Agent skill

Testing Mobile Applications

by trilwu in trilwu/secskills

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

MITAuto-check passedSecurity

Install Testing Mobile Applications

skills CLI
$ npx skills add trilwu/secskills --skill testing-mobile-applications -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills testing-mobile-applications --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/testing-mobile-applications .claude/skills/testing-mobile-applications && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
testing-mobile-applications
GitHub stars
157
Token cost
~2.8k tokens
SKILL.md length
502 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

  • Works in 7 steps: Static Analysis - Decompile, search… → Install - Install on emulator/device → Intercept Traffic - Set up… → …
  • Testing mobile app security
  • SKILL.md covers When to Use, When NOT to Use, Check the Framework Before… and Android Pentesting, plus 5 more sections
  • Calls adb, java and sqlite3; reaches mitm.it

What it does

Testing Mobile Applications is an agent skill from trilwu/secskills. Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities. Use when testing mobile app security or performing mobile pentesting.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security and Penetration testing. It works with Android, iOS, Flutter and React Native. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Testing mobile app security
  • Performing mobile pentesting

Example prompts

  • “/testing-mobile-applications”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Static Analysis - Decompile, search strings, analyze manifest/Info.plist
  2. Install - Install on emulator/device
  3. Intercept Traffic - Set up Burp/mitmproxy, bypass SSL pinning
  4. Dynamic Analysis - Use Frida to hook functions, bypass protections
  5. Test Components - Test exported components, deep links, intents
  6. Data Storage - Check for insecure data storage in files/DB/keychain
  7. Repackage - Modify and recompile to test additional scenarios

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb
    • java
    • sqlite3
    • ssh
    • rg
    • xcrun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • mitm.it

    Also links to:

    • book.hacktricks.xyz
    • github.com
    • mobile-security.gitbook.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Testing Mobile Applications loads about 2.8k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 502 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 502 words, ~2,809 tokens.

Download SKILL.mdSave it as .claude/skills/testing-mobile-applications/SKILL.md (or your agent's skills folder).
name
testing-mobile-applications
description
Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities. Use when testing mobile app security or performing mobile pentesting.
verified
2026-07-27

Testing Mobile Applications

When to Use

  • Android APK analysis and exploitation
  • iOS application pentesting
  • Mobile app security assessment
  • Bypassing security controls (SSL pinning, root detection)
  • Testing mobile-specific vulnerabilities

When NOT to Use

  • Backend API testing — use testing-apis
  • Deep native binary reversing — use analyzing-binaries
  • Analyzing a malicious app — use analyzing-malware
  • Source code is available — use auditing-code-for-vulnerabilities

Check the Framework Before Anything Else

jadx returning almost nothing does not mean the app is obfuscated — it usually means the logic is not in the dex at all. Run this first; it decides which skill you should be in.

bash
unzip -l target.apk | rg 'libflutter|libapp\.so|index\.android\.bundle|libhermes|global-metadata|libil2cpp|Assembly-CSharp'
MarkerFrameworkSkill
libflutter.so, libapp.so, flutter_assets/Flutter / Dartreversing-flutter-apps
index.android.bundle, libhermes.so, main.jsbundleReact Nativereversing-react-native-apps
global-metadata.dat, libil2cpp.so, Assembly-CSharp.dllUnityreversing-unity-il2cpp
libmonodroid.so, assemblies.blob, libxamarin-app.soXamarin / .NET MAUIreversing-xamarin-maui
classes*.dex with real application packagesNative Androidcontinue here

Two framework symptoms are worth naming, because they waste the most time when misread: a Flutter app shows no traffic at all in your proxy (it ignores the system proxy and CA store), and a React Native or Unity app shows a near-empty dex with all the logic in assets/.

Three more procedure skills split out of this one, because each needs far more detail than a general assessment can carry:

SituationSkill
App exits on a rooted device, or dies when Frida attachesbypassing-root-jailbreak-detection
iOS binary work: FairPlay decryption, Mach-O, class-dump, entitlementsanalyzing-ios-binaries
Exported components, deep links, URL schemes, content providerstesting-mobile-ipc

If the proxy fails for any other reason — a TLS handshake alert, or an app that reports a network error with the proxy on — go to bypassing-mobile-pinning before assuming certificate pinning. On Android 7+ the most common cause is that your CA is installed as a user certificate, which apps do not trust by default, and no pinning bypass fixes that.

