Agent skill

Svc Mobile Android

by s0ld13rr in s0ld13rr/pentestcode

Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

MITAuto-check passedSecurity

Install Svc Mobile Android

skills CLI
$ npx skills add s0ld13rr/pentestcode --skill svc-mobile-android -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install s0ld13rr/pentestcode svc-mobile-android --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/s0ld13rr/pentestcode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/services/mobile-android .claude/skills/svc-mobile-android && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
svc-mobile-android
GitHub stars
827
Token cost
~2.9k tokens
SKILL.md length
867 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

  • Works in 8 steps: API Security Audit — read ALL… → Transport Security —… → Auth Flow Analysis — full auth chain,… → …
  • Target is an APK/Android app
  • SKILL.md covers Task Decomposition — MANDATORY, How to Read Decompiled Code, Checklist: OWASP Mobile Top 10 and Build Artifact Forensics, plus 4 more sections
  • Needs API_KEY

What it does

Svc Mobile Android is an agent skill from s0ld13rr/pentestcode. Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis. Use when target is an APK/Android app. Triggers - APK, Android, mobile app, decompiled, smali, jadx, apktool.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST, Authentication and Web application vulnerabilities. It works with Android. The repository describes itself as: PentestCode - Multi-agent AI penetration testing system with persistent engagement state, strategic coordination, and parallel autonomous operations. The licence is MIT.

When your agent uses it

  • Target is an APK/Android app
  • Tasks that involve Static analysis and SAST
  • Tasks that involve Authentication

Example prompts

  • “/svc-mobile-android”

Requirements

  • A credential in API_KEY

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. API Security Audit — read ALL Retrofit/API interface files, find sensitive data in URLs
  2. Transport Security — network_security_config, certificate pinning, cleartext
  3. Auth Flow Analysis — full auth chain, session management, token handling
  4. Component Security — exported activities/receivers/providers/services, intent filters, deep links
  5. Build Hygiene — debug flags, dev tools in production, staging endpoints, logging
  6. Secrets & Crypto — hardcoded keys (but FILTER non-issues — see Known Non-Vulns below)
  7. Data Storage — SharedPreferences, Room/SQLite, file storage, backup flags
  8. Root/Tamper Detection — what's present AND what's MISSING

What it can do on your machine

Read from SKILL.md and the folder at commit 6053679. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash, smali and java).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Svc Mobile Android loads about 2.9k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 867 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from s0ld13rr/pentestcode at commit 6053679, republished under its MIT licence (© s0ld13rr). 867 words, ~2,883 tokens.

Download SKILL.mdSave it as .claude/skills/svc-mobile-android/SKILL.md (or your agent's skills folder).
name
svc-mobile-android
description
Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis. Use when target is an APK/Android app. Triggers - APK, Android, mobile app, decompiled, smali, jadx, apktool.

Android APK Static Analysis — Full Methodology

Load this skill when the target is an Android APK (decompiled or not). This covers SAST — for dynamic testing (Frida, MITM), combine with playbook-webapp.

Task Decomposition — MANDATORY

An APK audit is NOT one grep job. Decompose into these independent tasks (run in parallel):

  1. API Security Audit — read ALL Retrofit/API interface files, find sensitive data in URLs
  2. Transport Security — network_security_config, certificate pinning, cleartext
  3. Auth Flow Analysis — full auth chain, session management, token handling
  4. Component Security — exported activities/receivers/providers/services, intent filters, deep links
  5. Build Hygiene — debug flags, dev tools in production, staging endpoints, logging
  6. Secrets & Crypto — hardcoded keys (but FILTER non-issues — see Known Non-Vulns below)
  7. Data Storage — SharedPreferences, Room/SQLite, file storage, backup flags
  8. Root/Tamper Detection — what's present AND what's MISSING

