All skills
hardw00t avatar

/android-pentest

@f9bb3b2

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest

This session only. Nothing lands on disk.

referencestroubleshooting.md

≈676 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Troubleshooting

Common failures during Android pentests and minimum-fix recipes.

Frida

"Failed to spawn: unable to find application"

Verify the exact package name.

adb shell pm list packages | grep <partial>
# or
list_installed_apps()  # MCP

"Failed to attach: process not found"

App isn't running — use frida_spawn(pkg) instead of frida_attach(pkg).

"Script terminated with error" — class/method not found

Likely obfuscation (class names become a, b, c…).

frida_enumerate_classes(pid, "*TargetClass*")

Cross-reference jadx decompile to locate the renamed class.

Frida server crashes or version mismatch

frida --version  # client version
# Download matching frida-server from github.com/frida/frida/releases
adb push frida-server /data/local/tmp/ && adb shell "su -c chmod 755 /data/local/tmp/frida-server"

SSL pinning

Universal bypass does nothing

Custom pinner — decompile APK, search for certificate/pin/ssl/trust, then write a targeted hook. See workflows/ssl_pinning_bypass.md Method 2.

App still fails after bypass

Multiple pinning layers:

  1. Native SSL verification in libssl.so — use Method 3 (SSL_CTX_set_custom_verify).
  2. Frida-detection: run anti_tampering_bypass.js first.
  3. Try objection -g <pkg> explore → android sslpinning disable.
  4. Consider embedding frida-gadget in the APK.

Root detection

App exits on launch with "rooted device"

frida_run_script(pid, "root_bypass.js")

Additional layers:

  • Enable Magisk Hide / Zygisk DenyList for the package.
  • Native root checks → hook fopen, access, stat from libc.
  • Frida-gadget embedded in the APK for persistent injection.

App detects Frida itself

  • Apply anti_tampering_bypass.js before other scripts.
  • Rename the frida-server binary on device.
  • Hook pthread_create to hide Frida threads.

ADB

"device unauthorized"

adb kill-server && adb start-server
# then accept the RSA key prompt on device

"Permission denied" reading app data

adb root                         # userdebug builds only
adb shell su -c "cat /data/data/<pkg>/..."  # rooted production devices

Data extraction

SQLCipher-encrypted database

Capture the passphrase at open time:

frida_hook_method(pid, "net.sqlcipher.database.SQLiteDatabase", "openOrCreateDatabase")

Or scan memory for PRAGMA key strings:

frida_memory_search(pid, "PRAGMA key")

Files exist but are zero bytes after pull

Scoped storage (Android 10+) — use adb shell run-as <pkg> cat <path> on debuggable builds, or adb shell su -c cat on rooted devices.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive environment and automated workflows for Android mobile application penetration testing. It interfaces with standard industry tools like ADB and Frida to perform security audits aligned with the OWASP MASTG methodology. While it performs sensitive operations like command execution and remote tool downloads, these are transparently implemented for its stated purpose using trusted sources.

  • Socket16d

    21 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/android-pentest