_security_config.xml
/*
<?xml version="1.0" encoding="utf-8"?>
<network-security-config>
    <domain-config cleartextTrafficPermitted="false">
        <domain includeSubdomains="true">api.myapp.com</domain>
        <pin-set expiration="2025-06-01">
            <pin digest="SHA-256">AAAAAAAAAA...=</pin>
            <pin digest="SHA-256">BBBBBBBBBB...=</pin>
        </pin-set>
    </domain-config>

    <base-config cleartextTrafficPermitted="false">
        <trust-anchors>
            <certificates src="system" />
        </trust-anchors>
    </base-config>
</network-security-config>
*/
Certificate Pinning Best Practices
DO:
  - Pin the public key hash (SPKI), not the certificate itself
  - Always include at least one backup pin (different CA)
  - Set expiration dates and plan for rotation
  - Report pinning failures to a monitoring endpoint
  - Test pin rotation in staging before production

DON'T:
  - Pin leaf certificate (breaks on renewal)
  - Use only one pin (no recovery if key compromised)
  - Skip to update pins before expiration
  - Pin in debug builds (breaks proxy debugging)

Secure Storage

iOS Keychain
swift
import Security

class SecureStorage {

    func store(key: String, data: Data, accessibility: CFString = kSecAttrAccessibleWhenUnlockedThisDeviceOnly) throws {
        let query: [String: Any] = [
            kSecClass as String: kSecClassGenericPassword,
            kSecAttrAccount as String: key,
            kSecValueData as String: data,
            kSecAttrAccessible as String: accessibility,
            kSecAttrAccessControl as String: SecAccessControlCreateWithFlags(
                nil,
                accessibility,
                .biometryCurrentSet,
                nil
            )!,
        ]

        // Delete existing item first
        SecItemDelete(query as CFDictionary)

        let status = SecItemAdd(query as CFDictionary, nil)
        guard status == errSecSuccess else {
            throw KeychainError.storeFailed(status)
        }
    }

    func get(key: String) throws -> Data? {
        let query: [String: Any] = [
            kSecClass as String: kSecClassGenericPassword,
            kSecAttrAccount as String: key,
            kSecReturnData as String: true,
            kSecMatchLimit as String: kSecMatchLimitOne,
        ]

        var result: AnyObject?
        let status = SecItemCopyMatching(query as CFDictionary, &result)

        switch status {
        case errSecSuccess:
            return result as? Data
        case errSecItemNotFound:
            return nil
        default:
            throw KeychainError.retrieveFailed(status)
        }
    }
}

// Accessibility levels (choose based on security needs):
// kSecAttrAccessibleWhenUnlockedThisDeviceOnly  - Best for most sensitive data
// kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly - Good for background access
// kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly - Deleted if passcode removed
Android Encrypted Storage
kotlin
import androidx.security.crypto.EncryptedSharedPreferences
import androidx.security.crypto.MasterKeys
import android.security.keystore.KeyGenParameterSpec
import android.security.keystore.KeyProperties

class SecureStorage(context: Context) {
    private val masterKeyAlias = MasterKeys.getOrCreate(
        KeyGenParameterSpec.Builder(
            MasterKeys.AES256_GCM_SPEC.keystoreAlias,
            KeyProperties.PURPOSE_ENCRYPT or KeyProperties.PURPOSE_DECRYPT
        )
        .setBlockModes(KeyProperties.BLOCK_MODE_GCM)
        .setEncryptionPaddings(KeyProperties.ENCRYPTION_PADDING_NONE)
        .setKeySize(256)
        .setUserAuthenticationRequired(true)
        .setUserAuthenticationValidityDurationSeconds(300) // 5 min
        .build()
    )

    private val encryptedPrefs = EncryptedSharedPreferences.create(
        "secure_prefs",
        masterKeyAlias,
        context,
        EncryptedSharedPreferences.PrefKeyEncryptionScheme.AES256_SIV,
        EncryptedSharedPreferences.PrefValueEncryptionScheme.AES256_GCM
    )

    fun storeToken(key: String, token: String) {
        encryptedPrefs.edit().putString(key, token).apply()
    }

    fun getToken(key: String): String? {
        return encryptedPrefs.getString(key, null)
    }
}