How to Read Decompiled Code

Smali basics (you'll see this from apktool/baksmali)
.method public someMethod(Ljava/lang/String;)V   # method signature
invoke-virtual {v0}, Lcom/example/Foo;->bar()V    # method call
const-string v1, "hardcoded_value"                # string constant
sget-object v0, Lcom/example/Config;->API_KEY:Ljava/lang/String;  # static field
Retrofit annotations in smali (THE most important pattern)
smali
# @GET("endpoint") — HTTP method + path
.annotation runtime Lretrofit2/http/GET;
    value = "auth/password"
.end annotation

# @Query("password") — parameter goes in URL query string!
.annotation runtime Lretrofit2/http/Query;
    value = "password"
.end annotation

# @QueryMap — ALL params go in URL query string!
.annotation runtime Lretrofit2/http/QueryMap;
.end annotation

# @Body — parameter goes in request body (SAFE)
.annotation runtime Lretrofit2/http/Body;
.end annotation

# @Field — parameter goes in form body (SAFE)
.annotation runtime Lretrofit2/http/Field;
    value = "password"
.end annotation

# @Header — parameter sent as HTTP header
.annotation runtime Lretrofit2/http/Header;
    value = "Authorization"
.end annotation

CRITICAL CHECK: Any @Query/@QueryMap on a POST/PUT that carries sensitive data (password, PIN, OTP, token) = CRITICAL finding. Sensitive data in URL is logged everywhere (server access logs, proxies, CDNs, browser history, HTTP interceptors).

Jadx output (Java-like, easier to read)
java
@POST("auth/password")
Call<AuthResponse> login(@QueryMap Map<String, String> params);
// ^ This means login credentials go in URL query string = CRITICAL

