Security Review
getsentry/skills
Security code review for vulnerabilities. An agent skill from getsentry/skills.
Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile…
$ npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install FerroxLabs/wayland mobile-security-engineer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer .claude/skills/mobile-security-engineer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mobile-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer into .claude/skills/mobile-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-security-engineer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install FerroxLabs/wayland mobile-security-engineer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer .agents/skills/mobile-security-engineer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mobile-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer into .agents/skills/mobile-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-security-engineer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install FerroxLabs/wayland mobile-security-engineer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer .cursor/skills/mobile-security-engineer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mobile-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer into .cursor/skills/mobile-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-security-engineer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/FerroxLabs/wayland.git --path src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install FerroxLabs/wayland mobile-security-engineer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer .gemini/skills/mobile-security-engineer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mobile-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer into .gemini/skills/mobile-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-security-engineer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install FerroxLabs/wayland mobile-security-engineerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .github/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer .github/skills/mobile-security-engineer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mobile-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer into .github/skills/mobile-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-security-engineer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install FerroxLabs/wayland mobile-security-engineer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer .opencode/skills/mobile-security-engineer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mobile-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer into .opencode/skills/mobile-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-security-engineer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mobile-security-engineerMobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile…
Mobile Security Engineer is an agent skill from FerroxLabs/wayland. Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile clients, biometric authentication, secure key management, network security, reverse engineering defense, and compliance with OWASP MASVS. Use when the user asks about mobile security engineer, mobile security engineer best practices, or needs guidance on mobile security engineer implementation. Do NOT use when the user…
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Mobile application security, Cryptography and Web application vulnerabilities. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are kotlin, swift and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mobile Security Engineer loads about 4.8k tokens when it runs. Until then it costs about 157 tokens; SKILL.md has 320 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 320 words, ~4,750 tokens.
.claude/skills/mobile-security-engineer/SKILL.md (or your agent's skills folder).Mobile security engineering protects applications from reverse engineering, data theft, man-in-the-middle attacks, and runtime tampering. Mobile apps operate in hostile environments where attackers have physical device access, can decompile code, intercept network traffic, and modify app behavior at runtime. This skill covers defense-in-depth strategies aligned with OWASP Mobile Application Security Verification Standard (MASVS).
Level Target Apps Key Requirements
---------------------------------------------------------------------
MASVS-L1 All apps Basic security hygiene: secure
storage, network security, auth
MASVS-L2 Sensitive data apps Defense against targeted attacks:
(banking, health, PII) certificate pinning, obfuscation,
tampering detection
MASVS-R Highest risk apps Resilience against reverse
(payments, DRM) engineering: root detection,
integrity checks, anti-debug// URLSession delegate for certificate pinning
class PinnedSessionDelegate: NSObject, URLSessionDelegate {
// SHA-256 hash of the server's public key (SubjectPublicKeyInfo)