Android Pentesting

APK Analysis Tools
bash
# Decompile APK
apktool d app.apk -o app_decompiled

# Convert DEX to JAR
d2j-dex2jar app.apk

# View JAR with JD-GUI
jd-gui app-dex2jar.jar

# Automated analysis
mobsf  # Mobile Security Framework
jadx app.apk  # APK to Java decompiler
Show full SKILL.md (202 more words)Show less
ADB (Android Debug Bridge)
bash
# List devices
adb devices

# Connect over network
adb connect 192.168.1.100:5555

# Install APK
adb install app.apk

# Uninstall
adb uninstall com.package.name

# List packages
adb shell pm list packages
adb shell pm list packages | grep -i "keyword"

# Get APK path
adb shell pm path com.package.name

# Pull APK from device
adb pull /data/app/com.package.name-xxx/base.apk

# Start activity
adb shell am start -n com.package.name/.MainActivity

# View logs
adb logcat

# Shell access
adb shell
Static Analysis

Search for Sensitive Data:

bash
# Extract strings
strings app.apk | grep -i password
strings app.apk | grep -i api
strings app.apk | grep -i token
strings app.apk | grep -i key

# Search in decompiled code
grep -r "password" app_decompiled/
grep -r "http://" app_decompiled/
grep -r "api_key" app_decompiled/

Check AndroidManifest.xml:

bash
# Decompile and view
apktool d app.apk
cat app_decompiled/AndroidManifest.xml

# Look for:
# - android:debuggable="true"
# - android:allowBackup="true"
# - Exported activities/services
# - Custom permissions
# - URL schemes
Dynamic Analysis

Frida (Runtime Instrumentation):

bash
# List running apps
frida-ps -U

# Attach to app
frida -U -n "App Name"
frida -U -f com.package.name

# Load script
frida -U -f com.package.name -l script.js

# Common scripts
# - Bypass SSL pinning
# - Bypass root detection
# - Hook functions
# - Dump memory

SSL Pinning Bypass:

javascript
// Frida script - Universal SSL pinning bypass
Java.perform(function() {
    var TrustManager = Java.use('javax.net.ssl.X509TrustManager');
    TrustManager.checkServerTrusted.implementation = function() {};

    var SSLContext = Java.use('javax.net.ssl.SSLContext');
    SSLContext.init.overload('[Ljavax.net.ssl.KeyManager;', '[Ljavax.net.ssl.TrustManager;', 'java.security.SecureRandom').implementation = function(a,b,c) {
        this.init.overload('[Ljavax.net.ssl.KeyManager;', '[Ljavax.net.ssl.TrustManager;', 'java.security.SecureRandom').call(this, a, null, c);
    };
});

Root Detection Bypass:

javascript
// Frida - Bypass root detection
Java.perform(function() {
    var RootClass = Java.use('com.package.name.RootDetection');
    RootClass.isRooted.implementation = function() {
        return false;
    };
});
Intercepting Traffic

Burp Suite Setup:

bash
# 1. Install Burp CA certificate
# Download from http://burp:8080 on device
# Install in Settings -> Security -> Install from storage

# 2. Configure proxy
adb shell settings put global http_proxy 192.168.1.100:8080

# 3. For apps with SSL pinning, use Frida bypass

# 4. Clear proxy when done
adb shell settings put global http_proxy :0

mitmproxy:

bash
# Start mitmproxy
mitmproxy --listen-port 8080

# Install certificate on device
# http://mitm.it

# Set device proxy to attacker IP:8080
Modifying and Repackaging APK
bash
# 1. Decompile
apktool d app.apk -o app_mod

# 2. Modify smali code
# Edit files in app_mod/smali/

# 3. Recompile
apktool b app_mod -o app_modified.apk

# 4. Sign APK
# Generate keystore (first time only)
keytool -genkey -v -keystore my-key.keystore -alias alias_name -keyalg RSA -keysize 2048 -validity 10000

# Sign
jarsigner -verbose -sigalg SHA1withRSA -digestalg SHA1 -keystore my-key.keystore app_modified.apk alias_name

# Or use uber-apk-signer
java -jar uber-apk-signer.jar -a app_modified.apk

# 5. Install
adb install app_modified.apk
Common Vulnerabilities

Insecure Data Storage:

bash
# Check shared preferences
adb shell
cd /data/data/com.package.name/shared_prefs/
cat *.xml