Checklist: OWASP Mobile Top 10

M1: Improper Platform Usage
  • Exported components without permission protection
  • Deep links with sensitive actions (password reset, transfers)
  • Content providers with grant-uri-permissions or no read/write permission
  • Intent filters on activities that handle sensitive data
  • android:debuggable="true" in manifest
  • android:allowBackup="true" (data extractable via ADB)
  • android:usesCleartextTraffic="true"
bash
grep -r 'exported="true"' resources/AndroidManifest.xml
grep -r 'android:debuggable' resources/AndroidManifest.xml
grep -r 'allowBackup' resources/AndroidManifest.xml
M2: Insecure Data Storage
  • Sensitive data in SharedPreferences (tokens, passwords, PII)
  • Unencrypted SQLite/Room databases with sensitive data
  • Sensitive data in external storage
  • Logging of sensitive data (Log.d/Log.i with tokens/credentials)
bash
# SharedPreferences usage
grep -rn "SharedPreferences\|getSharedPreferences\|PreferenceManager" sources/
# Logging sensitive data
grep -rn "Log\.\(d\|i\|v\|w\|e\)" sources/ | grep -i "token\|password\|secret\|key\|auth"
# External storage
grep -rn "getExternalStorage\|EXTERNAL_STORAGE\|Environment.getExternalStorageDirectory" sources/
M3: Insecure Communication
  • Certificate pinning — check network_security_config.xml for <pin-set> elements
  • Cleartext traffic — cleartextTrafficPermitted should be false
  • Custom TrustManager — accepting all certs (X509TrustManager with empty checkServerTrusted)
  • HostnameVerifier — custom verifier that always returns true
  • WebView — setMixedContentMode(MIXED_CONTENT_ALWAYS_ALLOW)
bash
# Certificate pinning
grep -r "pin-set\|CertificatePinner\|sha256/" resources/ sources/
# Trust all certs
grep -rn "X509TrustManager\|checkServerTrusted\|TrustAllCerts\|ALLOW_ALL" sources/
# Hostname verifier bypass
grep -rn "HostnameVerifier\|ALLOW_ALL_HOSTNAME_VERIFIER\|verify.*return true" sources/
M4: Insecure Authentication
  • Auth credentials in URL query params (@Query/@QueryMap on auth endpoints)
  • Biometric auth without server-side validation (local-only bypass)
  • Hardcoded credentials (admin/password patterns in code)
  • Token storage (where is the auth token kept? SharedPrefs? Encrypted?)
  • Session timeout — is there an expiry? Auto-logout?
  • PIN/pattern stored locally (hash vs plaintext)
bash
# Find all API interface files (Retrofit)
find sources/ -name "*Api*" -o -name "*Service*" -o -name "*Endpoint*" | grep -i "\.java$\|\.smali$"
# Query params on auth
grep -A5 "@Query\|@QueryMap" sources/ | grep -B2 -i "password\|pin\|otp\|sms\|token\|secret"
M5: Insufficient Cryptography
  • Hardcoded encryption keys/IVs
  • ECB mode (patterns leak through encryption)
  • MD5/SHA1 for security-critical operations
  • Custom crypto implementations
  • Weak key derivation (no PBKDF2/bcrypt/scrypt)
bash
grep -rn "AES/ECB\|DES\|RC4\|Cipher.getInstance" sources/
grep -rn "MessageDigest.getInstance.*MD5\|MessageDigest.getInstance.*SHA-1" sources/
grep -rn "SecretKeySpec\|IvParameterSpec" sources/ | grep -i "hardcoded\|static\|final"
M6: Insecure Authorization
  • Client-side authorization checks only (role checks in app, not server)
  • IDOR — predictable/sequential IDs in API calls (transfer confirm by ID)
  • Missing server-side validation on state transitions
bash
# Find operations that use simple IDs
grep -rn '@Query("id")\|@Path("id")' sources/
M7: Client Code Quality
  • Debug code in production (WebView debugging, Chucker, Stetho, LeakCanary, Flipper)
  • Development/staging endpoints in production code
  • Verbose error messages exposing internal details
  • Test accounts or bypass codes
bash
# Debug tools in production
grep -rn "setWebContentsDebuggingEnabled\|ChuckerInterceptor\|Stetho\|LeakCanary\|Flipper" sources/
# Dev/staging URLs
grep -rn "staging\|\.dev/\|localhost\|10\.0\.\|192\.168\.\|debug" sources/ resources/
M8: Code Tampering
  • Root/jailbreak detection (RootBeer, custom checks for su, Superuser.apk)
  • Frida/Xposed detection
  • Emulator detection (how robust? Package name checks only = weak)
  • Integrity verification (SafetyNet/Play Integrity, PairIP)
  • Debugger detection (anti-debug techniques)
bash
# Root detection
grep -rn "RootBeer\|isRooted\|/system/app/Superuser\|/system/xbin/su\|test-keys" sources/
# Frida detection
grep -rn "frida\|xposed\|substrate\|Magisk" sources/
# Emulator detection
grep -rn "generic\|goldfish\|sdk_gphone\|emulator\|genymotion\|bluestacks" sources/
M9: Reverse Engineering
  • Obfuscation level (ProGuard/R8/DexGuard)
  • Native code protection (if any)
  • String encryption
M10: Extraneous Functionality
  • Admin/debug endpoints accessible from client
  • Hidden features triggered by config flags
  • Logging/analytics sending sensitive data

Build Artifact Forensics

Dagger/Hilt DI Graph

Read the DI component files to find what's wired into the app:

bash
# Find DI modules
find sources/ -name "*Module*" -o -name "*Component*" | grep -i "dagger\|hilt\|di\|inject"
# Look for interceptors in OkHttp chain
grep -rn "Interceptor\|addInterceptor\|addNetworkInterceptor" sources/

Chucker/Stetho/Flipper interceptors in the OkHttp chain = HIGH (logs all HTTP traffic).

Show full SKILL.md (344 more words)Show less
Network Configuration Analysis
bash
# Full network security config
cat resources/res/xml/network_security_config.xml
# Check for domain-config entries (dev/staging domains?)
grep -r "domain-config\|includeSubdomains\|cleartextTrafficPermitted" resources/
Permission Audit

Map each permission to its justification. Flag excessive:

  • READ_CONTACTS / READ_CALL_LOG — legitimate for banking?
  • QUERY_ALL_PACKAGES — anti-emulator, but privacy concern
  • RECORD_AUDIO — voice banking or unnecessary?
  • ACCESS_FINE_LOCATION — branch locator or tracking?

