Agent skill

Exploiting Insecure Data Storage In Mobile

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences…

Apache-2.0Auto-check passedSecurity

Install Exploiting Insecure Data Storage In Mobile

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-insecure-data-storage-in-mobile -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-insecure-data-storage-in-mobile --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploiting-insecure-data-storage-in-mobile .claude/skills/exploiting-insecure-data-storage-in-mobile && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
exploiting-insecure-data-storage-in-mobile
GitHub stars
34k
Token cost
~1.9k tokens
SKILL.md length
438 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences…

  • Works in 6 steps: Map Application Data Storage Locations → Extract and Analyze SharedPreferences… → Analyze SQLite Databases → …
  • Performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage)
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder; calls adb, sqlite3 and java

What it does

Exploiting Insecure Data Storage In Mobile is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirements. Activates for requests involving mobile data storage security, local storage exploitation, SharedPreferences…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Penetration testing and Web application vulnerabilities. It works with Android, iOS and SQLite. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage)
  • Assessing compliance with MASVS-STORAGE requirements

Example prompts

  • “Use the exploiting-insecure-data-storage-in-mobile skill to identify and exploits insecure local data storage vulnerabilities in Android and iOS…”
  • “/exploiting-insecure-data-storage-in-mobile”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Map Application Data Storage Locations
  2. Extract and Analyze SharedPreferences (Android)
  3. Analyze SQLite Databases
  4. Inspect iOS Keychain Storage
  5. Assess External Storage and Backup Exposure
  6. Runtime Memory Analysis

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • adb
    • sqlite3
    • java

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Exploiting Insecure Data Storage In Mobile loads about 1.9k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 438 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 438 words, ~1,933 tokens.

Download SKILL.mdSave it as .claude/skills/exploiting-insecure-data-storage-in-mobile/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
exploiting-insecure-data-storage-in-mobile
description
Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirements. Activates for requests involving mobile data storage security, local storage exploitation, SharedPreferences analysis, or mobile data leakage assessment.
domain
cybersecurity
subdomain
mobile-security
author
mahipal
tags
mobile-security, android, ios, data-storage, owasp-mobile, penetration-testing
version
1.0.0
license
Apache-2.0
atlas_techniques
AML.T0057
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4, GOVERN-1.1, GOVERN-4.2
nist_csf
PR.PS-01, PR.AA-05, ID.RA-01, DE.CM-09
mitre_attack
T1059, T1056, T1036, T1078, T1003

Exploiting Insecure Data Storage in Mobile

When to Use

Use this skill when:

  • Assessing whether mobile applications store sensitive data securely on the device filesystem
  • Testing for credential leakage through SharedPreferences, SQLite databases, or plists
  • Evaluating keychain/keystore implementation for proper access control attributes
  • Performing data-at-rest security assessment during mobile penetration tests

Do not use this skill on production user devices without authorization -- data extraction techniques require physical access or root/jailbreak privileges.

Prerequisites

  • Rooted Android device or emulator with ADB access
  • Jailbroken iOS device with SSH access or Objection-patched IPA
  • ADB (Android Debug Bridge) for Android filesystem access
  • SQLite3 CLI for database inspection
  • Frida/Objection for runtime data extraction
  • Target application installed and exercised (logged in, data cached)

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Workflow

Step 1: Map Application Data Storage Locations

Android storage paths:

bash
# Internal storage (app-private, requires root)
/data/data/<package_name>/
├── shared_prefs/      # SharedPreferences XML files
├── databases/         # SQLite databases
├── files/             # General files
├── cache/             # Cached data
├── lib/               # Native libraries
└── app_webview/       # WebView data

# External storage (world-readable on older Android)
/sdcard/Android/data/<package_name>/

# Check for world-readable files
adb shell run-as <package_name> ls -la /data/data/<package_name>/

iOS storage paths:

bash
# App sandbox (accessible via SSH on jailbroken device)
/var/mobile/Containers/Data/Application/<UUID>/
├── Documents/         # User data, backed up by default
├── Library/
│   ├── Preferences/   # NSUserDefaults plists
│   ├── Caches/        # Cache data
│   └── Application Support/
└── tmp/               # Temporary files
Step 2: Extract and Analyze SharedPreferences (Android)
bash
# Pull SharedPreferences files
adb shell run-as <package_name> cat shared_prefs/*.xml