# Check databases
cd /data/data/com.package.name/databases/
sqlite3 database.db
.tables
SELECT * FROM users;

# Check files
cd /data/data/com.package.name/files/
ls -la
cat *

Exported Components:

bash
# List exported activities
adb shell dumpsys package com.package.name | grep -A 20 "Activity"

# Start exported activity
adb shell am start -n com.package.name/.ExportedActivity

# Call exported service
adb shell am startservice -n com.package.name/.ExportedService

# Broadcast to receiver
adb shell am broadcast -a com.package.name.ACTION

Insecure WebView:

bash
# Check for JavaScript enabled
# Look in code for:
webView.getSettings().setJavaScriptEnabled(true);

# Check for addJavascriptInterface
# Can lead to RCE if exposed

iOS Pentesting

Setup

Jailbreak Tools:

  • checkra1n (iOS 12-14)
  • unc0ver (iOS 11-14.8)
  • Taurine (iOS 14-14.3)

SSH Access:

bash
# Default credentials
ssh root@<device-ip>
# password: alpine

# Change default password!
passwd
IPA Analysis
bash
# Extract IPA
unzip app.ipa

# View binary
otool -L Payload/App.app/App
strings Payload/App.app/App

# Class dump
class-dump Payload/App.app/App > classes.txt

# Decrypt binary (on jailbroken device)
frida-ios-dump -u App

# Static analysis with Hopper/Ghidra
Runtime Analysis

Frida on iOS:

bash
# List apps
frida-ps -Ua

# Attach
frida -U -n "App Name"
frida -U -f com.company.app

# SSL pinning bypass (iOS)
objection -g "App Name" explore
ios sslpinning disable

Objection:

bash
# Launch objection
objection -g com.company.app explore

# Common commands
ios info binary
ios hooking list classes
ios hooking search methods MainActivity
ios sslpinning disable
ios jailbreak disable
ios keychain dump
ios nsuserdefaults get
File System Access
bash
# Connect via SSH
ssh root@device-ip

# App data location
cd /var/mobile/Containers/Data/Application/<UUID>/

# Find app UUID
ipainstaller -l  # List apps
ls /var/mobile/Containers/Data/Application/

# Common paths
Documents/
Library/
Library/Preferences/  # plist files
Library/Caches/
tmp/
Keychain Access
bash
# Using objection
ios keychain dump

# Manual (requires keychain-dumper on device)
./keychain_dumper

# Specific item
security find-generic-password -s "ServiceName"
Common iOS Vulnerabilities

Insecure Data Storage:

bash
# Check plist files
plutil -p Info.plist

# Check UserDefaults
ios nsuserdefaults get

# Check SQLite databases
sqlite3 database.db
.tables
SELECT * FROM sensitive_table;

Binary Protections:

bash
# Check for PIE
otool -hv App | grep PIE

# Check for stack canaries
otool -I App | grep stack_chk

# Check for ARC
otool -I App | grep objc_release

Mobile-Specific Attacks

Deep Link Exploitation:

bash
# Android
adb shell am start -a android.intent.action.VIEW -d "app://open?param=value"

# iOS
xcrun simctl openurl booted "app://open?param=value"

Intent Injection:

bash
# Send malicious intent
adb shell am start -n com.package/.Activity --es "extra_key" "malicious_value"

Backup Extraction:

bash
# Android backup
adb backup -f backup.ab com.package.name
# Extract
java -jar abe.jar unpack backup.ab backup.tar

# iOS backup
idevicebackup2 backup --full backup_directory

Tools

Android:

  • APKTool - Decompile/recompile APKs
  • dex2jar - Convert DEX to JAR
  • JADX - APK to Java decompiler
  • Frida - Dynamic instrumentation
  • Objection - Frida-based toolkit
  • MobSF - Automated analysis
  • Drozer - Android security framework

iOS:

  • Frida - Dynamic instrumentation
  • Objection - Frida toolkit
  • class-dump - Extract class info
  • Hopper/Ghidra - Disassemblers
  • frida-ios-dump - Decrypt binaries
  • iproxy - Forward ports

