All skills
hardw00t avatar

/android-pentest

@f9bb3b2

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest

This session only. Nothing lands on disk.

templatesfinding_template.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Finding Template

Use this template to document individual vulnerabilities discovered during testing.


[FINDING-XXX] [Descriptive Title]

Metadata

Field Value
Finding ID FINDING-XXX
Severity Critical / High / Medium / Low / Informational
CVSS Score X.X
CVSS Vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Status Open / Remediated / Accepted Risk
Component [Affected component/file/function]
MASTG Reference MASTG-TEST-XXXX
CWE CWE-XXX ([CWE Name])
OWASP Mobile Top 10 M1-M10

Description

[Provide a clear, concise description of the vulnerability. Explain what the issue is and why it matters from a security perspective. This should be understandable by both technical and non-technical readers.]


Technical Details

[Provide detailed technical information about the vulnerability, including:

  • Exact location (file path, class name, method)
  • Vulnerable code or configuration
  • How the vulnerability was discovered
  • Technical root cause]

Affected Location:

/data/data/com.target.app/[path]

Vulnerable Code/Configuration:

// Example vulnerable code
public void storeCredentials(String password) {
    SharedPreferences prefs = getSharedPreferences("auth", MODE_PRIVATE);
    prefs.edit().putString("password", password).apply();  // Plaintext!
}

Steps to Reproduce

  1. [First step with exact commands/actions]
  2. [Second step]
  3. [Third step]
  4. [Observe the vulnerability]

Commands Used:

# MCP tool
dump_shared_prefs("com.target.app")

# or ADB
adb shell "su -c 'cat /data/data/com.target.app/shared_prefs/auth.xml'"

Frida Script (if applicable):

Java.perform(function() {
    // Hook code here
});

Evidence

Screenshot 1: [Description]

[Insert screenshot or reference to evidence file]

Log Output
[Relevant log output or tool output]
Request/Response (if applicable)
POST /api/login HTTP/1.1
Host: api.target.com
Content-Type: application/json

{"username": "test", "password": "test123"}

Impact

[Describe the potential impact of this vulnerability if exploited. Consider:

  • Confidentiality impact
  • Integrity impact
  • Availability impact
  • Business impact
  • Affected users/data]

Potential Attack Scenarios:

  1. Scenario 1: An attacker with physical device access could...
  2. Scenario 2: A malicious app on the same device could...
  3. Scenario 3: Through ADB backup, an attacker could...

Remediation

Recommended Fix

[Provide specific, actionable remediation steps]

  1. [First remediation step]
  2. [Second remediation step]
  3. [Third remediation step]
Secure Code Example
// Secure implementation
import androidx.security.crypto.EncryptedSharedPreferences;

public void storeCredentials(String token) {
    SharedPreferences prefs = EncryptedSharedPreferences.create(
        "auth_secure",
        MasterKeys.getOrCreate(MasterKeys.AES256_GCM_SPEC),
        context,
        EncryptedSharedPreferences.PrefKeyEncryptionScheme.AES256_SIV,
        EncryptedSharedPreferences.PrefValueEncryptionScheme.AES256_GCM
    );
    prefs.edit().putString("token", token).apply();
}
References

Timeline

Date Action
YYYY-MM-DD Vulnerability discovered
YYYY-MM-DD Reported to client
YYYY-MM-DD Remediation implemented
YYYY-MM-DD Fix verified

Notes

[Any additional notes, considerations, or context that may be helpful]


Severity Rating Guide

Severity CVSS Range Description
Critical 9.0 - 10.0 Direct system compromise, widespread impact
High 7.0 - 8.9 Significant security impact, data exposure
Medium 4.0 - 6.9 Moderate impact, requires specific conditions
Low 0.1 - 3.9 Minor impact, limited exposure
Info 0.0 Best practice recommendation

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive environment and automated workflows for Android mobile application penetration testing. It interfaces with standard industry tools like ADB and Frida to perform security audits aligned with the OWASP MASTG methodology. While it performs sensitive operations like command execution and remote tool downloads, these are transparently implemented for its stated purpose using trusted sources.

  • Socket16d

    21 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/android-pentest