All skills
hardw00t avatar

/android-pentest

@f9bb3b2

Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/android-pentest

This session only. Nothing lands on disk.

workflowsdata_exfiltration.md

≈497 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Data Storage & Exfiltration Analysis

Maps to MASTG-TEST-0001 / 0002 / 0003. Confirm what leaves the sandbox and what's readable without root.

1. Full dump (parallel)

dump_databases("com.target.app")
dump_shared_prefs("com.target.app")
dump_internal_storage("com.target.app")
dump_external_storage("com.target.app")
get_logcat("com.target.app")

2. Sensitive-data grep

Search all dumped artifacts for: token, bearer, password, api_key, secret, jwt, -----BEGIN, SSN regex, PAN regex (\b(?:\d[ -]*?){13,16}\b), email regex.

3. Real-time write monitoring

frida_run_script(pid, """
Java.perform(function() {
    var Editor = Java.use('android.app.SharedPreferencesImpl$EditorImpl');
    Editor.putString.implementation = function(key, value) {
        console.log('[PREFS] ' + key + ' = ' + value);
        return this.putString(key, value);
    };
});
""")

4. External storage exposure

External paths (/sdcard/Android/data/...) are world-readable on pre-scoped-storage targets and readable by any app with READ_EXTERNAL_STORAGE on Android ≤ 10. Flag any credential/token/financial doc found there.

5. Backup & debuggable flags

From the manifest (via get_app_info): flag android:allowBackup=true and android:debuggable=true.

adb backup -apk -noshared com.target.app  # if allowBackup=true

6. SQLCipher-encrypted DBs

If dump_databases returns unreadable blobs, hook the open call:

frida_hook_method(pid, "net.sqlcipher.database.SQLiteDatabase", "openOrCreateDatabase")
frida_memory_search(pid, "PRAGMA key")

Typical findings table

Location Sensitive data → Severity
SharedPreferences plaintext auth_token / refresh_token → HIGH
Unencrypted SQLite balances, transactions → HIGH
/files/*.json PII (email, phone, SSN4) → MEDIUM
/sdcard/Android/data statements, exports → MEDIUM
logcat token/password echo → HIGH

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive environment and automated workflows for Android mobile application penetration testing. It interfaces with standard industry tools like ADB and Frida to perform security audits aligned with the OWASP MASTG methodology. While it performs sensitive operations like command execution and remote tool downloads, these are transparently implemented for its stated purpose using trusted sources.

  • Socket16d

    21 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/android-pentest