Mobile Security
transilienceai/communitytools
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…
Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…
$ npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills bypassing-mobile-pinning --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/bypassing-mobile-pinning .claude/skills/bypassing-mobile-pinning && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bypassing-mobile-pinning" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-mobile-pinning into .claude/skills/bypassing-mobile-pinning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-mobile-pinning", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-mobile-pinningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills bypassing-mobile-pinning --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-offense/skills/bypassing-mobile-pinning .agents/skills/bypassing-mobile-pinning && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bypassing-mobile-pinning" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-mobile-pinning into .agents/skills/bypassing-mobile-pinning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-mobile-pinning", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills bypassing-mobile-pinning --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-offense/skills/bypassing-mobile-pinning .cursor/skills/bypassing-mobile-pinning && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bypassing-mobile-pinning" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-mobile-pinning into .cursor/skills/bypassing-mobile-pinning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-mobile-pinning", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-offense/skills/bypassing-mobile-pinning--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills bypassing-mobile-pinning --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-offense/skills/bypassing-mobile-pinning .gemini/skills/bypassing-mobile-pinning && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bypassing-mobile-pinning" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-mobile-pinning into .gemini/skills/bypassing-mobile-pinning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-mobile-pinning", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills bypassing-mobile-pinningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-offense/skills/bypassing-mobile-pinning .github/skills/bypassing-mobile-pinning && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bypassing-mobile-pinning" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-mobile-pinning into .github/skills/bypassing-mobile-pinning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-mobile-pinning", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills bypassing-mobile-pinning --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-offense/skills/bypassing-mobile-pinning .opencode/skills/bypassing-mobile-pinning && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bypassing-mobile-pinning" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/bypassing-mobile-pinning into .opencode/skills/bypassing-mobile-pinning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bypassing-mobile-pinning", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bypassing-mobile-pinningDiagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…
Bypassing Mobile Pinning is an agent skill from trilwu/secskills. Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection, Frida, SSL Kill Switch, and APK patching. Use when Burp, mitmproxy, or Charles shows a TLS handshake error, an empty proxy, or "network error" from a mobile app, or when a target is known to pin certificates.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Network security and Mobile application security. It works with Android, Frida and Flutter. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
adbrgopensslFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bypassing Mobile Pinning loads about 2.5k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 1,020 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,020 words, ~2,544 tokens.
.claude/skills/bypassing-mobile-pinning/SKILL.md (or your agent's skills folder).Most time lost here is spent bypassing pinning that was never there. An empty proxy has at least six causes, and the fix for each is different — one of them is not pinning at all but Android's default distrust of user CAs, and another is that the app has its own TLS stack and never saw your proxy. Diagnose before you reach for a bypass script.
Use only against apps you are authorized to test.
reversing-flutter-apps; Flutter's failure looks
identical but the cause and fix are specific to its enginetesting-mobile-applicationstesting-apis.so in depth — use analyzing-binariesRun this before installing anything. The symptom tells you the cause.
| Symptom | Likely cause | Fix |
|---|---|---|
Proxy sees the CONNECT, then TLS alert unknown_ca / bad_certificate | Your CA is not trusted | Install as system CA, or patch Network Security Config |
| Proxy sees the CONNECT, then alert only for some domains | Real pinning, scoped to those hosts | Hook the pinning check |
| Proxy sees nothing at all, app works | App ignores the system proxy | Force traffic at the network layer (Flutter, gRPC, some SDKs) |
| Proxy sees the handshake, server rejects the client | Mutual TLS — the app presents a client certificate | Extract the client cert; this is not pinning |
| Works on emulator, fails on device (or vice versa) | Root/emulator detection, not TLS | Different problem — see the detection section |
| Fails only after login | Pinning applied to the API host only | Hook, then re-check |
