Topic · Security

Best mobile application security skills for Claude Code, Codex and other agents.

Skills that test the security of Android and iOS apps.
skills
42
official
2

Mobile application security skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Mobile application security skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

微信收藏可视化:从加密的微信本地数据库端到端解密、解析,生成交互式 HTML 可视化报告. An agent skill from zhuyansen/wx-favorites-report.

zhuyansen/wx-favorites-report643—~1.3kAutomated safety check: PassNo licence5 mo ago
2

Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

ptn1411/skill219—~917Automated safety check: PassNo licence15 days ago
3

移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

s7safe/android-h1210—~631Automated safety check: PassNo licence5 mo ago
4

用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

index-login/MobileRE-Skill111—~3kAutomated safety check: PassMIT7 days ago
5

Run Mira environment risk collection. An agent skill from vw2x/Mira.

vw2x/Mira105—~793Automated safety check: PassGPL-3.02 days ago
6

Debug and emulate specific code fragments or functions using the Unicorn engine.

index-login/MobileRE-Skill111—~1.9kAutomated safety check: PassMIT7 days ago
7

Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira.

vw2x/Mira105—~637Automated safety check: PassGPL-3.02 days ago
8

Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository.

vw2x/Mira105—~892Automated safety check: PassGPL-3.02 days ago
9

Route Mira detection findings into a reusable knowledge pipeline.

vw2x/Mira105—~1.1kAutomated safety check: PassGPL-3.02 days ago
10

当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是…

zhaji2333/CkSKILLS112—~1.7kAutomated safety check: PassMIT22 days ago
11

Maintain a Mira detection topic after user confirmation. An agent skill from vw2x/Mira.

vw2x/Mira105—~575Automated safety check: PassGPL-3.02 days ago
12

Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

index-login/MobileRE-Skill111—~1.9kAutomated safety check: PassMIT7 days ago
13

当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest…

zhaji2333/CkSKILLS112—~3.3kAutomated safety check: PassMIT22 days ago
14

Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only.

trailofbits/skills7.4k—~1.8kAutomated safety check: PassCC-BY-SA-4.05 days ago
15

NVIDIA's runtime safety framework for LLM applications. An agent skill from Orchestra-Research/AI-Research-SKILLs.

Orchestra-Research/AI-Research-SKILLs13k2 repos~1.9kAutomated safety check: WarnMIT3 mo ago
16

面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。

manyuegong33/r0crawl_skills305—~1.2kAutomated safety check: PassNo licence17 days ago
17

减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

index-login/MobileRE-Skill111—~242Automated safety check: PassMIT7 days ago
18

Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
19
19.Azure AigatewayOfficial

Configure Azure API Management as an AI Gateway for AI models, MCP tools, and agents.

microsoft/GitHub-Copilot-for-Azure2552 repos~1.3kAutomated safety check: PassMITtoday
20

Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

sickn33/agentic-awesome-skills47k1 repo~1.5kAutomated safety check: PassMITyesterday
21

Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
22

Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.01 mo ago
23

Mobile (Android + iOS) application penetration testing methodology.

SnailSploit/Claude-Red7.3k—~3.5kAutomated safety check: PassMIT17 days ago
24

You are a frontend security specialist focusing on Cross-Site Scripting (XSS) vulnerability detection and prevention.

aiskillstore/marketplace4306 repos~2.4kAutomated safety check: PassNo licencetoday
25

Expert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns.

aiskillstore/marketplace4306 repos~3.2kAutomated safety check: PassNo licencetoday
26

Generate and inject Frida hooks for dynamic instrumentation — license bypass, SSL pinning bypass, function tracing, crypto interception, anti-debug bypass.

ptn1411/skill219—~983Automated safety check: NotesNo licence15 days ago
27

Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.01 mo ago
28

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC…

transilienceai/communitytools559—~2.5kAutomated safety check: PassMIT2 mo ago
29

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

trilwu/secskills156—~2kAutomated safety check: PassMIT1 mo ago
30

Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…

trilwu/secskills156—~2.5kAutomated safety check: PassMIT1 mo ago
31

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…

trilwu/secskills156—~2.4kAutomated safety check: PassMIT1 mo ago
32

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

trilwu/secskills156—~2.8kAutomated safety check: PassMIT1 mo ago
33

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
34

Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance.

briiirussell/cybersecurity-skills412—~2.6kAutomated safety check: WarnMIT4 mo ago
35

Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

dslsdzc/rev-skills117—~2kAutomated safety check: PassApache-2.02 days ago
36

Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.

dslsdzc/rev-skills117—~2.8kAutomated safety check: PassApache-2.02 days ago
37

Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills.

dslsdzc/rev-skills117—~1.2kAutomated safety check: PassApache-2.02 days ago
38

Secure iOS apps with secure storage, biometrics, and data protection.

HoangNguyen0403/agent-skills-standard570—~500Automated safety check: PassMITtoday
39

Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。

dslsdzc/rev-skills117—~1.1kAutomated safety check: PassApache-2.02 days ago
40

Android 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复. An agent skill from dslsdzc/rev-skills.

dslsdzc/rev-skills117—~2kAutomated safety check: PassApache-2.02 days ago
41

移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React…

langbyyi/CyberStrikeAI-SRC133—~12kAutomated safety check: PassApache-2.010 days ago
42

Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile…

FerroxLabs/wayland608—~4.8kAutomated safety check: PassApache-2.0yesterday

Questions, answered from the data.

What is the best mobile application security skill?

Wx Favorites Report from zhuyansen/wx-favorites-report ranks first of the 42 mobile application security skills listed here, with the highest score: its repository has 643 GitHub stars, its SKILL.md loads about 1.3k tokens and it passes the automated safety check with no findings. Next come Android APK Pentester and Mobile Security Expert.

Which mobile application security skills are official?

2 of the 42 mobile application security skills are official, published by the vendor's own GitHub organization: Firebase APK Security Scanner and Azure Aigateway.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.