# Or on rooted device
adb pull /data/data/<package_name>/shared_prefs/ ./shared_prefs/

# Search for sensitive data
grep -ri "password\|token\|secret\|key\|session\|auth\|cookie" shared_prefs/

Common insecure storage patterns:

xml
<!-- Plaintext credentials -->
<string name="user_password">mysecretpass123</string>
<string name="auth_token">eyJhbGciOiJIUzI1NiIs...</string>
<string name="api_key">sk-live-abc123def456</string>

<!-- Sensitive PII -->
<string name="user_ssn">123-45-6789</string>
<string name="credit_card">4111111111111111</string>
Step 3: Analyze SQLite Databases
bash
# Pull databases
adb pull /data/data/<package_name>/databases/ ./databases/

# Open and inspect
sqlite3 databases/app.db
.tables
.schema users
SELECT * FROM users;
SELECT * FROM sessions;
SELECT * FROM tokens;

# Search all tables for sensitive columns
sqlite3 databases/app.db ".dump" | grep -i "password\|token\|secret\|credit"

Check for unencrypted SQLCipher databases:

bash
# If database opens without password, it's unencrypted
sqlite3 databases/app.db "SELECT count(*) FROM sqlite_master;"
# Success = unencrypted (vulnerability)
Step 4: Inspect iOS Keychain Storage
bash
# Using Objection
objection --gadget com.target.app explore
ios keychain dump

# Check protection class attributes
# kSecAttrAccessibleWhenUnlocked - OK for most data
# kSecAttrAccessibleAlways - VULNERABLE: accessible even when locked
# kSecAttrAccessibleAfterFirstUnlock - acceptable for background apps
Step 5: Assess External Storage and Backup Exposure

Android:

bash
# Check if backup is enabled
aapt dump badging target.apk | grep -i "allowBackup"
# android:allowBackup="true" = vulnerability

# Extract backup data
adb backup -f backup.ab -apk <package_name>
java -jar abe.jar unpack backup.ab backup.tar
tar xvf backup.tar
# Inspect extracted data for sensitive information

# Check external storage
adb shell ls -la /sdcard/Android/data/<package_name>/

iOS:

bash
# Check backup exclusion
# Files in Documents/ are backed up by default
# Check NSURLIsExcludedFromBackupKey attribute
objection --gadget com.target.app explore
ios plist cat Info.plist
Step 6: Runtime Memory Analysis
bash
# Dump process memory for sensitive data
objection --gadget com.target.app explore
memory search "password" --string
memory search "BEGIN RSA PRIVATE KEY" --string
memory dump all /tmp/memdump/

# Android: Check for sensitive data in logs
adb logcat -d | grep -i "password\|token\|key\|secret"

Key Concepts

TermDefinition
SharedPreferencesAndroid key-value storage in XML format; often misused for storing credentials in plaintext
Keychain ServicesiOS secure credential storage backed by Secure Enclave hardware on modern devices
Android KeystoreHardware-backed cryptographic key storage on Android; keys cannot be extracted from the device
SQLCipherTransparent encryption extension for SQLite databases; prevents data extraction without password
Data Protection APIiOS file-level encryption tied to device passcode; controlled via protection class attributes
Show full SKILL.md (157 more words)Show less

Tools & Systems

  • ADB (Android Debug Bridge): Command-line tool for Android device interaction and filesystem access
  • Objection: Frida-powered runtime exploration for keychain dumping and memory inspection
  • SQLite3: Command-line interface for inspecting unencrypted SQLite databases
  • Android Backup Extractor (ABE): Tool for unpacking ADB backup files to inspect stored data
  • iExplorer: GUI tool for browsing iOS app sandbox filesystem