# What does the app actually declare?
apktool d target.apk -o out
cat out/res/xml/network_security_config.xml 2>/dev/null
rg -n 'networkSecurityConfig|usesCleartextTraffic' out/AndroidManifest.xml
# Which TLS stack is in play?
rg -l 'okhttp3|CertificatePinner|TrustKit|AFNetworking|Alamofire' out/ 2>/dev/null | head
unzip -l target.apk | rg 'libssl|libcrypto|libconscrypt|libflutter|libil2cpp|libmonodroid'Check Network Security Config before assuming pinning. Since Android 7, apps do not trust user-installed CAs by default. An app with no pinning code at all will still fail interception. Two fixes:
# A. Install your CA as a SYSTEM certificate (no app modification — preferred)
# Emulator:
emulator -avd <name> -writable-system
adb root && adb remount
openssl x509 -inform PEM -subject_hash_old -in burp.pem | head -1 # → e.g. 9a5ba580
cp burp.pem 9a5ba580.0 && adb push 9a5ba580.0 /system/etc/security/cacerts/
adb shell chmod 644 /system/etc/security/cacerts/9a5ba580.0
# Rooted device: use a Magisk module so the change survives reboot
# B. Patch the config and repack (when you cannot get a system CA)
# Add to network_security_config.xml:
# <base-config><trust-anchors>
# <certificates src="system"/><certificates src="user"/>
# </trust-anchors></base-config>
apktool b out -o patched.apk && apksigner sign --ks debug.keystore patched.apkOption A is better: it modifies nothing in the app, so integrity checks, signature checks, and Play Integrity are unaffected. Reach for B only when you cannot get a system CA onto the device.
Identify the stack, then hook it. A generic script that misses will look like "the bypass failed" when it simply targeted the wrong layer.
# Start here — covers the common Java-layer stacks in one shot
objection -g com.target.app explore
# then: android sslpinning disable
# Or a maintained universal script
frida -U -f com.target.app -l android-ssl-bypass.js --no-pause| Stack | Marker | Hook point |
|---|---|---|
| OkHttp 3/4 | okhttp3.CertificatePinner | CertificatePinner.check() — return normally |
| HttpURLConnection | javax.net.ssl.* | Custom X509TrustManager.checkServerTrusted() |
| Conscrypt | libconscrypt_jni.so | Platform.checkServerTrusted, or the native layer |
| Apache HttpClient | org.apache.http | SSLSocketFactory verifier |
| WebView | onReceivedSslError | Force handler.proceed() |
| Native / BoringSSL | libssl.so, custom .so | SSL_CTX_set_custom_verify, ssl_verify_peer_cert |
| Xamarin | libmonodroid.so, libxamarin* | Mono-level ServicePointManager / HttpClientHandler |
| Unity | libil2cpp.so | UnityWebRequest cert handler, or BestHTTP's verifier |
| gRPC | libgrpc.so | Channel credentials; often also ignores the proxy |
Native pinning is where the universal scripts stop working. When
objection reports success but traffic still fails, the check is in a .so.
BoringSSL's verification entry points are not exported, so scripts locate them
by pattern scanning — and the pattern is version-specific. Confirm what you
are dealing with:
# Is a native TLS stack even present?
unzip -j target.apk 'lib/arm64-v8a/*' -d libs && rg -l 'SSL_|BoringSSL|s2n' libs/
# Trace the native calls to see which library terminates TLS
frida-trace -U -f com.target.app -i 'SSL_*' -i '*verify*'For Unity, Xamarin, and Flutter builds, recover symbols first —
reversing-unity-il2cpp, reversing-flutter-apps — then hook the named
function rather than pattern-scanning blind.
# Frida-based, covers NSURLSession and the common libraries
objection -g com.target.app explore
# then: ios sslpinning disable
# Jailbroken device, no Frida
# SSL Kill Switch 3 — system-wide, survives app updates| Library | Hook point |
|---|---|
| NSURLSession (default) | URLSession:didReceiveChallenge: → .useCredential with the server trust |
| TrustKit | TSKPinningValidator result |
| AFNetworking | AFSecurityPolicy.evaluateServerTrust: |
| Alamofire | ServerTrustManager / ServerTrustEvaluating |
| Native/BoringSSL | Same as Android — hook the verify callback |
Non-jailbroken devices: repackage the IPA with the Frida gadget
(objection patchipa), re-sign, and sideload. Expect this to trip integrity
or attestation checks in hardened apps.
