← ClaudeAtlas

mobile-application-securitylisted

Android and iOS application security testing — static and dynamic analysis, APK/IPA inspection, OWASP MASVS/MASTG verification, secure-storage and transport review, and mobile malware triage for authorized assessments
marcosdeaza/claude-code-security-arsenal · ★ 0 · Testing & QA · score 66
Install: claude install-skill marcosdeaza/claude-code-security-arsenal
# Mobile Application Security ## Purpose Enable Claude to assess Android and iOS application security against the **OWASP MASVS** (Mobile Application Security Verification Standard) and execute tests from the **OWASP MASTG** (Mobile Application Security Testing Guide). Claude performs static analysis on APK/IPA artifacts, guides dynamic instrumentation (Frida/objection), reviews secure storage, transport, and platform-interaction controls, and triages potentially malicious mobile apps. > **Authorization Required**: Only test applications you own or are explicitly authorized to assess. Decompiling and modifying third-party apps may violate licenses and law. Confirm written scope before proceeding. --- ## Activation Triggers This skill activates when the user asks about: - Android (APK/AAB) or iOS (IPA) application security testing - OWASP MASVS / MASTG verification or a mobile pentest checklist - Decompiling, reversing, or static analysis of a mobile app - Insecure data storage, hardcoded secrets, or keystore/keychain review - Certificate pinning, SSL bypass, or mobile TLS/transport security - Frida / objection dynamic instrumentation or runtime hooking - `AndroidManifest.xml`, exported components, deep links, or `Info.plist` review - Mobile malware analysis or suspicious APK triage - Root/jailbreak detection, tampering, or anti-RE controls --- ## Prerequisites ```bash pip install requests pyaxmlparser ``` **Optional enhanced capabilities:** - `apktool` — APK decode/