// Storage decision matrix:
// Auth tokens      -> EncryptedSharedPreferences or Keystore
// User credentials -> Android Keystore (hardware-backed)
// Session data     -> In-memory only (cleared on app close)
// Cached API data  -> Encrypted database (SQLCipher)
// NEVER use:       -> Plain SharedPreferences, plain SQLite, external storage

Jailbreak and Root Detection

Multi-Layer Detection
kotlin
class DeviceIntegrityChecker {

    fun isDeviceCompromised(): Boolean {
        return isRooted() || isEmulator() || isDebuggerAttached() || isHooked()
    }

    private fun isRooted(): Boolean {
        val checks = listOf(
            ::checkRootManagementApps,
            ::checkSuBinary,
            ::checkDangerousProps,
            ::checkRWSystem,
            ::checkMagisk,
        )
        return checks.any { it() }
    }

    private fun checkRootManagementApps(): Boolean {
        val rootApps = listOf(
            "com.topjohnwu.magisk",
            "eu.chainfire.supersu",
            "com.koushikdutta.superuser",
        )
        return rootApps.any { isPackageInstalled(it) }
    }

    private fun checkSuBinary(): Boolean {
        val paths = listOf(
            "/system/bin/su", "/system/xbin/su",
            "/sbin/su", "/data/local/su",
            "/data/local/bin/su", "/data/local/xbin/su",
        )
        return paths.any { File(it).exists() }
    }

    private fun checkMagisk(): Boolean {
        // Magisk hides itself, check for signs using ProcessBuilder
        return try {
            val process = ProcessBuilder("which", "magisk")
                .redirectErrorStream(true)
                .start()
            process.waitFor() == 0
        } catch (e: Exception) {
            false
        }
    }

    private fun isEmulator(): Boolean {
        return (Build.FINGERPRINT.contains("generic")
            || Build.MODEL.contains("Emulator")
            || Build.MODEL.contains("Android SDK built for x86")
            || Build.HARDWARE.contains("goldfish")
            || Build.HARDWARE.contains("ranchu")
            || Build.PRODUCT.contains("sdk_gphone"))
    }

    private fun isDebuggerAttached(): Boolean {
        return android.os.Debug.isDebuggerConnected()
            || android.os.Debug.waitingForDebugger()
    }

    private fun isHooked(): Boolean {
        // Check for Frida (common hooking framework)
        return try {
            // Frida typically listens on port 27042
            val socket = java.net.Socket()
            socket.connect(java.net.InetSocketAddress("127.0.0.1", 27042), 1000)
            socket.close()
            true  // Connection succeeded = Frida detected
        } catch (e: Exception) {
            false
        }
    }
}
Response Strategies for Compromised Devices
Detection Level    Response                      User Experience
------------------------------------------------------------------------
Informational      Log and monitor               Transparent (analytics only)
Warning            Disable sensitive features     "Some features unavailable
                   (biometric, payments)          on modified devices"
Blocking           Prevent app from running       "This app cannot run on
                                                  modified devices"
Silent             Corrupt sensitive data,        No visible indication
                   report to server               (honeypot approach)

Recommendation: Use graduated response. Don't block outright unless
regulation requires it (banking). Always report to server for risk scoring.