Work through these in order rather than trying more bypass scripts.
iptables, or a
VPN/tun-based proxy.adb shell su -c 'iptables -t nat -A OUTPUT -p tcp --dport 443 -j DNAT --to <proxy>:8080'.p12
or keystore from the app bundle, recover its password (often in code or
strings), and load it into your proxy's client-certificate settings. This
is a separate mechanism from pinning and no pinning bypass will touch it.frida string
scan, port 27042 probing, /proc/self/maps inspection, or Play Integrity.
Bypass the detection first, then retry the pinning bypass.A bypass is confirmed when you can see and modify a request end to end — not when the app merely stops erroring.
1. Proxy shows the API host, not just analytics and CDN traffic
2. Request and response bodies are readable
3. A modified request produces a different server response
4. Authenticated flows still work through the proxyIf only step 1 passes, you may be seeing a fallback path while the real API traffic goes elsewhere.
testing-mobile-applications — the wider assessment this unblocksreversing-flutter-apps — Flutter's separate TLS stack and proxy behaviourreversing-unity-il2cpp, reversing-react-native-apps — symbol recovery
before hooking framework-specific stackstesting-apis — where the actual findings are, once you can see the traffic© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-offense/skills/bypassing-mobile-pinning of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Bypassing Mobile Pinning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bypassing Mobile Pinning this skilltrilwu/secskills | 157 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Mobile Securitytransilienceai/communitytools | 563 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC | 129 | — | ~12k | Automated safety check: Pass | Apache-2.0 | |
| Frida Mobile Securityindex-login/MobileRE-Skill | 158 | — | ~3k | Automated safety check: Pass | MIT | |
| Mira Risk Collectvw2x/Mira | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | |
| Rev Dex Dumperindex-login/MobileRE-Skill | 158 | — | ~1.9k | Automated safety check: Pass | MIT |
transilienceai/communitytools
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…
langbyyi/CyberStrikeAI-SRC
移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…
index-login/MobileRE-Skill
用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…
vw2x/Mira
Run Mira environment risk collection. An agent skill from vw2x/Mira.
index-login/MobileRE-Skill
Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.
manyuegong33/r0crawl_skills
面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Categories
Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…. Bypassing Mobile Pinning is an agent skill from trilwu/secskills. Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection, Frida, SSL Kill Switch, and APK patching.
Bypassing Mobile Pinning fits situations like: charles shows a TLS handshake error; network error from a mobile app; A target is known to pin certificates.
Run `npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a claude-code`. Or copy the skill folder (secskills-offense/skills/bypassing-mobile-pinning in trilwu/secskills) into .claude/skills/bypassing-mobile-pinning in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a codex`. Or copy the skill folder (secskills-offense/skills/bypassing-mobile-pinning in trilwu/secskills) into .agents/skills/bypassing-mobile-pinning in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill bypassing-mobile-pinning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bypassing-mobile-pinning, .gemini/skills/bypassing-mobile-pinning, .github/skills/bypassing-mobile-pinning and .opencode/skills/bypassing-mobile-pinning in your project.
Going by SKILL.md and its folder, Bypassing Mobile Pinning needs the command-line tools its instructions call (adb, rg and openssl).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bypassing Mobile Pinning is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bypassing Mobile Pinning: Mobile Security (transilienceai/communitytools, 563 stars), Mobile App Security Testing (langbyyi/CyberStrikeAI-SRC, 129 stars), Frida Mobile Security (index-login/MobileRE-Skill, 158 stars) and Mira Risk Collect (vw2x/Mira, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.