World-class Android pentesting skill for AI agents. It combines static analysis, dynamic instrumentation, RASP detection, authorized bypass validation, source-to-sink tracing, MASVS scoring, and professional reporting in one DRY workflow.
This skill turns an AI agent into an Android APK security auditor. It can:
- Decode and inspect APKs with APKTool, JADX, APKiD, Android SDK tools, and Frida.
- Map attack surface: manifest, exported components, deep links, WebViews, storage, crypto, networking, native code, and framework-specific code.
- Run static analysis with curated grep patterns and MASTG-aligned Semgrep rules, then merge and deduplicate findings.
- Trace source-to-sink flows and separate confirmed issues from findings that need dynamic validation.
- Detect runtime defenses and RASP/shielding SDKs, then build authorized Frida bypass stacks using reusable profiles instead of duplicated logic.
- Validate common client-side protections such as SSL pinning, root/debug/emulator checks, anti-Frida, FLAG_SECURE, RASP callbacks, and packer/native checks where technically feasible.
- Score and report findings with CVSS 4.0, MASVS mapping, executive risk context, JSON schemas, and professional report templates.
- Support APK modification workflows: smali/resource patching, repackaging, signing, and validation.
- Ingest APKs from a read-only Gmail mailbox (optional OAuth adapter) and audit on-device
/data/datastorage on rooted lab devices.
Important: Client-side hooks do not forge server-side attestation verdicts. For Approov, Play Integrity, SafetyNet, or similar backend-enforced controls, use an authorized test tenant, backend allowlist, mock verifier, or approved lab configuration.
# For Claude Code / OpenCode agents
cd ~/.agents/skills/
git clone https://github.com/DragonJAR/Android-Pentesting-Skill Android-Pentesting-Skill
# For other agents, place in your skills directory# Clone to any location
git clone https://github.com/DragonJAR/Android-Pentesting-Skill.git
# Add to your agent's skill path configurationThe skill expects these tools to be installed:
| Tool | Version | Purpose |
|---|---|---|
| APKTool | 3.0.1+ | APK decoding/rebuilding (aapt2-only mode) |
| JADX | 1.5.5+ | Java/Kotlin decompilation |
| Android SDK | Platform 36+, Build 36+ | adb, aapt2, zipalign, apksigner |
| Frida | 17.9+ | Dynamic instrumentation |
| Objection | 1.12.4+ | Mobile exploration (maintenance mode) |
| APKiD | 3.0.0+ | Framework detection |
Run the Python preflight check to verify all dependencies:
python3 scripts/06-setup/preflight-check.pyShell variant for Linux or macOS with Homebrew Bash 4+:
/opt/homebrew/bin/bash scripts/06-setup/preflight-check.shOr, on systems where /usr/bin/env bash is Bash 4+:
./scripts/06-setup/preflight-check.shPowerShell variant for Windows environments:
./scripts/06-setup/preflight-check.ps1The RASP workflow is intentionally DRY:
- Detect protections with RDA.
- Map triggered detectors to bypass profiles.
- Reuse existing Frida scripts from
assets/frida-scripts/. - Print first, run only when authorized with
--run --authorized-lab.
# 1) Detect RASP/runtime defenses
bash scripts/02-rasp/runtime-defense-analyzer.sh app.apk com.target.app --output findings-rda.json
# 2) Review available bypass profiles
bash scripts/02-rasp/rasp-bypass-runner.sh --list-profiles
# 3) Generate a reviewed Frida command from findings
bash scripts/02-rasp/rasp-bypass-runner.sh \
--package com.target.app \
--from-rda findings-rda.json \
--print-command
# 4) Execute only in an authorized lab
bash scripts/02-rasp/rasp-bypass-runner.sh \
--package com.target.app \
--from-rda findings-rda.json \
--run --authorized-labProfiles live in scripts/02-rasp/bypass-profiles.json and reuse existing Frida scripts under assets/frida-scripts/. See references/rasp-bypass-workflow.md for coverage, limits, and reporting requirements.
User prompt:
Audit this APK: /path/to/app.apk
Agent response:
I'll analyze the APK for security vulnerabilities.
[Phase 0] Decoding APK with APKTool...
[Phase 1] Analyzing AndroidManifest.xml...
[Phase 2] Running targeted security patterns...
[Phase 3] Tracing data flows...
[Phase 5] Generating findings report...
Found 3 issues:
1. [HIGH] Exported Activity Without Permission (M8: Security Misconfiguration)
2. [MEDIUM] Hardcoded API Key (M1: Improper Credential Usage)
3. [LOW] Debug Logging Enabled (M8: Security Misconfiguration)
User prompt:
Audit this APK with all modules: runtime defense, semgrep, and MASVS scoring.
Agent response:
[Phase 0] Decoding APK with APKTool + JADX...
