The skill is built for authorized testing of Android apps packaged as a plain APK, an XAPK, or a split bundletool APKS archive. Five scripted phases carry it out: setting up an emulator with adb root and a pushed frida-server; extracting manifest metadata, permissions, DEX strings, native libraries and protection indicators; installing a plain, split or bundletool package; applying lab emulator property changes that must be reapplied after every cold boot since they live only in memory; and injecting a mitmproxy certificate into the system trust store to configure the device's proxy. A references file goes deeper into detection vectors, certificate injection and APK format differences.
A separate script generates Frida scripts for SSL-pinning tests, crypto logging and detection validation, and every run can produce an analysis JSON report, a manifest of the generated hooks, and optional mitmproxy capture output. Practical notes call for a dry run before changing an emulator, bundletool for APKS archives, system-level certificate injection since Android 7 and later usually ignores user-added certificates, and physical devices for targets that rely on hardware-backed attestation.