All skills
hardw00t avatar

/android-pentest

@f9bb3b2

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest

This session only. Nothing lands on disk.

methodologystatic_analysis.md

≈2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Static Analysis Methodology

Static analysis examines the application without executing it. This includes decompiling the APK, reviewing source code, identifying hardcoded secrets, and analyzing the security configuration.


APK Decompilation

Using apktool (Resources + Smali)

# Full decompilation
apktool d base.apk -o apktool_output/

# Key outputs:
# - AndroidManifest.xml (decoded)
# - res/ (decoded resources)
# - smali/ (Dalvik bytecode)

Using jadx (Java Source)

# Command line
jadx base.apk -d jadx_output/

# GUI for interactive analysis
jadx-gui base.apk

Using dex2jar + JD-GUI

# Convert DEX to JAR
d2j-dex2jar base.apk -o app.jar

# View in JD-GUI
jd-gui app.jar

AndroidManifest.xml Analysis

Critical Attributes

<!-- Debuggable - CRITICAL if true in production -->
<application android:debuggable="true">

<!-- Backup enabled - allows data extraction -->
<application android:allowBackup="true">

<!-- Clear text traffic - HTTP allowed -->
<application android:usesCleartextTraffic="true">

<!-- Exported without permission -->
<activity android:exported="true" android:name=".SensitiveActivity">

Component Security

# Find exported components without permissions
grep -B5 'android:exported="true"' AndroidManifest.xml | grep -v "permission"

# Find deep links
grep -A10 "<intent-filter>" AndroidManifest.xml | grep -E "(scheme|host|path)"

# Find custom permissions with weak protection
grep -A2 "<permission" AndroidManifest.xml | grep "protectionLevel"

Source Code Review

Hardcoded Secrets

# API keys and tokens
grep -rniE "(api[_-]?key|apikey|api_secret|client_secret)" jadx_output/ --include="*.java"
grep -rniE "(access[_-]?token|auth[_-]?token|bearer)" jadx_output/ --include="*.java"

# AWS keys
grep -rniE "AKIA[0-9A-Z]{16}" jadx_output/

# Private keys
grep -rniE "-----BEGIN (RSA |EC |DSA |OPENSSH )?PRIVATE KEY" jadx_output/

# Google API keys
grep -rniE "AIza[0-9A-Za-z\-_]{35}" jadx_output/

# Firebase
grep -rniE "firebase[a-z0-9-]+\.firebaseio\.com" jadx_output/

# Generic secrets
grep -rniE "(password|passwd|secret|credentials)\s*=\s*[\"'][^\"']+[\"']" jadx_output/

Insecure Cryptography

# Weak algorithms
grep -rniE "(DES|RC4|RC2|MD5|SHA1)[^a-zA-Z]" jadx_output/ --include="*.java"
grep -rni "DESede" jadx_output/

# ECB mode
grep -rni "AES/ECB" jadx_output/
grep -rni "DES/ECB" jadx_output/

# Hardcoded IVs
grep -rniE "IvParameterSpec.*new byte\[" jadx_output/

# Hardcoded keys
grep -rni "SecretKeySpec" jadx_output/ -A5

SQL Injection Vectors

# Raw queries
grep -rniE "(rawQuery|execSQL|compileStatement)" jadx_output/ --include="*.java"

# String concatenation in queries
grep -rniE "SELECT.*\+" jadx_output/ --include="*.java"
grep -rniE "INSERT.*\+" jadx_output/ --include="*.java"
grep -rniE "UPDATE.*\+" jadx_output/ --include="*.java"
grep -rniE "DELETE.*\+" jadx_output/ --include="*.java"

WebView Security

# JavaScript enabled
grep -rni "setJavaScriptEnabled(true)" jadx_output/

# JavaScript interface
grep -rni "addJavascriptInterface" jadx_output/

# File access
grep -rniE "(setAllowFileAccess|setAllowFileAccessFromFileURLs|setAllowUniversalAccessFromFileURLs)" jadx_output/

# Mixed content
grep -rni "setMixedContentMode" jadx_output/

Logging Sensitive Data

# Log statements
grep -rniE "Log\.(d|v|i|w|e)\(" jadx_output/ --include="*.java"

# Specific sensitive logging
grep -rniE "Log\..*password|Log\..*token|Log\..*key|Log\..*secret" jadx_output/

# System.out
grep -rni "System.out.print" jadx_output/

Insecure Data Storage

# SharedPreferences
grep -rni "getSharedPreferences" jadx_output/ -A2
grep -rni "MODE_WORLD_READABLE" jadx_output/
grep -rni "MODE_WORLD_WRITEABLE" jadx_output/

