Agent skill

Conducting Mobile App Penetration Test

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

Apache-2.0Auto-check passedSecurity

Install Conducting Mobile App Penetration Test

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-mobile-app-penetration-test -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills conducting-mobile-app-penetration-test --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/conducting-mobile-app-penetration-test .claude/skills/conducting-mobile-app-penetration-test && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
conducting-mobile-app-penetration-test
GitHub stars
34k
Token cost
~3.2k tokens
SKILL.md length
1,305 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

  • Works in 5 steps: Static Analysis → Network Security Testing → Data Storage Analysis → …
  • Tasks that involve Mobile application security
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls python, sqlite3 and adb

What it does

Conducting Mobile App Penetration Test is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Mobile application security, Penetration testing and Static analysis and SAST. It works with Android and iOS. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Mobile application security
  • Tasks that involve Penetration testing
  • Tasks that involve Static analysis and SAST

Example prompts

  • “Use the conducting-mobile-app-penetration-test skill to conduct penetration testing of iOS and Android mobile applications following the OWASP…”
  • “/conducting-mobile-app-penetration-test”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Static Analysis
  2. Network Security Testing
  3. Data Storage Analysis
  4. Authentication and Session Management
  5. Runtime Manipulation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • sqlite3
    • adb

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Conducting Mobile App Penetration Test loads about 3.2k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 152 tokens; SKILL.md has 1,305 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~152
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,305 words, ~3,183 tokens.

Download SKILL.mdSave it as .claude/skills/conducting-mobile-app-penetration-test/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
conducting-mobile-app-penetration-test
description
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment, Android security testing, or OWASP MASTG assessment.
domain
cybersecurity
subdomain
penetration-testing
tags
mobile-pentest, OWASP-MASTG, Android-security, iOS-security, mobile-application-security
version
1.0.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4
atlas_techniques
AML.T0070, AML.T0066, AML.T0082
nist_csf
ID.RA-01, ID.RA-06, GV.OV-02, DE.AE-07
mitre_attack
T1426, T1409, T1521.003, T1633, T1417, T1422

Conducting Mobile App Penetration Test

When to Use

  • Testing mobile applications before release to identify security vulnerabilities and data protection issues
  • Conducting compliance assessments against OWASP MASVS (Mobile Application Security Verification Standard) levels L1 and L2
  • Evaluating the security of mobile banking, healthcare, or government applications handling sensitive data
  • Testing mobile apps that interact with backend APIs to assess the end-to-end security of the mobile ecosystem
  • Assessing mobile application resistance to reverse engineering, tampering, and runtime manipulation

Do not use against mobile applications without written authorization from the application owner, for distributing modified or repackaged applications, or for testing apps on the public app stores without a separate test build.

Prerequisites

  • Target application IPA (iOS) and APK (Android) files or access to download from a private distribution channel
  • Rooted Android device or emulator (Genymotion, Android Studio AVD) with Frida, Objection, and Magisk installed
  • Jailbroken iOS device or Corellium virtual device with Frida, Objection, and SSL Kill Switch installed
  • Static analysis tools: jadx (Android decompilation), Hopper/Ghidra (iOS binary analysis), MobSF (automated scanning)
  • Burp Suite Professional configured as proxy for intercepting mobile app traffic with CA certificate installed on the test device

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Workflow

Step 1: Static Analysis

Analyze the application binary without executing it:

Android Static Analysis:

  • Decompile the APK: jadx -d output/ target.apk to obtain Java/Kotlin source code
  • Review AndroidManifest.xml for exported components (activities, services, receivers, content providers), permissions, and debuggable flag
  • Search for hardcoded secrets: grep -rn "api_key\|password\|secret\|token\|aws_" output/
  • Identify insecure data storage patterns: SharedPreferences with sensitive data, SQLite databases without encryption, files in external storage
  • Check for WebView vulnerabilities: setJavaScriptEnabled(true), addJavascriptInterface(), and loading untrusted content
  • Run MobSF automated scan: python manage.py runserver and upload the APK for automated static analysis

iOS Static Analysis:

  • Extract the IPA and locate the Mach-O binary
  • Use otool -L <binary> to list linked frameworks and identify third-party libraries
  • Analyze with Ghidra or Hopper for hardcoded URLs, API endpoints, and embedded credentials
  • Check Info.plist for App Transport Security (ATS) exceptions that allow insecure HTTP connections
  • Review embedded entitlements for excessive capabilities
Step 2: Network Security Testing

Intercept and analyze all network communications:

  • Configure Burp Suite as proxy on the test device and install the Burp CA certificate
  • Exercise all application functionality while Burp captures API traffic
  • SSL/TLS validation: Verify the app validates server certificates properly. If the app fails to connect through the proxy, it may implement certificate pinning.
  • Certificate pinning bypass:
    • Android: Use Frida script: frida -U -f com.target.app -l ssl-pinning-bypass.js --no-pause
    • iOS: Use SSL Kill Switch or Objection: objection -g "Target App" explore --startup-command "ios sslpinning disable"
  • API traffic analysis: Review all API calls for:
    • Sensitive data transmitted without encryption
    • Authentication tokens in URL parameters (visible in logs)
    • Excessive data in API responses beyond what the UI displays
    • Missing or weak authentication on API endpoints
  • WebSocket and custom protocols: Check for non-HTTP communication channels that may bypass standard proxy interception
Step 3: Data Storage Analysis