API Security for Mobile

Secure API Communication Pattern
kotlin
class SecureApiClient(private val context: Context) {

    // Device attestation for API calls
    fun getDeviceAttestation(): String {
        // Android: Use Play Integrity API
        val integrityManager = IntegrityManagerFactory.create(context)
        val integrityTokenResponse = integrityManager
            .requestIntegrityToken(
                IntegrityTokenRequest.builder()
                    .setNonce(generateNonce())
                    .build()
            )
            .await()
        return integrityTokenResponse.token()
    }

    // Request signing to prevent tampering
    fun signRequest(method: String, path: String, body: String, timestamp: Long): String {
        val message = "$method\n$path\n$timestamp\n${sha256(body)}"
        val key = getSigningKey()  // From secure storage
        return hmacSha256(key, message)
    }

    // Anti-replay: timestamp + nonce
    fun buildSecureHeaders(request: Request): Headers {
        val timestamp = System.currentTimeMillis() / 1000
        val nonce = UUID.randomUUID().toString()
        val body = request.body?.toString() ?: ""

        return Headers.Builder()
            .add("X-Timestamp", timestamp.toString())
            .add("X-Nonce", nonce)
            .add("X-Signature", signRequest(
                request.method, request.url.encodedPath, body, timestamp))
            .add("X-Device-Id", getDeviceId())
            .add("X-App-Version", BuildConfig.VERSION_NAME)
            .build()
    }
}
API Security Checklist
Transport:
  [ ] TLS 1.2+ enforced (no cleartext)
  [ ] Certificate pinning with backup pins
  [ ] No sensitive data in URL parameters

Authentication:
  [ ] Short-lived access tokens (15 min)
  [ ] Refresh tokens stored in secure storage
  [ ] Biometric gating for sensitive operations
  [ ] Device attestation for critical endpoints

Request Security:
  [ ] Request signing (HMAC)
  [ ] Timestamp validation (prevent replay)
  [ ] Rate limiting per device
  [ ] Input validation on client AND server

Response Security:
  [ ] No sensitive data in responses beyond need
  [ ] Cache-Control: no-store for sensitive endpoints
  [ ] Response integrity verification

Biometric Authentication

iOS Face ID / Touch ID
swift
import LocalAuthentication

class BiometricAuth {
    func authenticate(reason: String, completion: @escaping (Bool, Error?) -> Void) {
        let context = LAContext()
        context.localizedFallbackTitle = "Use Passcode"

        var error: NSError?
        guard context.canEvaluatePolicy(.deviceOwnerAuthenticationWithBiometrics, error: &error) else {
            completion(false, error)
            return
        }

        context.evaluatePolicy(
            .deviceOwnerAuthenticationWithBiometrics,
            localizedReason: reason
        ) { success, authError in
            DispatchQueue.main.async {
                completion(success, authError)
            }
        }
    }

    func biometricType() -> String {
        let context = LAContext()
        _ = context.canEvaluatePolicy(.deviceOwnerAuthenticationWithBiometrics, error: nil)
        switch context.biometryType {
        case .faceID: return "Face ID"
        case .touchID: return "Touch ID"
        case .opticID: return "Optic ID"
        default: return "None"
        }
    }
}

Security Testing Checklist (MASVS Aligned)

Storage (MASVS-STORAGE):
  [ ] Sensitive data not in plaintext storage
  [ ] Keychain/Keystore used for credentials
  [ ] No sensitive data in app backups
  [ ] No sensitive data in system logs
  [ ] Clipboard cleared after paste of sensitive data
  [ ] No sensitive data in screenshots/app switcher

Network (MASVS-NETWORK):
  [ ] TLS 1.2+ with strong cipher suites
  [ ] Certificate pinning implemented
  [ ] No cleartext traffic permitted
  [ ] Certificate validation not bypassed

Authentication (MASVS-AUTH):
  [ ] Biometric auth uses platform APIs correctly
  [ ] Session tokens properly invalidated on logout
  [ ] Password/PIN stored as hash, never plaintext
  [ ] Step-up auth for sensitive operations

Resilience (MASVS-RESILIENCE):
  [ ] Root/jailbreak detection active
  [ ] Debugger detection active
  [ ] Code obfuscation applied
  [ ] Integrity checks on app binary
  [ ] Reverse engineering countermeasures tested

