Agent skill

Mobile Security

by transilienceai in transilienceai/communitytools

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

MITAuto-check passedSecurity

Install Mobile Security

skills CLI
$ npx skills add transilienceai/communitytools --skill mobile-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install transilienceai/communitytools mobile-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/transilienceai/communitytools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mobile-security .claude/skills/mobile-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mobile-security
GitHub stars
562
Token cost
~2.5k tokens
SKILL.md length
957 words
Files
11
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

  • Works in 4 steps: Static reverse engineering of compiled… → SAST — manifest / Info.plist,… → Dynamic analysis (DAST) —… → …
  • Tasks that involve Mobile application security
  • SKILL.md covers Scope, Coverage contract, When to use and Methodology, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Mobile Security is an agent skill from transilienceai/communitytools. Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC, storage, crypto, signing), dynamic analysis (Frida/objection, TLS-pinning + root/jailbreak bypass, traffic interception), and privacy testing.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files (for example `reference/android-dynamic-analysis.md`, `reference/android-static-analysis.md` and `reference/flutter-aot-reversing.md`).

It sits in Security, covering Mobile application security, Cross-platform mobile apps and Web application vulnerabilities. It works with Frida, React Native, Android and iOS. The repository describes itself as: Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research. The licence is MIT.

When your agent uses it

  • Tasks that involve Mobile application security
  • Tasks that involve Cross-platform mobile apps
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/mobile-security”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Static reverse engineering of compiled artifacts — Dart AOT snapshots, Unity IL2CPP, React Native/Hermes bytecode, native ARM64…
  2. SAST — manifest / Info.plist, exported-component & IPC surface, WebView, local storage, cryptographic-primitive weakness, code-signing…
  3. Dynamic analysis (DAST) — Frida/objection instrumentation, traffic interception, TLS-pinning bypass across stacks, Keychain/Keystore…
  4. Privacy — data-collection inventory, tracker/SDK enumeration, PII leakage, declared-vs-actual (Play Data Safety / Apple Privacy Manifest).

What it can do on your machine

Read from SKILL.md and the folder at commit 95fdc12. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mobile Security loads about 2.5k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 957 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from transilienceai/communitytools at commit 95fdc12, republished under its MIT licence (© transilienceai). 957 words, ~2,533 tokens.

Download SKILL.mdSave it as .claude/skills/mobile-security/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
mobile-security
description
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC, storage, crypto, signing), dynamic analysis (Frida/objection, TLS-pinning + root/jailbreak bypass, traffic interception), and privacy testing.

Mobile Security

Scope

End-to-end mobile application VAPT for Android (APK/AAB) and iOS (IPA), aligned to the OWASP MASVS v2.x control groups and the MASTG testing process. Four complementary tiers:

  1. Static reverse engineering of compiled artifacts — Dart AOT snapshots, Unity IL2CPP, React Native/Hermes bytecode, native ARM64 .so/Mach-O, smali. Recover secrets, endpoints, and the crypto contract without a device.
  2. SAST — manifest / Info.plist, exported-component & IPC surface, WebView, local storage, cryptographic-primitive weakness, code-signing, and automated baseline (MobSF/apkid/apkleaks) → then manual deep-dive.
  3. Dynamic analysis (DAST) — Frida/objection instrumentation, traffic interception, TLS-pinning bypass across stacks, Keychain/Keystore runtime dumps, IPC probing, and root/jailbreak/anti-tamper defeat for MAS-L2 / MASA scope.
  4. Privacy — data-collection inventory, tracker/SDK enumeration, PII leakage, declared-vs-actual (Play Data Safety / Apple Privacy Manifest).

Static dump first (faster, no device); dynamic is a first-class phase whenever a control can only be proven at runtime (enforced pinning, Keystore-backed keys, root reaction, IPC guards). Cross-asset stitching, scoring, and reporting are owned by sibling skills — this skill produces MASVS/MASTG-tagged findings and hands them off.

Coverage contract

In a coverage-mode engagement (pentest-engagement mobile mode) completion is code-enforced, not narrative. Two surfaces are gated, and both are mandatory:

SurfaceFileClasses
The app bundlerecon/inventory/mobile-surface.jsonthe 15 MAS-* MASVS classes
The backend recovered from the bundle<apex>-api/recon/inventory/surface.jsonthe ordinary OWASP API/web classes

The second row is where the material risk has historically been. A decompiled bundle hands you the full server contract, and that surface is not browser-reachable — so it is systematically under-tested by everyone, including the app's own developers. Recovering the endpoint inventory and driving it through the API classes is not an optional extra; a bundle that yields zero endpoints is treated as a failed acquisition.