[Phase 0] Detected framework: Flutter
[Phase 1] Mapping attack surface from AndroidManifest.xml...
[Phase 2] Running targeted grep patterns...
[Phase 2.5] Running Semgrep MASTG rules (70+ rules)...
[Phase 3] Tracing source-to-sink data flows...
[Phase 4] Running Runtime Defense Analysis (18 catalog entries, 14 executable detectors)...
[Phase 5] Classifying findings and calculating MASVS compliance score...
MASVS Score: 72.6/100 (Grade: C)
- 16/23 controls passed
- 7 controls failed (Critical: 1, High: 1, Medium: 1, Low: 4)
Found 4 issues:
1. [CRITICAL] Hardcoded API Key (M1: Improper Credential Usage)
2. [HIGH] Exported Activity with Intent Redirection (M8: Security Misconfiguration)
3. [MEDIUM] Weak SSL Certificate Validation (M5: Insecure Communication)
4. [LOW] Debug Mode Enabled (M8: Security Misconfiguration)
User prompt:
The app has SSL pinning. Bypass it with Frida and intercept traffic.
Agent response:
I'll use the SSL pinning bypass script to intercept HTTPS traffic.
[1] Identifying SSL pinning implementation...
Found: OkHttp3 CertificatePinner
[2] Loading Frida script: ssl-pinning-bypass.js
[3] Hooking CertificatePinner.check()
[4] SSL pinning bypassed. Traffic now decrypted.
Intercepted request:
POST /api/login
{"email": "user@example.com", "password": "secret123"}
User prompt:
Analyze this React Native APK for hardcoded secrets in the JavaScript bundle.
Agent response:
[Phase 0] Detected React Native framework (libhermes.so found)
[Phase 0] Extracting JavaScript bundle from assets/index.android.bundle
[Phase 2] Scanning for secrets in JavaScript bundle...
Found 2 hardcoded secrets:
- API_KEY = "sk_live_abc123..." at bundle.js:4521 (M1: Improper Credential Usage)
- AWS_SECRET = "wJalrXUtnFEMI/K7MDENG..." at bundle.js:8912 (M1: Improper Credential Usage)
User prompt:
Analyze this Flutter APK. I need to intercept HTTPS traffic from the app.
Agent response:
[Phase 0] Detected Flutter framework (libflutter.so found)
[Phase 0] Flutter uses BoringSSL natively - Java SSL hooks won't work
[Phase 0] Using Blutter to extract Dart code: python3 blutter.py lib/arm64-v8a/
[Phase 4] Loading Frida script: native-hook.js (BoringSSL targets)
[Phase 4] Hooking SSL_CTX_set_custom_verify() for certificate bypass
[Phase 4] Hooking SSL_read/SSL_write() for traffic interception
Flutter traffic now intercepted and decrypted.
User prompt:
Disable the root detection in this APK and repackage it.
Agent response:
[1] Decoding APK with APKTool...
[2] Locating root detection code...
Found: com/app/security/RootDetector.checkRoot()
[3] Patching smali to return false...
const/4 v0, 0x0 # Always return false
[4] Rebuilding with APKTool...
[5] Aligning with zipalign...
[6] Signing with apksigner...
[7] Verifying signature...
Modified APK ready: app_patched.apk
SHA-256: abc123def456...
User prompt:
Run the runtime defense analysis to check what protections this app has.
Agent response:
[Phase 4] Loading Runtime Defense Analysis...
Detector catalog: 18 entries (14 executable Frida detectors + 4 backend/cloud entries marked not applicable).
Executable detectors include:
- rootbeer, safetynet, emulator, debug, frida_detect
- screenshot, screenrecorded, custom
- talsec, approov, dexguard, appdome, doverunner, digitalai
Running passive detection...
Results: 3 protections detected:
- [DETECTED] Root detection (RootBeer library)
- [DETECTED] Emulator detection
- [NOT DETECTED] Frida detection
findings-rda.json generated with full detector report.
