mobile-application-securitylisted
Install: claude install-skill gztes/security-for-platforms
# Mobile Application Security
## Purpose
Enable Claude to assess Android and iOS application security against the **OWASP MASVS** (Mobile Application Security Verification Standard) and execute tests from the **OWASP MASTG** (Mobile Application Security Testing Guide). Claude performs static analysis on APK/IPA artifacts, guides dynamic instrumentation (Frida/objection), reviews secure storage, transport, and platform-interaction controls, and triages potentially malicious mobile apps.
> **Authorization Required**: Only test applications you own or are explicitly authorized to assess. Decompiling and modifying third-party apps may violate licenses and law. Confirm written scope before proceeding.
---
## Activation Triggers
This skill activates when the user asks about:
- Android (APK/AAB) or iOS (IPA) application security testing
- OWASP MASVS / MASTG verification or a mobile pentest checklist
- Decompiling, reversing, or static analysis of a mobile app
- Insecure data storage, hardcoded secrets, or keystore/keychain review
- Certificate pinning, SSL bypass, or mobile TLS/transport security
- Frida / objection dynamic instrumentation or runtime hooking
- `AndroidManifest.xml`, exported components, deep links, or `Info.plist` review
- Mobile malware analysis or suspicious APK triage
- Root/jailbreak detection, tampering, or anti-RE controls
---
## Prerequisites
```bash
pip install requests pyaxmlparser
```
**Optional enhanced capabilities:**
- `apktool` — APK decode/