Agent skill

Mobile Code Review

by OWASP in OWASP/secure-agent-playbook

Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0.

CC-BY-4.0Auto-check passedSecurity

Install Mobile Code Review

skills CLI
$ npx skills add OWASP/secure-agent-playbook --skill mobile-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OWASP/secure-agent-playbook mobile-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/code-security-skills/skills/mobile-code-review .claude/skills/mobile-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mobile-code-review
GitHub stars
187
Token cost
~622 tokens
SKILL.md length
262 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0.

  • Works in 5 steps: Scope & Context — Language… → Platform Detection — Fingerprint Android… → Systematic Review by MASVS Group — For… → …
  • Reviewing mobile codebases
  • SKILL.md covers Steps, Output and OWASP References
  • Reaches github.com and mas.owasp.org

What it does

Mobile Code Review is an agent skill from OWASP/secure-agent-playbook. Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0. Use when reviewing mobile codebases, mobile PR diffs, or auditing a mobile module.

Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities and Code review. It works with Android and iOS. The repository describes itself as: OWASP Secure Agent Playbook Project. The licence is CC-BY-4.0.

When your agent uses it

  • Reviewing mobile codebases
  • Mobile PR diffs
  • Auditing a mobile module

Example prompts

  • “/mobile-code-review”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Scope & Context — Language (Java/Kotlin/Swift/Obj-C/Dart), platform, app type, sensitive data, exposure.
  2. Platform Detection — Fingerprint Android (AndroidManifest.xml, build.gradle) and/or iOS (Info.plist, *.xcodeproj). If only a…
  3. Systematic Review by MASVS Group — For each of the 8 MASVS groups (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) in…
  4. Diff-Specific Analysis (for PRs) — Focus on changed lines; verify pinning, permissions, and KeyStore/Keychain usage are not weakened.
  5. Produce Findings — Use templates/finding.md. Sort by severity (CRITICAL > HIGH > MEDIUM > LOW > INFO). Deduplicate cross-group findings…

What it can do on your machine

Read from SKILL.md and the folder at commit 1b5fd4c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • mas.owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mobile Code Review loads about 622 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~622

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OWASP/secure-agent-playbook at commit 1b5fd4c, republished under its CC-BY-4.0 licence (© OWASP). 262 words, ~622 tokens.

Download SKILL.mdSave it as .claude/skills/mobile-code-review/SKILL.md (or your agent's skills folder).
name
mobile-code-review
description
Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0. Use when reviewing mobile codebases, mobile PR diffs, or auditing a mobile module.
license
CC-BY-4.0

Mobile Security Code Review

Review native Android and iOS source code for security vulnerabilities by following the full procedure in plays/mobile-code-review.md.

Steps

  1. Scope & Context — Language (Java/Kotlin/Swift/Obj-C/Dart), platform, app type, sensitive data, exposure.
  2. Platform Detection — Fingerprint Android (AndroidManifest.xml, build.gradle) and/or iOS (Info.plist, *.xcodeproj). If only a cross-platform shell is detected, declare partial coverage.
  3. Systematic Review by MASVS Group — For each of the 8 MASVS groups (STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, RESILIENCE, PRIVACY) in priority order:
    • Load data/masvs/MASVS-<GROUP>-<N>.md for the control statement and the mastg_tests: list.
    • For each MASTG test ID, load data/mastg/MASTG-TEST-####.md and apply its Static Analysis content (V1) or Steps/Observation/Evaluation (V2) to the source tree.
    • Note V1-fallback tests in findings using the file's status_note.
  4. Diff-Specific Analysis (for PRs) — Focus on changed lines; verify pinning, permissions, and KeyStore/Keychain usage are not weakened.
  5. Produce Findings — Use templates/finding.md. Sort by severity (CRITICAL > HIGH > MEDIUM > LOW > INFO). Deduplicate cross-group findings (cite the most specific MASVS control in OWASP Ref).

Output

Scope summary (platform, languages), upstream-pointer note for MASTG IDs (https://github.com/OWASP/mastg, https://mas.owasp.org/MASTG/), findings sorted by severity using templates/finding.md (each finding carries an optional MASTG references: bullet listing any non-TEST @MASTG-<KIND>-#### cross-refs cited in the informing tests, grouped by KIND alphabetically, IDs sorted numerically, omitted when empty), positive observations, severity count table, RESILIENCE static-only notice block, PRIVACY runtime-required caveat for findings against PRIVACY-2/PRIVACY-3, dynamic-test follow-up list (collected from data/mastg/ entries with type: [dynamic] that informed findings).