Per-class detail: reference/masvs-class-map.md. Two rules worth internalising before you write a negative:

  • proof_mode: runtime cannot be closed statically. Pinning and root detection are the classic traps: static analysis can prove a control is inert (a CertificatePinner built and never attached, a RootBeer that no DEX references) — raise that as a positive. It can never prove the control is effective; that needs a bypass attempt that failed, and a failed bypass is a legitimate, reportable result.
  • proof_mode: static can never be device-deferred. No device does not excuse the manifest, the signature, the bundled dependencies, or the secrets in the artifact.

When to use

  • Target ships an Android APK/AAB or iOS IPA — extract and inspect before any runtime testing.
  • Built with Flutter (lib/arm64-v8a/libapp.so / iOS App.framework), Unity (libil2cpp.so + global-metadata.dat), or React Native + Hermes (libhermes.so + index.android.bundle) — needs a runtime-aware decompiler, not just jadx.
  • Stock Android/iOS app — you need the manifest/IPC/storage/crypto/signing attack surface (SAST) and, where a control is runtime-only, dynamic confirmation.
  • App uses encrypted API envelopes (KEY/IV/SALT/SIGNATURE headers) and you need to reverse the crypto contract, then replay against the live API.
  • TLS pinning / root / jailbreak detection blocks testing — bypass it dynamically (or defeat it statically) and demonstrate the protected flow.
  • You suspect IDOR / mass assignment / business-logic flaws easier to find in the dumped client, then confirmed server-side.
  • You need a MASVS-PRIVACY pass (trackers, over-collection, PII leakage, declared-vs-actual).

Methodology

Start at reference/methodology.md — the phase backbone (ACQUIRE → TRIAGE → STATIC → DYNAMIC → NETWORK → STORAGE → PLATFORM/IPC → BACKEND PIVOT → REPORT), app acquisition + evidence integrity, the MASVS→file coverage map, finding-tagging convention, and the client→API pivot. It routes to every reference below. Do preflight (../coordination/reference/preflight-checklist.md) first.

Show full SKILL.md (416 more words)Show less

References

Cross-cutting

Android

  • reference/android-static-analysis.md — SAST: MobSF/apkid/apkleaks baseline, manifest & exported-component/IPC, ContentProvider SQLi/traversal, PendingIntent, deep links, native WebView RCE, storage & Keystore review, crypto-primitive weakness pass, NSC, apksigner/Janus, SBOM.
  • reference/android-dynamic-analysis.md — DAST: device/Magisk/Zygisk setup, frida-server bring-up, objection recipes, interception + Android-7 user-CA workarounds, cross-stack pinning bypass (OkHttp/BoringSSL-Flutter/RN), drozer IPC, runtime storage, RESILIENCE active bypass + repack/resign.

iOS

  • reference/ios-static-analysis.md — SAST: IPA acquisition + FairPlay decrypt (cryptid), Mach-O/ObjC/Swift RE, ATS, entitlements/provisioning, binary hardening, Keychain accessibility + Data Protection, URL schemes/Universal Links, WKWebView, pasteboard/snapshot, MobSF/SBOM.
  • reference/ios-dynamic-analysis.md — DAST: jailbroken vs non-JB (objection patchipa / frida-gadget) bring-up, objection/Frida on iOS, SSL Kill Switch / SecTrust pinning bypass, Keychain dump, LAContext biometric bypass, jailbreak/anti-debug defeat, method tracing.

Framework-specific reverse engineering

Cross-skill (reused capabilities — cross-linked, not duplicated)

Deterministic control-wiring detector

  • ../../tools/apk_control_wiring.py — static cross-reference over a decompiled Android tree that distinguishes a REAL applied control from an ORPHANED one: RootBeer/SafetyNet/Play-Integrity shipped-but-unwired (referenced but the result gates nothing), CertificatePinner built-but-not-attached to an OkHttpClient, hardcoded AES/DES key literals + their invoke-sites, and bundled-but-never-loaded .so. Run it in the STATIC phase BEFORE authoring remediation verdicts — a naive re-test that only greps for the control's presence wrongly reports an inert control "fixed" (a recurring mobile re-test crux).

Anti-patterns

  • Reaching for Frida/emulator before the static dump exists — static-first is faster and needs no device. But do not treat dynamic as out of scope: pinning enforcement, Keystore binding, root reaction, and IPC reachability are runtime-only.
  • Reporting a control as present (root/pinning/tamper detection) without an active bypass attempt — MAS-L2 / MASA require you defeat it or prove you can't.
  • Concluding "no pinning" from an empty network_security_config.xml, or "no secrets" from a cryptid 1 iOS binary — check the JS/native pin layers, and decrypt the IPA first.
  • Stopping at a client-side IDOR — it is a server-side hypothesis; confirm via the api-security pivot.
  • Reporting a CVE from a library's mere presence — confirm the exact version and a reachable code path.

