All skills
hardw00t avatar

/android-pentest

@f9bb3b2

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest

This session only. Nothing lands on disk.

checklistsreport_items.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Report Items Checklist

Ensure all required items are included in the penetration test report.


Executive Summary Items

  • Overall security posture assessment
  • Critical and high findings count
  • Key risk areas identified
  • Immediate action items
  • Comparison to industry standards (if applicable)
  • Testing scope summary
  • Testing timeline

Methodology Section

  • Testing approach described
  • Tools and techniques listed
  • OWASP MASTG reference
  • Test coverage summary
  • Limitations and exclusions

Findings Documentation

For Each Finding Include:

  • Unique finding ID
  • Descriptive title
  • Severity rating (Critical/High/Medium/Low/Info)
  • CVSS score (optional)
  • Affected component/location
  • Description of vulnerability
  • Technical details
  • Steps to reproduce
  • Evidence (screenshots, logs, code snippets)
  • Impact statement
  • Remediation recommendation
  • OWASP MASTG reference
  • CWE reference

Finding Template

## [FINDING-001] Sensitive Data in Plaintext SharedPreferences

**Severity**: High
**CVSS**: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
**Location**: /data/data/com.target.app/shared_prefs/auth.xml
**MASTG**: MASTG-TEST-0001
**CWE**: CWE-312 (Cleartext Storage of Sensitive Information)

### Description
Authentication tokens are stored in plaintext in SharedPreferences,
allowing any application with root access or backup capability to
extract user credentials.

### Technical Details
The application stores JWT authentication tokens in SharedPreferences
without encryption:
- File: auth_prefs.xml
- Key: auth_token
- Value: eyJhbGciOiJIUzI1NiIs...

### Steps to Reproduce
1. Install application and log in
2. Run: adb shell "su -c 'cat /data/data/com.target.app/shared_prefs/auth.xml'"
3. Observe plaintext token in output

### Evidence
[Screenshot or code snippet]

### Impact
An attacker with device access or backup capability can:
- Extract authentication tokens
- Impersonate users
- Access sensitive account data

### Remediation
1. Use Android Keystore for sensitive data storage
2. Implement EncryptedSharedPreferences
3. Set tokens to expire after reasonable period

Evidence Requirements

Screenshots

  • Application version/info screen
  • Vulnerable configuration
  • Exploitation proof
  • Sensitive data exposure
  • Error messages

Technical Evidence

  • HTTP requests/responses
  • Frida script output
  • Log entries
  • Database contents
  • File contents
  • Code snippets (decompiled)

Video (if applicable)

  • Complex exploitation steps
  • Time-sensitive vulnerabilities
  • Authentication bypass

Severity Classification

Use Consistent Ratings

Severity Description Examples
Critical Remote compromise, data breach RCE, SQL injection, hardcoded keys
High Significant security impact Auth bypass, plaintext credentials
Medium Moderate security risk Missing pinning, weak crypto
Low Minor security issues Missing headers, info disclosure
Info Best practice recommendations Obfuscation suggestions

Risk Assessment

  • Overall risk rating
  • Business impact analysis
  • Likelihood assessment
  • Risk matrix included

Risk Matrix

Impact
High    | Medium | High    | Critical
Medium  | Low    | Medium  | High
Low     | Info   | Low     | Medium
        +--------------------------
          Low     Medium    High
                Likelihood

Remediation Section

For Each Finding

  • Specific fix recommendation
  • Code examples (if applicable)
  • Reference documentation
  • Priority/timeline suggestion

Overall Recommendations

  • Short-term fixes (critical issues)
  • Medium-term improvements
  • Long-term security enhancements
  • Security awareness recommendations

Appendices

Required Appendices

  • Appendix A: Tool list and versions
  • Appendix B: Testing timeline
  • Appendix C: Raw evidence (if separate)
  • Appendix D: OWASP MASTG mapping
  • Appendix E: Glossary

Optional Appendices

  • Full Frida scripts used
  • Complete HTTP traffic logs
  • Database dumps (sanitized)
  • Decompiled code excerpts

Quality Checks

Before Submission

  • All findings have complete documentation
  • Screenshots are clear and annotated
  • Technical accuracy verified
  • Grammar and spelling checked
  • Sensitive data redacted appropriately
  • Client information accurate
  • Page numbers and TOC updated
  • Report reviewed by peer (if applicable)

Sensitive Data Handling

  • Test credentials redacted
  • Personal data anonymized
  • API keys/tokens masked
  • Internal IPs/hostnames sanitized

Report Deliverables

Primary Deliverables

  • Executive Summary (PDF)
  • Technical Report (PDF)
  • Finding Spreadsheet (Excel/CSV)

Supporting Materials

  • Evidence archive (ZIP)
  • Remediation guide
  • Presentation slides (if required)

Finding Categories Summary

Ensure findings are categorized properly:

MASVS-STORAGE

  • Insecure data storage findings
  • Backup vulnerabilities
  • Logging issues

MASVS-CRYPTO

  • Weak cryptography
  • Key management issues
  • Random number issues

MASVS-AUTH

  • Authentication bypass
  • Session management
  • Biometric issues

MASVS-NETWORK

  • Cleartext traffic
  • TLS configuration
  • Certificate pinning

MASVS-PLATFORM

  • IPC vulnerabilities
  • WebView issues
  • Deep link issues

MASVS-CODE

  • Debug configuration
  • Code quality issues
  • Reverse engineering

Sign-Off

  • Technical reviewer sign-off
  • Quality assurance review
  • Final approval
  • Client delivery confirmed

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive environment and automated workflows for Android mobile application penetration testing. It interfaces with standard industry tools like ADB and Frida to perform security audits aligned with the OWASP MASTG methodology. While it performs sensitive operations like command execution and remote tool downloads, these are transparently implemented for its stated purpose using trusted sources.

  • Socket16d

    21 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/android-pentest