API Surface Mapping — MANDATORY for Banking Apps

Read ALL Retrofit API interface files and build a complete endpoint map:

bash
# Find all API interfaces
find sources/ -name "*Api*" | grep -v "test\|mock\|fake"
# Extract HTTP methods and paths
grep -rn "@GET\|@POST\|@PUT\|@PATCH\|@DELETE\|@HTTP" sources/

For each endpoint, note:

  • HTTP method + path
  • How params are passed (@Query = URL, @Body = body, @Field = form)
  • Auth mechanism (header token? cookie?)
  • Sensitive data exposure

Endpoints to focus on: auth, transfers, payments, password management, profile changes.

Known Non-Vulnerabilities (FALSE POSITIVES — do NOT report as findings)

These are NOT findings — downgrade to INFO or skip:

  • Firebase/Google API keys in resources — required client-side, public by design
  • Google Maps API key — public, restricted by package name
  • reCAPTCHA site key — public by design (appears in HTML on every reCAPTCHA page)
  • GCM/FCM sender ID, OneSignal app ID — public identifiers
  • RSA/EC public keys for pinning/license/JWT verification — public by definition
  • Package name, version code, build config — not secrets
  • Obfuscated class names — obfuscation is defense, not a vuln

These BECOME findings only when:

  • API key grants server-side write access (Firebase Storage write, Firestore admin) — TEST IT
  • OneSignal REST API is unprotected (attempt notification send)
  • Firebase DB/Storage has open rules (check /.json and storage URL)

Impact Chaining — Connect Findings

After individual checks, chain findings for combined impact:

  • No pinning + sensitive data in URL = MITM intercepts passwords in plaintext
  • Chucker + passwords in URL = passwords logged in app's local DB
  • No root detection + local token storage = trivial token extraction on rooted device
  • Exported activity + deep link = intent hijacking to sensitive screens
  • IDOR + valid session = unauthorized access to other users' data

Recording Findings

For each finding, call state_update add_vuln with:

  • severity: use the chained impact, not individual
  • evidence: exact file:line or smali path + the relevant code/annotation
  • status: "confirmed" for code-level findings (they're deterministic, no FP risk)
  • description: what it is + WHY it matters + what an attacker can do

For absence findings (no pinning, no root detection): still record as vuln — the absence IS the finding. Evidence = "searched for X in all sources/resources, not found."

© s0ld13rr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/services/mobile-android of s0ld13rr/pentestcode.

Open the folder on GitHubat commit 6053679

Compare with similar skills

Svc Mobile Android next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Svc Mobile Android compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Svc Mobile Android this skills0ld13rr/pentestcode827—~2.9kAutomated safety check: PassMIT
Performing Android App Static Analysis With Mobsfmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Conducting Mobile App Penetration Testmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Performing Dynamic Analysis Of Android Appmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.0
Android Static AnalyzerLeoYeAI/openclaw-master-skills2.2k—~2.7kAutomated safety check: PassMIT
Clerk Androidgeekskai/blog1031 repos~2.1kAutomated safety check: PassMIT

Similar skills

  • Performing Android App Static Analysis With Mobsf

    mukul975/Anthropic-Cybersecurity-Skills

    Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Conducting Mobile App Penetration Test

    mukul975/Anthropic-Cybersecurity-Skills

    Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Dynamic Analysis Of Android App

    mukul975/Anthropic-Cybersecurity-Skills

    Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Android Static Analyzer

    LeoYeAI/openclaw-master-skills

    分析 Android 项目源码,用 LLM 从多维度生成 AI 自动化测试所需的先验知识文档,打包上报测试平台。核心价值:让 AI 测试 Agent 在运行前就知道「测什么、怎么断言、有哪些陷阱」。触发词:「分析我的 Android 项目」「生成测试画像」「理解这个 App 的业务」「提取测试先验知识」「帮我分析 Android 源码」

    2.2k GitHub stars~2.7k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Clerk Android

    geekskai/blog

    Implement Clerk authentication for native Android apps using Kotlin and Jetpack Compose with clerk-android source-guided patterns.