Platform (MASVS-PLATFORM):
  [ ] Permissions minimized to required only
  [ ] WebView configured securely (no file access)
  [ ] Deep links validated (no open redirect)
  [ ] IPC mechanisms secured

When to Use

Use this skill when:

  • Designing or implementing mobile security engineer solutions
  • Reviewing or improving existing mobile security engineer approaches
  • Making architectural or implementation decisions about mobile security engineer
  • Learning mobile security engineer patterns and best practices
  • Troubleshooting mobile security engineer-related issues

Do NOT use this skill when:

  • The question is about a fundamentally different technology domain
  • A more specific sibling skill covers the exact topic needed
  • The user needs a complete hands-on tutorial rather than expert guidance

Output Format

markdown
# Mobile Security Engineer Analysis

## Context Assessment
[Situation summary and constraints]

## Recommended Approach
[Primary recommendation with rationale]

## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]

## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]

## Next Steps
- [Immediate action item]
- [Follow-up action item]

Example

Input: "Help me implement mobile security engineer for a medium-scale production application"

Output: A structured analysis covering current state assessment, recommended mobile security engineer approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.

Edge Cases

  • Legacy system integration: When mobile security engineer must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
  • Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
  • Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
  • Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities

© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer of FerroxLabs/wayland.

Open the folder on GitHubat commit 4c030c7

Compare with similar skills

Mobile Security Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mobile Security Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mobile Security Engineer this skillFerroxLabs/wayland608—~4.8kAutomated safety check: PassApache-2.0
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Crypto Auditbriiirussell/cybersecurity-skills412—~2.8kAutomated safety check: NotesMIT
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT

Similar skills

  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    412 GitHub stars~2.8k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    240 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed

More from FerroxLabs/wayland

All 1,194 skills in this repo
  • Star Office Helper

    FerroxLabs/wayland

    Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.

    608 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Openclaw Setup

    FerroxLabs/wayland

    OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.

    608 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Tvcontrol Setup

    FerroxLabs/wayland

    Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.

    608 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Ab Testing Specialist

    FerroxLabs/wayland

    End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.

    608 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Academic Writer

    FerroxLabs/wayland

    Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Auditor

    FerroxLabs/wayland

    Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…

    608 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Mobile Security Engineer

What does Mobile Security Engineer do?

Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile…. Mobile Security Engineer is an agent skill from FerroxLabs/wayland. Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile clients, biometric authentication, secure key management, network security, reverse engineering defense, and compliance with OWASP MASVS.

When should I use Mobile Security Engineer?

Mobile Security Engineer fits situations like: the user asks about mobile security engineer; mobile security engineer best practices; needs guidance on mobile security engineer implementation; the user needs a different specialized skill.

How do I install Mobile Security Engineer in Claude Code?

Run `npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer in FerroxLabs/wayland) into .claude/skills/mobile-security-engineer in your project. Claude Code loads it when a task matches its description.

How do I install Mobile Security Engineer in Codex?

Run `npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer in FerroxLabs/wayland) into .agents/skills/mobile-security-engineer in your project. Codex loads it when a task matches its description.

Can I use Mobile Security Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mobile-security-engineer, .gemini/skills/mobile-security-engineer, .github/skills/mobile-security-engineer and .opencode/skills/mobile-security-engineer in your project.

What does Mobile Security Engineer need to run?

SKILL.md names no scripts, command-line tools or credentials: Mobile Security Engineer is instructions for the agent only.

Does Mobile Security Engineer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mobile Security Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mobile Security Engineer use?

Mobile Security Engineer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mobile Security Engineer use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mobile Security Engineer?

Skills that share tags, products or a category with Mobile Security Engineer: Security Review (getsentry/skills, 1k stars), Code Security (semgrep/skills, 322 stars), Crypto Audit (briiirussell/cybersecurity-skills, 412 stars) and Security Audit (jellydn/my-ai-tools, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mobile Security Engineer?

FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.

Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.