private let pinnedHashes: Set<String> = [
"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=", // Primary cert
"BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=", // Backup cert
]
func urlSession(
_ session: URLSession,
didReceive challenge: URLAuthenticationChallenge,
completionHandler: @escaping (URLSession.AuthChallengeDisposition, URLCredential?) -> Void
) {
guard let serverTrust = challenge.protectionSpace.serverTrust,
let certificate = SecTrustGetCertificateAtIndex(serverTrust, 0) else {
completionHandler(.cancelAuthenticationChallenge, nil)
return
}
// Extract public key and compute hash
let publicKey = SecCertificateCopyKey(certificate)
let publicKeyData = SecKeyCopyExternalRepresentation(publicKey!, nil)! as Data
let hash = SHA256.hash(data: publicKeyData)
let hashString = Data(hash).base64EncodedString()
if pinnedHashes.contains(hashString) {
completionHandler(.useCredential, URLCredential(trust: serverTrust))
} else {
// Pin validation failed - possible MITM
reportPinningFailure(host: challenge.protectionSpace.host)
completionHandler(.cancelAuthenticationChallenge, nil)
}
}
}
// TrustKit integration (recommended for production)
// Info.plist configuration:
// TSKConfiguration:
// TSKSwizzleNetworkDelegates: true
// TSKPinnedDomains:
// api.myapp.com:
// TSKPublicKeyHashes: [hash1, hash2]
// TSKEnforcePinning: true
// TSKReportUris: [[reference URL]]// OkHttp certificate pinning
val client = OkHttpClient.Builder()
.certificatePinner(
CertificatePinner.Builder()
.add("api.myapp.com",
"sha256/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=")
.add("api.myapp.com",
"sha256/BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=")
.build()
)
.build()
// Network Security Config (Android 7.0+)
// res/xml/network_security_config.xml
/*
<?xml version="1.0" encoding="utf-8"?>
<network-security-config>
<domain-config cleartextTrafficPermitted="false">
<domain includeSubdomains="true">api.myapp.com</domain>
<pin-set expiration="2025-06-01">
<pin digest="SHA-256">AAAAAAAAAA...=</pin>
<pin digest="SHA-256">BBBBBBBBBB...=</pin>
</pin-set>
</domain-config>
<base-config cleartextTrafficPermitted="false">
<trust-anchors>
<certificates src="system" />
</trust-anchors>
</base-config>
</network-security-config>
*/DO:
- Pin the public key hash (SPKI), not the certificate itself
- Always include at least one backup pin (different CA)
- Set expiration dates and plan for rotation
- Report pinning failures to a monitoring endpoint
- Test pin rotation in staging before production
DON'T:
- Pin leaf certificate (breaks on renewal)
- Use only one pin (no recovery if key compromised)
- Skip to update pins before expiration
- Pin in debug builds (breaks proxy debugging)import Security
class SecureStorage {
func store(key: String, data: Data, accessibility: CFString = kSecAttrAccessibleWhenUnlockedThisDeviceOnly) throws {
let query: [String: Any] = [
kSecClass as String: kSecClassGenericPassword,
kSecAttrAccount as String: key,
kSecValueData as String: data,
kSecAttrAccessible as String: accessibility,
kSecAttrAccessControl as String: SecAccessControlCreateWithFlags(
nil,
accessibility,
.biometryCurrentSet,
nil
)!,
]
// Delete existing item first
SecItemDelete(query as CFDictionary)
let status = SecItemAdd(query as CFDictionary, nil)
guard status == errSecSuccess else {
throw KeychainError.storeFailed(status)
}
}
func get(key: String) throws -> Data? {
let query: [String: Any] = [
kSecClass as String: kSecClassGenericPassword,
kSecAttrAccount as String: key,
kSecReturnData as String: true,
kSecMatchLimit as String: kSecMatchLimitOne,
]
var result: AnyObject?
let status = SecItemCopyMatching(query as CFDictionary, &result)
switch status {
case errSecSuccess:
return result as? Data
case errSecItemNotFound:
return nil
default:
throw KeychainError.retrieveFailed(status)
}
}
}
// Accessibility levels (choose based on security needs):
// kSecAttrAccessibleWhenUnlockedThisDeviceOnly - Best for most sensitive data
// kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly - Good for background access
// kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly - Deleted if passcode removedimport androidx.security.crypto.EncryptedSharedPreferences
import androidx.security.crypto.MasterKeys
import android.security.keystore.KeyGenParameterSpec
import android.security.keystore.KeyProperties
class SecureStorage(context: Context) {
private val masterKeyAlias = MasterKeys.getOrCreate(
KeyGenParameterSpec.Builder(
MasterKeys.AES256_GCM_SPEC.keystoreAlias,
KeyProperties.PURPOSE_ENCRYPT or KeyProperties.PURPOSE_DECRYPT
)
.setBlockModes(KeyProperties.BLOCK_MODE_GCM)
.setEncryptionPaddings(KeyProperties.ENCRYPTION_PADDING_NONE)
.setKeySize(256)
.setUserAuthenticationRequired(true)
.setUserAuthenticationValidityDurationSeconds(300) // 5 min
.build()
)
private val encryptedPrefs = EncryptedSharedPreferences.create(
"secure_prefs",
masterKeyAlias,
context,
EncryptedSharedPreferences.PrefKeyEncryptionScheme.AES256_SIV,
