All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

referencesios_vulns.md

≈601 tokens on demand. Your agent reads this file only when SKILL.md points to it.

iOS-Specific Vulnerability Reference

1. Keychain Misconfigurations (MASVS-STORAGE-1)

Flag Severity
kSecAttrAccessibleAlways CRITICAL
kSecAttrAccessibleAlwaysThisDeviceOnly HIGH
kSecAttrAccessibleAfterFirstUnlock MEDIUM
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly MEDIUM
kSecAttrAccessibleWhenUnlocked LOW
kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly BEST
Missing kSecAttrAccessControl on sensitive items (tokens, keys) = finding.

2. Data Protection Classes (MASVS-STORAGE-2)

  • NSFileProtectionComplete — expected for sensitive files.
  • NSFileProtectionCompleteUntilFirstUserAuthentication — acceptable for many cases but persists post-boot.
  • NSFileProtectionCompleteUnlessOpen — fine for files held open across lock.
  • NSFileProtectionNone — vulnerable for sensitive data.

3. IPC Vulnerabilities (MASVS-PLATFORM)

  • URL Scheme hijacking — attacker app claims the same scheme; without Universal Links the OS may route to the wrong app.
  • Universal Links — validate apple-app-site-association JSON; missing paths allowlist widens attack.
  • App Extensions — shared NSUserDefaults / App Group containers may leak across extensions.
  • Custom pasteboards — prefer named pasteboard over general.

4. Binary Protections (MASVS-CODE)

Expect all of: PIE, ARC, stack canaries, code signing valid, (App Store) encrypted. Missing any → lower-severity finding with cumulative scoring.

5. ATS & Network (MASVS-NETWORK)

NSAllowsArbitraryLoads=YES, per-domain insecure exceptions, TLS < 1.2, no pinning for highly sensitive apps.

6. Logging & Backup (MASVS-STORAGE / PRIVACY)

  • NSLog of tokens/PII in release.
  • Files in Documents/ without skipBackup attribute may reach iCloud.
  • Crash reports may contain sensitive stack state — strip via CocoaLumberjack formatter / Sentry scrubbers.

References

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest