Topic · Security
Best mobile application security skills for Claude Code, Codex and other agents.
- skills
- 42
- official
- 2
Mobile application security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 微信收藏可视化:从加密的微信本地数据库端到端解密、解析,生成交互式 HTML 可视化报告. An agent skill from zhuyansen/wx-favorites-report. | zhuyansen/ | 643 | — | ~1.3k | Automated safety check: Pass | No licence | 5 mo ago |
| 2 | Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation. | ptn1411/ | 219 | — | ~917 | Automated safety check: Pass | No licence | 15 days ago |
| 3 | 移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。 | s7safe/ | 210 | — | ~631 | Automated safety check: Pass | No licence | 5 mo ago |
| 4 | 用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF… | index-login/ | 111 | — | ~3k | Automated safety check: Pass | MIT | 7 days ago |
| 5 | Run Mira environment risk collection. An agent skill from vw2x/Mira. | vw2x/ | 105 | — | ~793 | Automated safety check: Pass | GPL-3.0 | 2 days ago |
| 6 | Debug and emulate specific code fragments or functions using the Unicorn engine. | index-login/ | 111 | — | ~1.9k | Automated safety check: Pass | MIT | 7 days ago |
| 7 | Update Mira topic articles from cases and patterns. An agent skill from vw2x/Mira. | vw2x/ | 105 | — | ~637 | Automated safety check: Pass | GPL-3.0 | 2 days ago |
| 8 | Capture Mira detection experiments locally, then distill selected evidence into a tracked case only when the user explicitly requests promotion into a report or the knowledge repository. | vw2x/ | 105 | — | ~892 | Automated safety check: Pass | GPL-3.0 | 2 days ago |
| 9 | Route Mira detection findings into a reusable knowledge pipeline. | vw2x/ | 105 | — | ~1.1k | Automated safety check: Pass | GPL-3.0 | 2 days ago |
| 10 | 当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准目录交付。命中场景:JADX 打开是… | zhaji2333/ | 112 | — | ~1.7k | Automated safety check: Pass | MIT | 22 days ago |
| 11 | Maintain a Mira detection topic after user confirmation. An agent skill from vw2x/Mira. | vw2x/ | 105 | — | ~575 | Automated safety check: Pass | GPL-3.0 | 2 days ago |
| 12 | Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other. | index-login/ | 111 | — | ~1.9k | Automated safety check: Pass | MIT | 7 days ago |
| 13 | 当需要在不对 APK 全量反编译的前提下秒级定位硬编码密钥/签名函数/隐藏接口/调试后门,或 APK 过大(100MB)JADX 全量反编译过慢、内存吃紧,或脱壳产物(裸 dex)需要快速检索,或只想先读一下 Manifest 组件面/权限清单时调用。负责基于 Droid ASC 的零预处理快速定位(findrefs 全局交叉引用搜索 + getclass 按需反编译 + Manifest… | zhaji2333/ | 112 | — | ~3.3k | Automated safety check: Pass | MIT | 22 days ago |
| 14 | Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 15 | NVIDIA's runtime safety framework for LLM applications. An agent skill from Orchestra-Research/AI-Research-SKILLs. | Orchestra-Research/ | 13k | 2 repos | ~1.9k | Automated safety check: Warn | MIT | 3 mo ago |
| 16 | 面向新手的全谱系逆向工程路由器,覆盖 Web/JavaScript、Android/iOS、Frida、脱壳、反分析、原生二进制、协议、固件、恶意软件、游戏、云 API、CTF、可复现一致性测试。用于逆向、起步、脱壳、反编译、hook、Frida、绕过检测、APK/SO/DEX/JS/PCAP/WASM/PE/ELF/Mach-O 分析、签名还原,或从样本到验证结果的完整调查。 | manyuegong33/ | 305 | — | ~1.2k | Automated safety check: Pass | No licence | 17 days ago |
| 17 | 减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。 | index-login/ | 111 | — | ~242 | Automated safety check: Pass | MIT | 7 days ago |
| 18 | Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Configure Azure API Management as an AI Gateway for AI models, MCP tools, and agents. | microsoft/ | 255 | 2 repos | ~1.3k | Automated safety check: Pass | MIT | today |
| 20 | Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP… | sickn33/ | 47k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | yesterday |
| 21 | Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | Mobile (Android + iOS) application penetration testing methodology. | SnailSploit/ | 7.3k | — | ~3.5k | Automated safety check: Pass | MIT | 17 days ago |
| 24 | You are a frontend security specialist focusing on Cross-Site Scripting (XSS) vulnerability detection and prevention. | aiskillstore/ | 430 | 6 repos | ~2.4k | Automated safety check: Pass | No licence | today |
| 25 | Expert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns. | aiskillstore/ | 430 | 6 repos | ~3.2k | Automated safety check: Pass | No licence | today |
| 26 | 26.Frida Hooker Generate and inject Frida hooks for dynamic instrumentation — license bypass, SSL pinning bypass, function tracing, crypto interception, anti-debug bypass. | ptn1411/ | 219 | — | ~983 | Automated safety check: Notes | No licence | 15 days ago |
| 27 | Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 28 | Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC… | transilienceai/ | 559 | — | ~2.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 29 | Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and… | trilwu/ | 156 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 30 | Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection… | trilwu/ | 156 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed… | trilwu/ | 156 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 32 | Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities. | trilwu/ | 156 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 33 | Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 34 | 34.Mobile Audit Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. | briiirussell/ | 412 | — | ~2.6k | Automated safety check: Warn | MIT | 4 mo ago |
| 35 | Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation. | dslsdzc/ | 117 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 36 | 36.Re Frida Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 117 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 37 | Frida 脚本生成方法论:目标特征 → 模板选择 → 改写 → 验证。独立于执行插桩(re-frida). An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 38 | 38.iOS Security Secure iOS apps with secure storage, biometrics, and data protection. | HoangNguyen0403/ | 570 | — | ~500 | Automated safety check: Pass | MIT | today |
| 39 | Android 加密体系审计(crypto audit):AndroidKeyStore 密钥体系分析(别名/算法/用途/硬件背书)、 Cipher/KeyInfo 审计、加密调用点 hook(Frida 拦截密钥别名与用途)。 | dslsdzc/ | 117 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 40 | Android 加固脱壳专项:乐固/360/梆梆/爱加密、DEX 恢复. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 117 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 41 | 移动应用安全深度测试专业技能(v3.0):移动端深层攻击链(App→API→后端→云)、Android/iOS深度逆向与动态调试、Frida全面对抗与加固脱壳、iOS越狱检测绕过/ObjC Runtime/LLDB调试/证书固定绕过、跨平台框架漏洞(Flutter/React… | langbyyi/ | 133 | — | ~12k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 42 | Mobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile… | FerroxLabs/ | 608 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
Questions, answered from the data.
What is the best mobile application security skill?
Wx Favorites Report from zhuyansen/wx-favorites-report ranks first of the 42 mobile application security skills listed here, with the highest score: its repository has 643 GitHub stars, its SKILL.md loads about 1.3k tokens and it passes the automated safety check with no findings. Next come Android APK Pentester and Mobile Security Expert.
Which mobile application security skills are official?
2 of the 42 mobile application security skills are official, published by the vendor's own GitHub organization: Firebase APK Security Scanner and Azure Aigateway.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Access reviews and audit trails34