EncryptedSharedPreferences.PrefValueEncryptionScheme.AES256_GCM
)
fun storeToken(key: String, token: String) {
encryptedPrefs.edit().putString(key, token).apply()
}
fun getToken(key: String): String? {
return encryptedPrefs.getString(key, null)
}
}
// Storage decision matrix:
// Auth tokens -> EncryptedSharedPreferences or Keystore
// User credentials -> Android Keystore (hardware-backed)
// Session data -> In-memory only (cleared on app close)
// Cached API data -> Encrypted database (SQLCipher)
// NEVER use: -> Plain SharedPreferences, plain SQLite, external storageclass DeviceIntegrityChecker {
fun isDeviceCompromised(): Boolean {
return isRooted() || isEmulator() || isDebuggerAttached() || isHooked()
}
private fun isRooted(): Boolean {
val checks = listOf(
::checkRootManagementApps,
::checkSuBinary,
::checkDangerousProps,
::checkRWSystem,
::checkMagisk,
)
return checks.any { it() }
}
private fun checkRootManagementApps(): Boolean {
val rootApps = listOf(
"com.topjohnwu.magisk",
"eu.chainfire.supersu",
"com.koushikdutta.superuser",
)
return rootApps.any { isPackageInstalled(it) }
}
private fun checkSuBinary(): Boolean {
val paths = listOf(
"/system/bin/su", "/system/xbin/su",
"/sbin/su", "/data/local/su",
"/data/local/bin/su", "/data/local/xbin/su",
)
return paths.any { File(it).exists() }
}
private fun checkMagisk(): Boolean {
// Magisk hides itself, check for signs using ProcessBuilder
return try {
val process = ProcessBuilder("which", "magisk")
.redirectErrorStream(true)
.start()
process.waitFor() == 0
} catch (e: Exception) {
false
}
}
private fun isEmulator(): Boolean {
return (Build.FINGERPRINT.contains("generic")
|| Build.MODEL.contains("Emulator")
|| Build.MODEL.contains("Android SDK built for x86")
|| Build.HARDWARE.contains("goldfish")
|| Build.HARDWARE.contains("ranchu")
|| Build.PRODUCT.contains("sdk_gphone"))
}
private fun isDebuggerAttached(): Boolean {
return android.os.Debug.isDebuggerConnected()
|| android.os.Debug.waitingForDebugger()
}
private fun isHooked(): Boolean {
// Check for Frida (common hooking framework)
return try {
// Frida typically listens on port 27042
val socket = java.net.Socket()
socket.connect(java.net.InetSocketAddress("127.0.0.1", 27042), 1000)
socket.close()
true // Connection succeeded = Frida detected
} catch (e: Exception) {
false
}
}
}Detection Level Response User Experience
------------------------------------------------------------------------
Informational Log and monitor Transparent (analytics only)
Warning Disable sensitive features "Some features unavailable
(biometric, payments) on modified devices"
Blocking Prevent app from running "This app cannot run on
modified devices"
Silent Corrupt sensitive data, No visible indication
report to server (honeypot approach)
Recommendation: Use graduated response. Don't block outright unless
regulation requires it (banking). Always report to server for risk scoring.class SecureApiClient(private val context: Context) {
// Device attestation for API calls
fun getDeviceAttestation(): String {
// Android: Use Play Integrity API
val integrityManager = IntegrityManagerFactory.create(context)
val integrityTokenResponse = integrityManager
.requestIntegrityToken(
IntegrityTokenRequest.builder()
.setNonce(generateNonce())
.build()
)
.await()
return integrityTokenResponse.token()
}
// Request signing to prevent tampering
fun signRequest(method: String, path: String, body: String, timestamp: Long): String {
val message = "$method\n$path\n$timestamp\n${sha256(body)}"
val key = getSigningKey() // From secure storage
return hmacSha256(key, message)
}
// Anti-replay: timestamp + nonce
fun buildSecureHeaders(request: Request): Headers {
val timestamp = System.currentTimeMillis() / 1000
val nonce = UUID.randomUUID().toString()
val body = request.body?.toString() ?: ""
return Headers.Builder()
.add("X-Timestamp", timestamp.toString())
.add("X-Nonce", nonce)
.add("X-Signature", signRequest(
request.method, request.url.encodedPath, body, timestamp))
.add("X-Device-Id", getDeviceId())
.add("X-App-Version", BuildConfig.VERSION_NAME)
.build()
}
}Transport:
[ ] TLS 1.2+ enforced (no cleartext)
[ ] Certificate pinning with backup pins
[ ] No sensitive data in URL parameters
Authentication:
[ ] Short-lived access tokens (15 min)
[ ] Refresh tokens stored in secure storage
[ ] Biometric gating for sensitive operations
[ ] Device attestation for critical endpoints
Request Security:
[ ] Request signing (HMAC)
[ ] Timestamp validation (prevent replay)
[ ] Rate limiting per device
[ ] Input validation on client AND server
Response Security:
[ ] No sensitive data in responses beyond need
[ ] Cache-Control: no-store for sensitive endpoints
[ ] Response integrity verificationimport LocalAuthentication
class BiometricAuth {
func authenticate(reason: String, completion: @escaping (Bool, Error?) -> Void) {
let context = LAContext()
context.localizedFallbackTitle = "Use Passcode"
var error: NSError?