© transilienceai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files in skills/mobile-security of transilienceai/communitytools.

  • SKILL.md
  • reference/android-dynamic-analysis.md
  • reference/android-static-analysis.md
  • reference/flutter-aot-reversing.md
  • reference/ios-dynamic-analysis.md
  • reference/ios-static-analysis.md
  • reference/masvs-class-map.md
  • reference/methodology.md
  • reference/privacy-testing.md
  • reference/scenarios/android/native-lib-host-extraction.md
  • reference/scenarios/android/react-native-hermes.md

Open the folder on GitHubat commit 95fdc12

Compare with similar skills

Mobile Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mobile Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mobile Security this skilltransilienceai/communitytools562—~2.5kAutomated safety check: PassMIT
Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC135—~12kAutomated safety check: PassApache-2.0
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Testing Mobile Applicationstrilwu/secskills157—~2.8kAutomated safety check: PassMIT
SimdeckNativeScript/SimDeck152—~3.6kAutomated safety check: PassMIT
Detour Onboardingsoftware-mansion-labs/skills291—~2.8kAutomated safety check: PassNone

Similar skills

  • Mobile App Security Testing

    langbyyi/CyberStrikeAI-SRC

    移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…

    135 GitHub stars~12k tokensUpdated yesterday
    SecurityAuto-check passed
  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

    157 GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Simdeck

    NativeScript/SimDeck

    A skill your agent uses for simulator lifecycle, app install/launch, live viewing, UI inspection, touch/keyboard automation, screenshots, recordings, logs, pasteboard, hardware controls, and…

    152 GitHub stars~3.6k tokensUpdated 27 days ago
    MobileAuto-check passed
  • Detour Onboarding

    software-mansion-labs/skills

    Complete onboarding guide for developers who are new to Detour, the open-source deferred deep linking SDK by Software Mansion.

    291 GitHub stars~2.8k tokensUpdated 11 days ago
    MobileAuto-check passed
  • Revyl CLI Auth Bypass

    RevylAI/revyl-cli

    Set up test-only auth bypass for Revyl runs across Expo, React Native, native iOS, native Android, and Flutter apps.

    522 GitHub stars~2.5k tokensUpdated today
    MobileAuto-check passed

More from transilienceai/communitytools

All 35 skills in this repo
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    562 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    562 GitHub stars~812 tokensUpdated 2 mo ago
    Auto-check: notes
  • Pci Secure Software

    transilienceai/communitytools

    Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

    562 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Protect With Password

    transilienceai/communitytools

    Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).

    562 GitHub stars~583 tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Update

    transilienceai/communitytools

    Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits.

    562 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    562 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check: notes

Categories

Questions about Mobile Security

What does Mobile Security do?

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…. Mobile Security is an agent skill from transilienceai/communitytools. Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC, storage, crypto, signing), dynamic analysis (Frida/objection, TLS-pinning + root/jailbreak bypass, traffic interception), and privacy testing.

When should I use Mobile Security?

Mobile Security fits situations like: tasks that involve Mobile application security; tasks that involve Cross-platform mobile apps; tasks that involve Web application vulnerabilities.

How do I install Mobile Security in Claude Code?

Run `npx skills add transilienceai/communitytools --skill mobile-security -a claude-code`. Or copy the skill folder (skills/mobile-security in transilienceai/communitytools) into .claude/skills/mobile-security in your project. Claude Code loads it when a task matches its description.

How do I install Mobile Security in Codex?

Run `npx skills add transilienceai/communitytools --skill mobile-security -a codex`. Or copy the skill folder (skills/mobile-security in transilienceai/communitytools) into .agents/skills/mobile-security in your project. Codex loads it when a task matches its description.

Can I use Mobile Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add transilienceai/communitytools --skill mobile-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mobile-security, .gemini/skills/mobile-security, .github/skills/mobile-security and .opencode/skills/mobile-security in your project.

What does Mobile Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Mobile Security is instructions for the agent only.

Does Mobile Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mobile Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mobile Security use?

Mobile Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mobile Security use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mobile Security?

Skills that share tags, products or a category with Mobile Security: Mobile App Security Testing (langbyyi/CyberStrikeAI-SRC, 135 stars), Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Testing Mobile Applications (trilwu/secskills, 157 stars) and Simdeck (NativeScript/SimDeck, 152 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mobile Security?

transilienceai (a GitHub organization) maintains it in transilienceai/communitytools, which has 562 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on July 29, 2026.

Source: transilienceai/communitytools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.