# External storage
grep -rniE "(getExternalStorageDirectory|getExternalFilesDir)" jadx_output/

# Temporary files
grep -rniE "(createTempFile|\.tmp)" jadx_output/

Certificate Pinning Implementation

# OkHttp pinning
grep -rni "CertificatePinner" jadx_output/

# Network Security Config
cat apktool_output/res/xml/network_security_config.xml

# Custom TrustManager
grep -rniE "(TrustManager|X509TrustManager)" jadx_output/
grep -rni "checkServerTrusted" jadx_output/

Root Detection

# Common root checks
grep -rniE "(isRooted|checkRoot|detectRoot)" jadx_output/
grep -rniE "/system/app/Superuser|/system/xbin/su|/sbin/su" jadx_output/
grep -rni "test-keys" jadx_output/

# RootBeer library
grep -rni "com.scottyab.rootbeer" jadx_output/

# SafetyNet
grep -rni "SafetyNet" jadx_output/

Native Library Analysis

Identify Native Functions

# List exported symbols
nm -D lib/arm64-v8a/libnative.so | grep " T "

# Find JNI functions
nm -D lib/arm64-v8a/libnative.so | grep "Java_"

# Check for dangerous functions
objdump -T lib/arm64-v8a/libnative.so | grep -E "system|exec|popen"

Ghidra Analysis

  1. Import native library into Ghidra
  2. Run auto-analysis
  3. Search for:
    • Hardcoded strings
    • Crypto function calls
    • Network operations
    • File operations
    • JNI method implementations

Resource Analysis

String Resources

# Search strings.xml
grep -rniE "(api|key|secret|password|token|url|endpoint)" apktool_output/res/values/strings.xml

Assets

# List assets
ls -la apktool_output/assets/

# Search for sensitive files
find apktool_output/assets/ -name "*.json" -o -name "*.xml" -o -name "*.pem" -o -name "*.p12"

# Check for embedded databases
find apktool_output/assets/ -name "*.db" -o -name "*.sqlite"

Automated Analysis Tools

MobSF (Mobile Security Framework)

# Run MobSF
docker run -it --rm -p 8000:8000 opensecurity/mobile-security-framework-mobsf

# Upload APK via web interface at http://localhost:8000

QARK (Quick Android Review Kit)

# Install
pip install qark

# Run analysis
qark --apk base.apk --report-type html

AndroBugs

# Run analysis
python androbugs.py -f base.apk

Static Analysis Checklist

Manifest Review

  • Debug flag checked
  • Backup flag checked
  • Clear text traffic flag checked
  • Exported components analyzed
  • Intent filters reviewed
  • Custom permissions examined
  • Network security config reviewed

Code Review

  • Hardcoded secrets searched
  • Insecure crypto identified
  • SQL injection vectors found
  • WebView security checked
  • Logging reviewed
  • Data storage analyzed
  • Certificate pinning reviewed
  • Root detection identified

Native Code

  • Native libraries identified
  • JNI functions mapped
  • Dangerous functions found
  • Hardcoded strings extracted

Resources

  • String resources checked
  • Assets analyzed
  • Embedded files identified

Output: Static Analysis Report

# Static Analysis Report

## Manifest Vulnerabilities
| Issue | Severity | Location |
|-------|----------|----------|
| android:debuggable="true" | Critical | AndroidManifest.xml |
| android:allowBackup="true" | High | AndroidManifest.xml |
| Exported activity without permission | High | .DeepLinkActivity |

## Hardcoded Secrets
| Secret Type | File | Line |
|-------------|------|------|
| AWS Access Key | Config.java | 45 |
| API Key | Constants.java | 12 |

## Insecure Cryptography
| Issue | File | Line |
|-------|------|------|
| DES encryption | CryptoUtil.java | 78 |
| ECB mode | EncryptionHelper.java | 34 |
| Hardcoded IV | SecurityManager.java | 56 |

## SQL Injection Vectors
| Method | File | Line |
|--------|------|------|
| rawQuery with concatenation | DBHelper.java | 102 |

## WebView Vulnerabilities
| Issue | File | Line |
|-------|------|------|
| JavaScript enabled | WebViewActivity.java | 25 |
| addJavascriptInterface | WebViewActivity.java | 30 |
| setAllowFileAccessFromFileURLs | WebViewActivity.java | 35 |

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive environment and automated workflows for Android mobile application penetration testing. It interfaces with standard industry tools like ADB and Frida to perform security audits aligned with the OWASP MASTG methodology. While it performs sensitive operations like command execution and remote tool downloads, these are transparently implemented for its stated purpose using trusted sources.

  • Socket16d

    21 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/android-pentest