Test for insecure local data storage:

Android Data Storage:

  • Access app data directory: /data/data/com.target.app/
  • Check SharedPreferences XML files for stored credentials, tokens, and PII
  • Examine SQLite databases: sqlite3 /data/data/com.target.app/databases/*.db ".dump"
  • Check for sensitive data in application logs: logcat -d | grep -i "password\|token\|key"
  • Verify that application data is excluded from backups: android:allowBackup="false" in AndroidManifest.xml
  • Check clipboard for sensitive data leakage

iOS Data Storage:

  • Examine the Keychain for stored credentials: objection -g "Target App" explore then ios keychain dump
  • Check NSUserDefaults/plist files: find /var/mobile/Containers/Data/Application/ -name "*.plist" -exec plutil -p {} \;
  • Inspect SQLite databases and Core Data stores for unencrypted sensitive data
  • Check for data leaking through screenshots (iOS captures screenshots during app backgrounding)
  • Verify data protection class: sensitive files should use NSFileProtectionComplete
Step 4: Authentication and Session Management

Test mobile-specific authentication controls:

  • Biometric bypass: Test if biometric authentication can be bypassed by hooking the authentication callback with Frida to always return success
  • Token storage: Verify that authentication tokens are stored in the Keychain (iOS) or Android Keystore, not in SharedPreferences or files
  • Session timeout: Verify that sessions expire after a reasonable idle timeout and that tokens are invalidated server-side on logout
  • Root/jailbreak detection bypass: Test if the app detects rooted/jailbroken devices and if the detection can be bypassed with Frida or Magisk Hide
  • Deep link abuse: Test if custom URL schemes or universal links can be used to bypass authentication or access restricted functionality
Show full SKILL.md (557 more words)Show less
Step 5: Runtime Manipulation

Test the application's resistance to runtime attacks:

  • Frida hooking: Use Frida to hook and modify application functions at runtime:
    • Bypass root detection: hook the detection function to return false
    • Modify return values of authentication checks
    • Intercept encryption functions to capture plaintext data before encryption
    • Bypass certificate pinning by hooking SSL verification
  • Method swizzling (iOS): Use Frida to replace Objective-C method implementations
  • Intent manipulation (Android): Send crafted intents to exported components: adb shell am start -n com.target.app/.InternalActivity -e "user_id" "admin"
  • Tampering detection: Modify the APK/IPA (add code, change resources), re-sign, and install. Verify whether the app detects tampering.

Key Concepts

TermDefinition
OWASP MASTGMobile Application Security Testing Guide; comprehensive manual for mobile app security testing covering both iOS and Android platforms
Certificate PinningA mobile security control that restricts which TLS certificates the app trusts, preventing man-in-the-middle attacks through proxy interception
FridaDynamic instrumentation toolkit that allows injection of JavaScript into running processes to hook functions, modify behavior, and bypass security controls
Root/Jailbreak DetectionApplication-level checks to detect if the device has been modified to grant root access, typically blocking app usage on compromised devices
Android KeystoreHardware-backed credential storage on Android that protects cryptographic keys and secrets from extraction even on rooted devices
App Transport Security (ATS)iOS security feature that enforces HTTPS connections by default; ATS exceptions may indicate insecure network communication
Deep LinksURL schemes that open specific screens within a mobile application, which may bypass normal navigation and authentication flows if not properly validated

Tools & Systems

  • Frida / Objection: Dynamic instrumentation tools for hooking functions, bypassing security controls, and manipulating application behavior at runtime
  • MobSF (Mobile Security Framework): Automated static and dynamic analysis platform for Android and iOS applications
  • jadx: Android decompiler that converts APK bytecode to readable Java source code for manual code review
  • Burp Suite Professional: HTTP proxy for intercepting and modifying mobile app API traffic after bypassing certificate pinning

Common Scenarios

Scenario: Mobile Banking Application Security Assessment

Context: A bank is launching a new mobile banking app for iOS and Android. The app handles account viewing, fund transfers, bill payment, and check deposit. OWASP MASVS L2 compliance is required due to the financial data handled.

