Agent skill

Mobile Security Expert

by s7safe in s7safe/android-h1

移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

No licenceAuto-check passedSecurity

Install Mobile Security Expert

skills CLI
$ npx skills add s7safe/android-h1 --skill mobile-security-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install s7safe/android-h1 mobile-security-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mobile-security-expert
GitHub stars
210
Token cost
~631 tokens
SKILL.md length
185 words
Files
5
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

  • Works in 4 steps: 需求识别与场景匹配 → 知识检索 → 分析与指导 → …
  • Tasks that involve Bug bounty
  • SKILL.md covers 任务目标, 操作步骤, 资源索引 and 注意事项, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Mobile Security Expert is an agent skill from s7safe/android-h1. 移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

Its SKILL.md is about 630 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `IOS.md`, `QUICK_REFERENCE.md` and `README.md`).

It sits in Security, covering Bug bounty and Mobile application security. It works with Android and iOS. The repository describes itself as: 移动安全漏洞挖掘专家SKILL,基于 HackerOne 真实报告的移动安全漏洞挖掘知识库,提供 Android 和 iOS 应用的漏洞挖掘手法、技术细节和代码模式分析。

When your agent uses it

  • Tasks that involve Bug bounty
  • Tasks that involve Mobile application security

Example prompts

  • “/mobile-security-expert”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 需求识别与场景匹配
  2. 知识检索
  3. 分析与指导
  4. 输出组织

What it can do on your machine

Read from SKILL.md and the folder at commit 62eb790. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mobile Security Expert loads about 631 tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 185 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~631

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 185 words (~631 tokens).

name
mobile-security-expert

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files in the repository root of s7safe/android-h1.

  • SKILL.md
  • IOS.md
  • QUICK_REFERENCE.md
  • README.md
  • android.md

Open the folder on GitHubat commit 62eb790

Compare with similar skills

Mobile Security Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mobile Security Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mobile Security Expert this skills7safe/android-h1210—~631Automated safety check: PassNone
Offensive MobileSnailSploit/Claude-Red7.3k—~3.5kAutomated safety check: PassMIT
Frida Mobile Securityindex-login/MobileRE-Skill123—~3kAutomated safety check: PassMIT
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
R0crawl Skillsmanyuegong33/r0crawl_skills306—~1.2kAutomated safety check: PassNone
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.3k GitHub stars~3.5k tokensUpdated 18 days ago
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    123 GitHub stars~3k tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 3 days ago
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    306 GitHub stars~1.2k tokensUpdated 18 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Conducting Mobile App Penetration Test

    mukul975/Anthropic-Cybersecurity-Skills

    Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

Works with

Categories

Questions about Mobile Security Expert

What does Mobile Security Expert do?

移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。. Mobile Security Expert is an agent skill from s7safe/android-h1.

When should I use Mobile Security Expert?

Mobile Security Expert fits situations like: tasks that involve Bug bounty; tasks that involve Mobile application security.

How do I install Mobile Security Expert in Claude Code?

Run `npx skills add s7safe/android-h1 --skill mobile-security-expert -a claude-code`. Or copy the skill folder (the s7safe/android-h1 repository) into .claude/skills/mobile-security-expert in your project. Claude Code loads it when a task matches its description.

How do I install Mobile Security Expert in Codex?

Run `npx skills add s7safe/android-h1 --skill mobile-security-expert -a codex`. Or copy the skill folder (the s7safe/android-h1 repository) into .agents/skills/mobile-security-expert in your project. Codex loads it when a task matches its description.

Can I use Mobile Security Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add s7safe/android-h1 --skill mobile-security-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mobile-security-expert, .gemini/skills/mobile-security-expert, .github/skills/mobile-security-expert and .opencode/skills/mobile-security-expert in your project.

What does Mobile Security Expert need to run?

SKILL.md names no scripts, command-line tools or credentials: Mobile Security Expert is instructions for the agent only.

Does Mobile Security Expert access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mobile Security Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mobile Security Expert use?

No licence was found for Mobile Security Expert or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Mobile Security Expert use?

About 631 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mobile Security Expert?

Skills that share tags, products or a category with Mobile Security Expert: Offensive Mobile (SnailSploit/Claude-Red, 7.3k stars), Frida Mobile Security (index-login/MobileRE-Skill, 123 stars), Mira Risk Collect (vw2x/Mira, 105 stars) and R0crawl Skills (manyuegong33/r0crawl_skills, 306 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mobile Security Expert?

s7safe (a GitHub user) maintains it in s7safe/android-h1, which has 210 GitHub stars. The repository was last updated on April 19, 2026.

Source: s7safe/android-h1 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.