All skills
hardw00t avatar

/ios-pentest

@f9bb3b2

iOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/ios-pentest

This session only. Nothing lands on disk.

workflowskeychain_extraction.md

≈462 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Keychain Extraction & Analysis

Extract

objection -g <bundle_id> explore
> ios keychain dump                       # human-readable table
> ios keychain dump --json > keychain.json

Triage Accessibility Attributes

Attribute Risk
kSecAttrAccessibleAlways CRITICAL — readable when device locked
kSecAttrAccessibleAlwaysThisDeviceOnly HIGH
kSecAttrAccessibleAfterFirstUnlock MEDIUM — persists after reboot
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly MEDIUM
kSecAttrAccessibleWhenUnlocked LOW
kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly BEST

Flag any sensitive item (JWT, refresh token, OAuth secret, encryption key, PII) at MEDIUM+ accessibility.

Confirm Biometric Gating

Look for kSecAttrAccessControl presence and flags: .biometryCurrentSet, .userPresence, .devicePasscode. Items lacking SecAccessControl with sensitive contents = finding.

Live Monitoring

objection -g <bundle_id> explore
> ios hooking watch class KeychainItemWrapper
> ios hooking watch class KeychainWrapper
> ios hooking watch method "+[KeychainService getItem:]" --dump-args --dump-return

Or Frida: frida -U <bundle_id> -l scripts/keychain_hooks.js.

Lock-screen Test

# Lock device, then from jailbroken SSH:
ssh root@<device> "ls /var/Keychains/"   # keychain DB presence
# Trigger the app (remote push / background fetch) and confirm whether it can still read items.

Evidence Fields

Populate evidence.keychain_dump (redact real secret values to last 4 chars) and affected.bundle_id, affected.ios_version. Map to MASTG-TEST-0011 / MASVS-STORAGE-1.

Source: SKILL.md on GitHub

2 alerts16d4 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    iOS penetration testing toolkit for security professionals. The skill provides methodologies, workflows, and Frida scripts for analyzing mobile applications on jailbroken or stock devices. It utilizes standard industry tools and well-known community repositories for its tasks.

  • Socket16d

    11 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    3/9 files flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/ios-pentest