Common Pitfalls

  • Encrypted but key in code: Some apps encrypt databases but store the encryption key in SharedPreferences or hardcoded in the binary. Always check for key storage alongside encryption.
  • MODE_WORLD_READABLE deprecation: This flag was deprecated in API 17, but legacy apps may still use it, making SharedPreferences readable by other apps.
  • iOS backup scope: By default, all files in the Documents directory are included in iTunes/iCloud backups. Verify that sensitive files have the backup exclusion attribute set.
  • Clipboard exposure: Data copied to clipboard is accessible to all apps. Check if the app copies sensitive data (passwords, tokens) to the clipboard.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/exploiting-insecure-data-storage-in-mobile of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Exploiting Insecure Data Storage In Mobile next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Exploiting Insecure Data Storage In Mobile compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Exploiting Insecure Data Storage In Mobile this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Web Sqlis0ld13rr/pentestcode828—~710Automated safety check: PassMIT
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Mobile Code ReviewOWASP/secure-agent-playbook188—~622Automated safety check: PassCC-BY-4.0
Mobile Securitytransilienceai/communitytools563—~2.5kAutomated safety check: PassMIT
Testing Mobile Applicationstrilwu/secskills157—~2.8kAutomated safety check: PassMIT

Similar skills

  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    828 GitHub stars~710 tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Mobile Code Review

    OWASP/secure-agent-playbook

    Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0.

    188 GitHub stars~622 tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Mobile Security

    transilienceai/communitytools

    Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

    563 GitHub stars~2.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

    157 GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sqli Testing

    NeoTheCapt/RedteamAgent

    Detect and exploit SQL injection vulnerabilities in web application parameters

    143 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Exploiting Insecure Data Storage In Mobile

What does Exploiting Insecure Data Storage In Mobile do?

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences…. Exploiting Insecure Data Storage In Mobile is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage.

When should I use Exploiting Insecure Data Storage In Mobile?

Exploiting Insecure Data Storage In Mobile fits situations like: performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage); assessing compliance with MASVS-STORAGE requirements.

How do I install Exploiting Insecure Data Storage In Mobile in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-insecure-data-storage-in-mobile -a claude-code`. Or copy the skill folder (skills/exploiting-insecure-data-storage-in-mobile in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/exploiting-insecure-data-storage-in-mobile in your project. Claude Code loads it when a task matches its description.

How do I install Exploiting Insecure Data Storage In Mobile in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-insecure-data-storage-in-mobile -a codex`. Or copy the skill folder (skills/exploiting-insecure-data-storage-in-mobile in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/exploiting-insecure-data-storage-in-mobile in your project. Codex loads it when a task matches its description.

Can I use Exploiting Insecure Data Storage In Mobile in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-insecure-data-storage-in-mobile -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploiting-insecure-data-storage-in-mobile, .gemini/skills/exploiting-insecure-data-storage-in-mobile, .github/skills/exploiting-insecure-data-storage-in-mobile and .opencode/skills/exploiting-insecure-data-storage-in-mobile in your project.

What does Exploiting Insecure Data Storage In Mobile need to run?

Going by SKILL.md and its folder, Exploiting Insecure Data Storage In Mobile needs Python for the scripts in its folder and the command-line tools its instructions call (adb, sqlite3 and java). Our summary lists: Python 3.

Does Exploiting Insecure Data Storage In Mobile access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Exploiting Insecure Data Storage In Mobile safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Exploiting Insecure Data Storage In Mobile use?

Exploiting Insecure Data Storage In Mobile is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Exploiting Insecure Data Storage In Mobile use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Exploiting Insecure Data Storage In Mobile?

Skills that share tags, products or a category with Exploiting Insecure Data Storage In Mobile: Web Sqli (s0ld13rr/pentestcode, 828 stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Mobile Code Review (OWASP/secure-agent-playbook, 188 stars) and Mobile Security (transilienceai/communitytools, 563 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Exploiting Insecure Data Storage In Mobile?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.