    103 GitHub starsUsed in 1 repo~2.1k tokens
    MobileAuto-check passed
  • Integration Privy

    aiskillstore/marketplace

    Add Privy authentication to a Solana Expo Android app on top of Mobile Wallet Adapter, using Sign-In-With-Solana.

    430 GitHub stars~2.6k tokensUpdated yesterday
    MobileAuto-check passed

More from s0ld13rr/pentestcode

All 9 skills in this repo
  • Svc Docker K8s

    s0ld13rr/pentestcode

    Docker/Kubernetes attack techniques — exposed API abuse, container escape, RBAC/privileged-pod issues, secret theft.

    827 GitHub stars~648 tokensUpdated 6 days ago
    Auto-check passed
  • Web Lfi Traversal

    s0ld13rr/pentestcode

    Path traversal / Local File Inclusion detection→file-read→RCE for web apps.

    827 GitHub stars~602 tokensUpdated 6 days ago
    Auto-check: notes
  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    827 GitHub stars~710 tokensUpdated 6 days ago
    Auto-check passed
  • Web Ssti

    s0ld13rr/pentestcode

    Server-Side Template Injection detection→engine-fingerprint→RCE for web apps.

    827 GitHub stars~621 tokensUpdated 6 days ago
    Auto-check passed
  • Web Xxe

    s0ld13rr/pentestcode

    XML External Entity injection detection→file-read/SSRF→proof for web apps.

    827 GitHub stars~585 tokensUpdated 6 days ago
    Auto-check passed
  • Svc Database

    s0ld13rr/pentestcode

    Database RCE paths — UDF, xpcmdshell, COPY TO PROGRAM, Redis key write.

    827 GitHub stars~379 tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Svc Mobile Android

What does Svc Mobile Android do?

Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis. Svc Mobile Android is an agent skill from s0ld13rr/pentestcode. Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

When should I use Svc Mobile Android?

Svc Mobile Android fits situations like: target is an APK/Android app; tasks that involve Static analysis and SAST; tasks that involve Authentication.

How do I install Svc Mobile Android in Claude Code?

Run `npx skills add s0ld13rr/pentestcode --skill svc-mobile-android -a claude-code`. Or copy the skill folder (skills/services/mobile-android in s0ld13rr/pentestcode) into .claude/skills/svc-mobile-android in your project. Claude Code loads it when a task matches its description.

How do I install Svc Mobile Android in Codex?

Run `npx skills add s0ld13rr/pentestcode --skill svc-mobile-android -a codex`. Or copy the skill folder (skills/services/mobile-android in s0ld13rr/pentestcode) into .agents/skills/svc-mobile-android in your project. Codex loads it when a task matches its description.

Can I use Svc Mobile Android in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add s0ld13rr/pentestcode --skill svc-mobile-android -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/svc-mobile-android, .gemini/skills/svc-mobile-android, .github/skills/svc-mobile-android and .opencode/skills/svc-mobile-android in your project.

What does Svc Mobile Android need to run?

Going by SKILL.md and its folder, Svc Mobile Android needs credentials named API_KEY. Our summary lists: A credential in API_KEY.

Does Svc Mobile Android access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Svc Mobile Android safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Svc Mobile Android use?

Svc Mobile Android is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Svc Mobile Android use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Svc Mobile Android?

Skills that share tags, products or a category with Svc Mobile Android: Performing Android App Static Analysis With Mobsf (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Conducting Mobile App Penetration Test (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Dynamic Analysis Of Android App (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Android Static Analyzer (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Svc Mobile Android?

s0ld13rr (a GitHub user) maintains it in s0ld13rr/pentestcode, which has 827 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 2, 2026.

Source: s0ld13rr/pentestcode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.