All skills
hardw00t avatar

/android-pentest

@f9bb3b2

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest

This session only. Nothing lands on disk.

methodologyrecon.md

≈1.8k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Reconnaissance Methodology

Reconnaissance is the first phase of Android penetration testing. It involves gathering information about the target application, its components, permissions, and potential attack vectors.


Information Gathering

Application Metadata

# Using MCP tool
get_app_info("com.target.app")

This returns:

  • Package name
  • Version name and code
  • Target SDK version
  • Minimum SDK version
  • Permissions (declared and granted)
  • Signing certificate information
  • Application class
  • Debuggable flag
  • Backup flag

Manual Information Gathering

# Package information
adb shell dumpsys package com.target.app

# APK path
adb shell pm path com.target.app

# App permissions
adb shell dumpsys package com.target.app | grep -A 50 "requested permissions"

# Granted runtime permissions
adb shell dumpsys package com.target.app | grep -A 50 "runtime permissions"

# Signature information
adb shell dumpsys package com.target.app | grep -A 10 "Signatures"

Attack Surface Mapping

Exported Components

# Using MCP tool
list_exported_components("com.target.app")

This identifies:

  • Exported Activities: UI entry points accessible by other apps
  • Exported Services: Background components accessible externally
  • Exported Broadcast Receivers: Components that receive broadcasts
  • Content Providers: Data exposure points
  • Intent Filters: Registered intents and deep links

Manual Component Enumeration

# All activities
adb shell dumpsys package com.target.app | grep -E "Activity|activity" | grep -B1 "exported=true"

# All services
adb shell dumpsys package com.target.app | grep -E "Service|service" | grep -B1 "exported=true"

# All receivers
adb shell dumpsys package com.target.app | grep -E "Receiver|receiver" | grep -B1 "exported=true"

# All providers
adb shell dumpsys package com.target.app | grep -E "Provider|provider" | grep -B1 "exported=true"

# Intent filters
adb shell dumpsys package com.target.app | grep -A 10 "intent-filter"

Deep Link Discovery

# From AndroidManifest.xml (after decompilation)
grep -E "(scheme|host|path)" AndroidManifest.xml

# From app links
adb shell dumpsys package com.target.app | grep -A 5 "App Links"

# Test discovered deep links
adb shell am start -W -a android.intent.action.VIEW -d "scheme://host/path"

APK Extraction and Analysis

Extract APK

# Using MCP tool
pull_apk("com.target.app")

Manual Extraction

# Find APK path
APK_PATH=$(adb shell pm path com.target.app | sed 's/package://')

# Pull APK
adb pull $APK_PATH ./base.apk

# For split APKs (Android 5.0+)
adb shell pm path com.target.app  # Lists all splits
# Pull each split individually

APK Structure Analysis

# Unzip APK
unzip base.apk -d extracted/

# Key files to examine:
# - AndroidManifest.xml (binary, needs apktool)
# - classes.dex (Dalvik bytecode)
# - resources.arsc (compiled resources)
# - res/ (resources)
# - lib/ (native libraries)
# - assets/ (raw assets)
# - META-INF/ (signature information)

# Decode with apktool
apktool d base.apk -o decoded/

# Now AndroidManifest.xml is readable
cat decoded/AndroidManifest.xml

Permission Analysis

Dangerous Permissions

Permission Risk
READ_CONTACTS PII leakage
READ_CALL_LOG PII leakage
READ_SMS PII leakage, 2FA bypass
CAMERA Privacy violation
RECORD_AUDIO Privacy violation
ACCESS_FINE_LOCATION Tracking
READ_EXTERNAL_STORAGE Data access
WRITE_EXTERNAL_STORAGE Data tampering

Custom Permissions

# Check for custom permissions
grep "permission android:name" decoded/AndroidManifest.xml

# Check protection level
grep "protectionLevel" decoded/AndroidManifest.xml

# Vulnerable: signature permission without proper verification
# Vulnerable: normal/dangerous without runtime check

Third-Party Library Identification

Common Libraries to Identify

# Search in decompiled code
grep -rniE "(okhttp|retrofit|volley|gson|jackson|glide|picasso)" jadx_output/

# Check for analytics/tracking
grep -rniE "(firebase|analytics|crashlytics|facebook|appsflyer)" jadx_output/

# Check for ad networks
grep -rniE "(admob|mopub|unity|vungle|ironsource)" jadx_output/

# Check for payment libraries
grep -rniE "(stripe|braintree|paypal|adyen)" jadx_output/

Native Library Analysis

# List native libraries
ls -la extracted/lib/*/

# Check for known libraries
file extracted/lib/arm64-v8a/*.so

# Identify symbols
nm -D extracted/lib/arm64-v8a/*.so | head -50

# Check for security libraries
# libsqlcipher.so - encrypted database
# libssl.so - SSL/TLS
# libcrypto.so - cryptography

Certificate Analysis

Signing Certificate

# Using keytool
keytool -printcert -jarfile base.apk

# Using apksigner
apksigner verify --verbose --print-certs base.apk

# Check for debug certificate
keytool -printcert -jarfile base.apk | grep "CN=Android Debug"

Network Security Config

# Check if custom config exists
grep "networkSecurityConfig" decoded/AndroidManifest.xml

# Analyze config file
cat decoded/res/xml/network_security_config.xml

# Look for:
# - cleartext traffic allowed
# - custom trust anchors
# - certificate pinning

Reconnaissance Checklist

Application Information

  • Package name identified
  • Version information gathered
  • SDK levels documented
  • Permissions analyzed
  • Signing certificate examined
  • Debuggable flag checked
  • Backup flag checked

Attack Surface

  • Exported activities mapped
  • Exported services identified
  • Broadcast receivers listed
  • Content providers documented
  • Deep links discovered
  • Intent filters analyzed

Code Analysis Preparation

  • APK extracted
  • APK decompiled (apktool)
  • Code decompiled (jadx)
  • Native libraries identified
  • Third-party libraries listed
  • Obfuscation level assessed

Security Configuration

  • Network security config reviewed
  • Certificate pinning identified
  • Custom permissions analyzed
  • Protection levels verified

Output: Reconnaissance Report

# Reconnaissance Report

## Application Overview
- **Package**: com.target.app
- **Version**: 3.2.1 (Build 321)
- **Target SDK**: 33 (Android 13)
- **Min SDK**: 26 (Android 8.0)

## Attack Surface Summary
| Component Type | Count | Exported |
|---------------|-------|----------|
| Activities | 25 | 5 |
| Services | 8 | 2 |
| Broadcast Receivers | 12 | 3 |
| Content Providers | 4 | 1 |

## High-Risk Findings
1. Deep link handler without validation: `targetapp://`
2. Exported content provider: `content://com.target.app.provider`
3. Debug build flag: TRUE
4. Backup enabled: TRUE

## Permissions of Interest
- READ_CONTACTS
- READ_SMS
- ACCESS_FINE_LOCATION
- CAMERA

## Next Steps
1. Static analysis of deep link handler
2. Content provider access testing
3. Data storage review (backup exploit)
4. Permission abuse testing

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive environment and automated workflows for Android mobile application penetration testing. It interfaces with standard industry tools like ADB and Frida to perform security audits aligned with the OWASP MASTG methodology. While it performs sensitive operations like command execution and remote tool downloads, these are transparently implemented for its stated purpose using trusted sources.

  • Socket16d

    21 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/android-pentest