android-pentest

Installation
SKILL.md

Android Mobile Application Penetration Testing

Thin router for full MASTG-aligned Android assessments via ADB + Frida + Mobile MCP. Load workflow / methodology / reference files on demand; do not attempt to memorise the whole skill up front.

When to Use

  • Start a new Android app security assessment
  • Bypass SSL pinning, root detection, anti-tamper, or biometric checks
  • Extract/triage local storage (SharedPreferences, DBs, files, logs)
  • Test exported activities, services, providers, receivers, deep links
  • Hook crypto / auth / session / keystore at runtime
  • Map a build to OWASP MASVS / MASTG for compliance evidence
  • Produce structured findings + remediation guidance

Trigger Phrases

"pentest this Android app" • "security test the APK" • "bypass SSL pinning on " • "extract data from " • "test Android authentication" • "fuzz Android intents" • "MASTG testing for " • "mobile app security assessment"

When NOT to Use This Skill

  • iOS apps → use ios-pentest (if available) or generic mobile skill
  • Server-side API fuzzing of mobile backends → use api-security / web-pentest
Related skills

More from hardw00t/ai-security-arsenal

Installs
36
GitHub Stars
39
First Seen
Feb 2, 2026