Quick Testing Workflow

  1. Static Analysis - Decompile, search strings, analyze manifest/Info.plist
  2. Install - Install on emulator/device
  3. Intercept Traffic - Set up Burp/mitmproxy, bypass SSL pinning
  4. Dynamic Analysis - Use Frida to hook functions, bypass protections
  5. Test Components - Test exported components, deep links, intents
  6. Data Storage - Check for insecure data storage in files/DB/keychain
  7. Repackage - Modify and recompile to test additional scenarios

References

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-offense/skills/testing-mobile-applications of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Testing Mobile Applications next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Testing Mobile Applications compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Testing Mobile Applications this skilltrilwu/secskills157—~2.8kAutomated safety check: PassMIT
Mobile Securitytransilienceai/communitytools562—~2.5kAutomated safety check: PassMIT
Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC135—~12kAutomated safety check: PassApache-2.0
Conducting Mobile App Penetration Testmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
SimdeckNativeScript/SimDeck152—~3.6kAutomated safety check: PassMIT
Detour Onboardingsoftware-mansion-labs/skills291—~2.8kAutomated safety check: PassNone

Similar skills

  • Mobile Security

    transilienceai/communitytools

    Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

    562 GitHub stars~2.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Mobile App Security Testing

    langbyyi/CyberStrikeAI-SRC

    移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…

    135 GitHub stars~12k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Conducting Mobile App Penetration Test

    mukul975/Anthropic-Cybersecurity-Skills

    Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Simdeck

    NativeScript/SimDeck

    A skill your agent uses for simulator lifecycle, app install/launch, live viewing, UI inspection, touch/keyboard automation, screenshots, recordings, logs, pasteboard, hardware controls, and…

    152 GitHub stars~3.6k tokensUpdated 28 days ago
    MobileAuto-check passed
  • Detour Onboarding

    software-mansion-labs/skills

    Complete onboarding guide for developers who are new to Detour, the open-source deferred deep linking SDK by Software Mansion.

    291 GitHub stars~2.8k tokensUpdated 11 days ago
    MobileAuto-check passed
  • Revyl CLI Auth Bypass

    RevylAI/revyl-cli

    Set up test-only auth bypass for Revyl runs across Expo, React Native, native iOS, native Android, and Flutter apps.

    522 GitHub stars~2.5k tokensUpdated today
    MobileAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Testing Mobile Applications

What does Testing Mobile Applications do?

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities. Testing Mobile Applications is an agent skill from trilwu/secskills. Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

When should I use Testing Mobile Applications?

Testing Mobile Applications fits situations like: testing mobile app security; performing mobile pentesting.

How do I install Testing Mobile Applications in Claude Code?

Run `npx skills add trilwu/secskills --skill testing-mobile-applications -a claude-code`. Or copy the skill folder (secskills-offense/skills/testing-mobile-applications in trilwu/secskills) into .claude/skills/testing-mobile-applications in your project. Claude Code loads it when a task matches its description.

How do I install Testing Mobile Applications in Codex?

Run `npx skills add trilwu/secskills --skill testing-mobile-applications -a codex`. Or copy the skill folder (secskills-offense/skills/testing-mobile-applications in trilwu/secskills) into .agents/skills/testing-mobile-applications in your project. Codex loads it when a task matches its description.

Can I use Testing Mobile Applications in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill testing-mobile-applications -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/testing-mobile-applications, .gemini/skills/testing-mobile-applications, .github/skills/testing-mobile-applications and .opencode/skills/testing-mobile-applications in your project.

What does Testing Mobile Applications need to run?

Going by SKILL.md and its folder, Testing Mobile Applications needs the command-line tools its instructions call (adb, java, sqlite3, ssh, rg and xcrun).

Does Testing Mobile Applications access the network?

SKILL.md names 4 domains. In commands or code: mitm.it; the agent is likely to contact it when it follows the instructions. As links in the text: book.hacktricks.xyz, github.com and mobile-security.gitbook.io. This is read from the text; nothing was executed.

Is Testing Mobile Applications safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Testing Mobile Applications use?

Testing Mobile Applications is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Testing Mobile Applications use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Testing Mobile Applications?

Skills that share tags, products or a category with Testing Mobile Applications: Mobile Security (transilienceai/communitytools, 562 stars), Mobile App Security Testing (langbyyi/CyberStrikeAI-SRC, 135 stars), Conducting Mobile App Penetration Test (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Simdeck (NativeScript/SimDeck, 152 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Testing Mobile Applications?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.