Approach:

  1. Static analysis of the Android APK reveals API endpoints, a hardcoded staging server URL, and an AWS API key in a configuration file
  2. Certificate pinning is implemented but bypassed with Frida SSL pinning bypass script
  3. API traffic analysis reveals that the balance check endpoint returns all account numbers associated with the user, not just the requested account
  4. Local data storage analysis finds that the app caches the last 10 transactions in an unencrypted SQLite database
  5. Biometric authentication bypass: Frida hook on the biometric callback always returns success, granting access without fingerprint
  6. Root detection is present but bypassed with Magisk Hide module, allowing the app to run on a rooted device with full data access

Pitfalls:

  • Testing only on an emulator and missing hardware-specific security features (Android Keystore hardware backing, iOS Secure Enclave)
  • Not testing both iOS and Android versions, as they may have different implementations and different vulnerabilities
  • Ignoring the backend API security because it was "tested separately" when the mobile app may call API endpoints differently than the web app
  • Failing to test certificate pinning bypass, resulting in an incomplete network analysis

Output Format

## Finding: Biometric Authentication Bypass via Frida Instrumentation

**ID**: MOB-003
**Severity**: High (CVSS 7.7)
**Platform**: Android and iOS
**OWASP MASVS**: MASVS-AUTH-2 (Biometric Authentication)

**Description**:
The mobile banking app's biometric authentication can be bypassed using Frida
dynamic instrumentation. The authentication callback function accepts a boolean
result from the biometric API, which can be hooked and forced to return true
without presenting a valid fingerprint or face scan.

**Proof of Concept (Android)**:
frida -U -f com.bank.mobileapp -l bypass-biometric.js --no-pause

// bypass-biometric.js
Java.perform(function() {
  var BiometricCallback = Java.use("com.bank.mobileapp.auth.BiometricCallback");
  BiometricCallback.onAuthenticationSucceeded.implementation = function(result) {
    console.log("[*] Biometric bypassed");
    this.onAuthenticationSucceeded(result);
  };
});

**Impact**:
An attacker with physical access to an unlocked device can bypass biometric
authentication and access the victim's bank accounts, initiate transfers,
and view financial data without biometric verification.

**Remediation**:
1. Implement server-side biometric verification using Android BiometricPrompt
   CryptoObject tied to a Keystore key
2. Require the biometric operation to decrypt a server-side challenge, making
   client-side bypass ineffective
3. Add runtime integrity checks to detect Frida and other instrumentation frameworks
4. Implement step-up authentication for high-risk operations (transfers > threshold)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/conducting-mobile-app-penetration-test of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Conducting Mobile App Penetration Test next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Conducting Mobile App Penetration Test compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Conducting Mobile App Penetration Test this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Android APK Pentesterptn1411/skill219—~917Automated safety check: PassNone
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Offensive MobileSnailSploit/Claude-Red7.4k—~3.5kAutomated safety check: PassMIT
Mobile Securitytransilienceai/communitytools563—~2.5kAutomated safety check: PassMIT
Testing Mobile Applicationstrilwu/secskills157—~2.8kAutomated safety check: PassMIT

Similar skills

  • Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

    219 GitHub stars~917 tokensUpdated 19 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.4k GitHub stars~3.5k tokensUpdated 21 days ago
    SecurityAuto-check passed
  • Mobile Security

    transilienceai/communitytools

    Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

    563 GitHub stars~2.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

    157 GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    158 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Conducting Mobile App Penetration Test

What does Conducting Mobile App Penetration Test do?

Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…. Conducting Mobile App Penetration Test is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls.

When should I use Conducting Mobile App Penetration Test?

Conducting Mobile App Penetration Test fits situations like: tasks that involve Mobile application security; tasks that involve Penetration testing; tasks that involve Static analysis and SAST.

How do I install Conducting Mobile App Penetration Test in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-mobile-app-penetration-test -a claude-code`. Or copy the skill folder (skills/conducting-mobile-app-penetration-test in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/conducting-mobile-app-penetration-test in your project. Claude Code loads it when a task matches its description.

How do I install Conducting Mobile App Penetration Test in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-mobile-app-penetration-test -a codex`. Or copy the skill folder (skills/conducting-mobile-app-penetration-test in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/conducting-mobile-app-penetration-test in your project. Codex loads it when a task matches its description.

Can I use Conducting Mobile App Penetration Test in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-mobile-app-penetration-test -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/conducting-mobile-app-penetration-test, .gemini/skills/conducting-mobile-app-penetration-test, .github/skills/conducting-mobile-app-penetration-test and .opencode/skills/conducting-mobile-app-penetration-test in your project.

What does Conducting Mobile App Penetration Test need to run?

Going by SKILL.md and its folder, Conducting Mobile App Penetration Test needs Python for the scripts in its folder and the command-line tools its instructions call (python, sqlite3 and adb). Our summary lists: Python 3.

Does Conducting Mobile App Penetration Test access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Conducting Mobile App Penetration Test safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Conducting Mobile App Penetration Test use?

Conducting Mobile App Penetration Test is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Conducting Mobile App Penetration Test use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 538 tokens, read only when the agent opens those files.

What are the alternatives to Conducting Mobile App Penetration Test?

Skills that share tags, products or a category with Conducting Mobile App Penetration Test: Android APK Pentester (ptn1411/skill, 219 stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Offensive Mobile (SnailSploit/Claude-Red, 7.4k stars) and Mobile Security (transilienceai/communitytools, 563 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Conducting Mobile App Penetration Test?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.