guard context.canEvaluatePolicy(.deviceOwnerAuthenticationWithBiometrics, error: &error) else {
completion(false, error)
return
}
context.evaluatePolicy(
.deviceOwnerAuthenticationWithBiometrics,
localizedReason: reason
) { success, authError in
DispatchQueue.main.async {
completion(success, authError)
}
}
}
func biometricType() -> String {
let context = LAContext()
_ = context.canEvaluatePolicy(.deviceOwnerAuthenticationWithBiometrics, error: nil)
switch context.biometryType {
case .faceID: return "Face ID"
case .touchID: return "Touch ID"
case .opticID: return "Optic ID"
default: return "None"
}
}
}Storage (MASVS-STORAGE):
[ ] Sensitive data not in plaintext storage
[ ] Keychain/Keystore used for credentials
[ ] No sensitive data in app backups
[ ] No sensitive data in system logs
[ ] Clipboard cleared after paste of sensitive data
[ ] No sensitive data in screenshots/app switcher
Network (MASVS-NETWORK):
[ ] TLS 1.2+ with strong cipher suites
[ ] Certificate pinning implemented
[ ] No cleartext traffic permitted
[ ] Certificate validation not bypassed
Authentication (MASVS-AUTH):
[ ] Biometric auth uses platform APIs correctly
[ ] Session tokens properly invalidated on logout
[ ] Password/PIN stored as hash, never plaintext
[ ] Step-up auth for sensitive operations
Resilience (MASVS-RESILIENCE):
[ ] Root/jailbreak detection active
[ ] Debugger detection active
[ ] Code obfuscation applied
[ ] Integrity checks on app binary
[ ] Reverse engineering countermeasures tested
Platform (MASVS-PLATFORM):
[ ] Permissions minimized to required only
[ ] WebView configured securely (no file access)
[ ] Deep links validated (no open redirect)
[ ] IPC mechanisms securedUse this skill when:
Do NOT use this skill when:
# Mobile Security Engineer Analysis
## Context Assessment
[Situation summary and constraints]
## Recommended Approach
[Primary recommendation with rationale]
## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]
## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]
## Next Steps
- [Immediate action item]
- [Follow-up action item]Input: "Help me implement mobile security engineer for a medium-scale production application"
Output: A structured analysis covering current state assessment, recommended mobile security engineer approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.
© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer of FerroxLabs/wayland.
Open the folder on GitHubat commit 4c030c7
Mobile Security Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mobile Security Engineer this skillFerroxLabs/wayland | 608 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| Security Reviewgetsentry/skills | 1k | 4 repos | ~2.9k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Code Securitysemgrep/skills | 322 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Crypto Auditbriiirussell/cybersecurity-skills | 412 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Security Auditjellydn/my-ai-tools | 123 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT |
getsentry/skills
Security code review for vulnerabilities. An agent skill from getsentry/skills.
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
briiirussell/cybersecurity-skills
Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.
jellydn/my-ai-tools
A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
unxed/f4
Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…
FerroxLabs/wayland
Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.
FerroxLabs/wayland
OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.
FerroxLabs/wayland
Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.
FerroxLabs/wayland
End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.
FerroxLabs/wayland
Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…
FerroxLabs/wayland
Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…
Categories
Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile…. Mobile Security Engineer is an agent skill from FerroxLabs/wayland. Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile clients, biometric authentication, secure key management, network security, reverse engineering defense, and compliance with OWASP MASVS.
Mobile Security Engineer fits situations like: the user asks about mobile security engineer; mobile security engineer best practices; needs guidance on mobile security engineer implementation; the user needs a different specialized skill.
Run `npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer in FerroxLabs/wayland) into .claude/skills/mobile-security-engineer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/software-engineering/mobile-security-engineer in FerroxLabs/wayland) into .agents/skills/mobile-security-engineer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill mobile-security-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mobile-security-engineer, .gemini/skills/mobile-security-engineer, .github/skills/mobile-security-engineer and .opencode/skills/mobile-security-engineer in your project.
SKILL.md names no scripts, command-line tools or credentials: Mobile Security Engineer is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Mobile Security Engineer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Mobile Security Engineer: Security Review (getsentry/skills, 1k stars), Code Security (semgrep/skills, 322 stars), Crypto Audit (briiirussell/cybersecurity-skills, 412 stars) and Security Audit (jellydn/my-ai-tools, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.
Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.