All skills
hardw00t avatar

/android-pentest

@f9bb3b2

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest

This session only. Nothing lands on disk.

workflowsauth_testing.md

≈429 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Authentication & Session Testing

Maps to MASTG-TEST-0015/0016/0017. Requires SSL pinning already bypassed (see ssl_pinning_bypass.md).

1. Hook auth surface (parallel)

frida_hook_method(pid, "com.target.app.auth.AuthService", "login")
frida_hook_method(pid, "com.target.app.auth.TokenValidator", "validateToken")
frida_run_script(pid, "credential_hooks.js")

2. Biometric bypass

frida_run_script(pid, "biometric_bypass.js")
# Drive the biometric prompt; script forces CryptoObject success callback.

Checks: is success verified server-side, or only via local callback?

3. Session manipulation

frida_hook_method(pid, "com.target.app.session.SessionManager", "*")

Look for: local JWT expiry checks, refresh without server round-trip, tokens kept after logout.

4. JWT analysis

frida_run_script(pid, """
Java.perform(function() {
    var JWT = Java.use('com.auth0.jwt.JWT');
    JWT.decode.implementation = function(token) {
        console.log('[JWT] ' + token);
        return this.decode(token);
    };
});
""")

Decode output at jwt.io — flag HS256 with guessable secret, alg=none, missing exp/iat, sensitive claims (pw hash, full PII).

5. Credential storage

dump_shared_prefs("com.target.app")
dump_databases("com.target.app")

Look for plaintext tokens, password hints, PIN hashes, refresh tokens.

UI-driven flows

For OAuth redirects and multi-step MFA, use Mobile MCP get_screen_state + tap_element to drive the flow while hooks capture state transitions.

Reporting

Every finding: include MASTG ID, Frida PID, package, decoded JWT claims, and screenshot of the auth screen at point of bypass.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive environment and automated workflows for Android mobile application penetration testing. It interfaces with standard industry tools like ADB and Frida to perform security audits aligned with the OWASP MASTG methodology. While it performs sensitive operations like command execution and remote tool downloads, these are transparently implemented for its stated purpose using trusted sources.

  • Socket16d

    21 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/android-pentest