All skills
hardw00t avatar

/android-pentest

@f9bb3b2

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest

This session only. Nothing lands on disk.

templatesexecutive_summary.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Executive Summary Template

Android Application Security Assessment

[Application Name] - Executive Summary


Document Information

Field Value
Client [Client Name]
Application [Application Name]
Package [com.example.app]
Version [X.X.X]
Assessment Date [Start Date] - [End Date]
Report Date [Report Date]
Prepared By [Tester Name / Company]
Classification Confidential

Overview

[Organization Name] engaged [Security Firm] to perform a security assessment of the [Application Name] Android mobile application. The assessment was conducted between [Start Date] and [End Date] and evaluated the application against OWASP Mobile Application Security Testing Guide (MASTG) standards.


Security Posture

Overall Rating: [Critical / High / Medium / Low Risk]

[Provide a 2-3 sentence summary of the overall security posture. Is the application secure enough for production use? What are the main concerns?]

Risk Distribution

Severity Count Percentage
Critical X XX%
High X XX%
Medium X XX%
Low X XX%
Informational X XX%
Total X 100%

Key Findings Summary

Critical Issues

  1. [Finding Title] - [One-line description and impact]
  2. [Finding Title] - [One-line description and impact]

High-Priority Issues

  1. [Finding Title] - [One-line description and impact]
  2. [Finding Title] - [One-line description and impact]
  3. [Finding Title] - [One-line description and impact]

Risk Areas

Data Protection

[Summary of data storage and protection findings]

  • Status: [Adequate / Needs Improvement / Critical Gaps]

Authentication & Session Management

[Summary of authentication findings]

  • Status: [Adequate / Needs Improvement / Critical Gaps]

Network Security

[Summary of network/transport security findings]

  • Status: [Adequate / Needs Improvement / Critical Gaps]

Platform Security

[Summary of platform interaction findings]

  • Status: [Adequate / Needs Improvement / Critical Gaps]

Cryptography

[Summary of cryptographic implementation findings]

  • Status: [Adequate / Needs Improvement / Critical Gaps]

Immediate Action Required

The following issues require immediate attention before the application should be used in production:

  1. [Critical Finding] - [Action needed]
  2. [Critical Finding] - [Action needed]
  3. [High Finding] - [Action needed]

Positive Observations

The assessment also identified the following security strengths:

  • [Positive finding 1]
  • [Positive finding 2]
  • [Positive finding 3]

Recommendations Summary

Short-Term (0-30 days)

  • Remediate all Critical findings
  • Address High-priority authentication issues
  • Remove debug flags from production build

Medium-Term (30-90 days)

  • Implement certificate pinning
  • Encrypt all local data storage
  • Review and restrict exported components

Long-Term (90+ days)

  • Implement comprehensive security monitoring
  • Establish security testing in CI/CD pipeline
  • Conduct periodic security assessments

Scope Summary

In Scope

  • [Application Name] Android application version [X.X.X]
  • All application functionality
  • Local data storage
  • Network communications
  • [Additional scope items]

Out of Scope

  • Backend API infrastructure
  • iOS application
  • Third-party integrations
  • [Additional exclusions]

Testing Methodology

The assessment was performed using the following methodology:

  • Static Analysis: Review of decompiled application code
  • Dynamic Analysis: Runtime testing with Frida instrumentation
  • Network Analysis: Traffic interception and API testing
  • Data Analysis: Review of local storage and databases
  • Component Testing: Testing of exported Android components

Reference: OWASP Mobile Application Security Testing Guide (MASTG)


Conclusion

[Provide a concluding paragraph summarizing:

  • Overall security state
  • Most significant risks
  • Recommendation for production readiness
  • Next steps]

Contact Information

For questions regarding this assessment:

[Security Firm Name]


This document contains confidential security information and should be handled appropriately.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive environment and automated workflows for Android mobile application penetration testing. It interfaces with standard industry tools like ADB and Frida to perform security audits aligned with the OWASP MASTG methodology. While it performs sensitive operations like command execution and remote tool downloads, these are transparently implemented for its stated purpose using trusted sources.

  • Socket16d

    21 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/android-pentest