OWASP References

  • OWASP MASVS v2.1.0
  • OWASP MASTG (forward cross-references)
  • OWASP MAS Checklist
  • OWASP ASVS v5.0 (overlap items only)
  • CWE-312, CWE-327, CWE-295, CWE-926, CWE-749, others per finding

© OWASP, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/code-security-skills/skills/mobile-code-review of OWASP/secure-agent-playbook.

Open the folder on GitHubat commit 1b5fd4c

Compare with similar skills

Mobile Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mobile Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mobile Code Review this skillOWASP/secure-agent-playbook187—~622Automated safety check: PassCC-BY-4.0
Exploiting Insecure Data Storage In Mobilemukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Conducting Mobile App Penetration Testmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Mobile Securitytransilienceai/communitytools562—~2.5kAutomated safety check: PassMIT
Grix Code Reviewaskie/grix153—~799Automated safety check: PassCustom licence

Similar skills

  • Exploiting Insecure Data Storage In Mobile

    mukul975/Anthropic-Cybersecurity-Skills

    Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Conducting Mobile App Penetration Test

    mukul975/Anthropic-Cybersecurity-Skills

    Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Mobile Security

    transilienceai/communitytools

    Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

    562 GitHub stars~2.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Audit Grix diffs and pull requests for correctness, regressions, security, lifecycle safety, and cross-component contract consistency.

    153 GitHub stars~799 tokensUpdated today
    DevelopmentAuto-check passed
  • Suede Code Review

    JasonColapietro/suede-creator-skills

    Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface.

    127 GitHub stars~7.1k tokensUpdated today
    DevelopmentAuto-check passed

More from OWASP/secure-agent-playbook

All 14 skills in this repo
  • Prd Securability Enhancement

    OWASP/secure-agent-playbook

    Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.

    187 GitHub stars~4.6k tokensUpdated 12 days ago
    Auto-check passed
  • Securability Engineering Review

    OWASP/secure-agent-playbook

    Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…

    187 GitHub stars~4.6k tokensUpdated 12 days ago
    Auto-check passed
  • Securability Engineering

    OWASP/secure-agent-playbook

    Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…

    187 GitHub stars~5.8k tokensUpdated 12 days ago
    Auto-check passed
  • Agent Security Audit

    OWASP/secure-agent-playbook

    Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

    187 GitHub stars~542 tokensUpdated 12 days ago
    Auto-check passed
  • AI Security Verification

    OWASP/secure-agent-playbook

    Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.

    187 GitHub stars~876 tokensUpdated 12 days ago
    Auto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    187 GitHub stars~744 tokensUpdated 12 days ago
    Auto-check passed

Works with

Questions about Mobile Code Review

What does Mobile Code Review do?

Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0. Mobile Code Review is an agent skill from OWASP/secure-agent-playbook.0.

When should I use Mobile Code Review?

Mobile Code Review fits situations like: reviewing mobile codebases; mobile PR diffs; auditing a mobile module.

How do I install Mobile Code Review in Claude Code?

Run `npx skills add OWASP/secure-agent-playbook --skill mobile-code-review -a claude-code`. Or copy the skill folder (plugins/code-security-skills/skills/mobile-code-review in OWASP/secure-agent-playbook) into .claude/skills/mobile-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Mobile Code Review in Codex?

Run `npx skills add OWASP/secure-agent-playbook --skill mobile-code-review -a codex`. Or copy the skill folder (plugins/code-security-skills/skills/mobile-code-review in OWASP/secure-agent-playbook) into .agents/skills/mobile-code-review in your project. Codex loads it when a task matches its description.

Can I use Mobile Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OWASP/secure-agent-playbook --skill mobile-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mobile-code-review, .gemini/skills/mobile-code-review, .github/skills/mobile-code-review and .opencode/skills/mobile-code-review in your project.

What does Mobile Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Mobile Code Review is instructions for the agent only.

Does Mobile Code Review access the network?

SKILL.md names 2 domains. In commands or code: github.com and mas.owasp.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Mobile Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mobile Code Review use?

Mobile Code Review is published under the CC-BY-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mobile Code Review use?

About 622 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mobile Code Review?

Skills that share tags, products or a category with Mobile Code Review: Exploiting Insecure Data Storage In Mobile (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Conducting Mobile App Penetration Test (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Mobile Security (transilienceai/communitytools, 562 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mobile Code Review?

OWASP (a GitHub organization) maintains it in OWASP/secure-agent-playbook, which has 187 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 25, 2026.

Source: OWASP/secure-agent-playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.