| Capability | Description |
|---|---|
| APK Decompilation | JADX for Java/Kotlin, APKTool for smali/resources |
| Framework Detection | React Native, Flutter, Cordova, Xamarin, Native |
| Obfuscation Analysis | ProGuard/R8, DexGuard, custom patterns |
| Manifest Analysis | 50+ security checks for exported components, permissions, deep links |
| IPC / Intent Abuse | Intent injection, nested intent relays, PendingIntent, FileProvider, deep link pivot patterns |
| Secrets Detection | API keys, passwords, tokens in code and resources |
| Data Flow Tracing | Source-to-sink methodology with confidence levels |
| Semgrep SAST (Phase 2.5) | 70+ MASTG-aligned rules for automated code scanning |
| Capability | Description |
|---|---|
| Frida Scripts | 37 scripts for hooking, bypass, interception, and native triage |
| SSL Pinning Bypass | Java/Conscrypt focused (HttpsURLConnection, TrustManagerImpl etc.). See script header for exact current coverage and gaps (OkHttp, WebView, NSC, Flutter require extra work). |
| Root Detection Bypass | 30+ root packages, 80+ paths, native hooks (fopen, access, stat) plus a focused native root detection probe |
| Runtime Defense Analysis (RDA) | 18 catalog entries, 14 executable Frida detectors, and authorized bypass profile runner |
| Crypto Interception | Monitor Cipher, MessageDigest, Mac, Signature operations |
| Biometric Bypass | BiometricPrompt, FingerprintManager, crypto-object binding |
| Keystore Inspection | List entries, extract metadata, check security flags |
| Network Interception | OkHttp chains, HttpURLConnection, WebSocket monitoring |
| Native Hooking | JNI_OnLoad, RegisterNatives, by-offset hooks, and library-load-aware native probes |
# List available bundled scripts
python3 scripts/07-tools/frida-exploit-helper.py --list-scripts
# Hook memory functions
python3 scripts/07-tools/frida-exploit-helper.py -p com.target.app --hook malloc,free
# Use bundled SSL pinning bypass script
python3 scripts/07-tools/frida-exploit-helper.py -p com.target.app --script ssl-pinning-bypass
# Memory layout analysis
python3 scripts/07-tools/frida-exploit-helper.py -p com.target.app --layout
# Runtime Defense Analysis (RDA) β detect app protections
python3 scripts/07-tools/frida-exploit-helper.py -p com.target.app --runtime-defense# Run static audit with Semgrep enrichment
bash scripts/auto-audit-static.sh app.apk --semgrep
# Run runtime defenses and scoring as explicit modules
bash scripts/02-rasp/runtime-defense-analyzer.sh app.apk com.target.app --active-mode --authorized-lab --output findings-rda.json
python3 scripts/03-static-analysis/semgrep-scan.py decoded/ --output semgrep.json
python3 scripts/05-scoring/calculate-score.py findings.json --json-output| Capability | Description |
|---|---|
| Smali Patching | Modify Dalvik bytecode directly |
| Resource Editing | Change XML, strings, configurations |
| Static Pinning Tampering | Override network_security_config, replace pins, bundled certs, or BKS/JKS truststores |
| Repackaging | Rebuild, align, sign with correct flow: zipalign β apksigner |
| Capability | Description |
|---|---|
| CVSS 4.0 Scoring | FIRST.org compliant severity ratings |
| MASVS Compliance Score | OWASP MASVS v2 control coverage with explicit pass/fail/not-tested semantics |
| Executive Risk Score | Optional aggregate 0-100/A-F business-risk summary, separate from CVSS and MASVS |
| OSINT Enrichment | Optional passive correlation of package, domains, endpoints, public leaks, and archived URLs |
| Audit Modes | Presets for quick, static, full, protected-app, OSINT, and reporting-only workflows |
| OWASP MASTG Mapping | Test IDs and MASVS categories |
| Professional Templates | Executive summary, findings, remediation |
Android-Pentesting-Skill/
βββ SKILL.md # Skill definition (Phases 0-5)
βββ references/ # 90 reference/support files
β βββ attack-patterns.md # OWASP M1-M10 patterns
β βββ intent-injection.md # Nested intent / confused deputy guide
β βββ pendingintent-security.md # PendingIntent abuse and hardening
β βββ dynamic-analysis-setup.md # Frida/Objection + SSL pinning playbook
β βββ frida-scripts-index.md # Canonical bundled script catalog
β βββ cvss-scoring-guide.md # CVSS 4.0 methodology
β βββ reporting-templates.md # Finding templates
β βββ flutter-security.md # Flutter security guide
β βββ react-native-security.md # React Native security guide
β βββ android-keystore2-testing.md # Keystore2 testing (Android 12+)
β βββ biometric-testing-comprehensive.md # BiometricPrompt testing
β βββ deep-link-exploitation.md # Deep link attacks
β βββ project-manifest.md # Ground-truth file inventory
β βββ ... (77 more)
βββ assets/frida-scripts/ # 38 files (37 Frida scripts + README)
β βββ ssl-pinning-bypass.js # SSL pinning bypass
β βββ root-detection-bypass.js # Root detection bypass
β βββ native-root-detection-probe.js # Focused native root/RASP triage
β βββ native-hook.js # Generic JNI / native helper
β βββ biometric-bypass.js # Biometric auth bypass
β βββ network-interceptor.js # HTTP/HTTPS interception
β βββ crypto-intercept.js # Crypto operations hooking
β βββ ... (30 more)
βββ scripts/ # Utility and validation scripts
β βββ 00-ingestion/ # Optional input adapters (Gmail APK fetch)
β β βββ fetch-apk-gmail.py # Read-only Gmail β APK attachment ingester
β βββ 01-cross-platform/ # Framework-specific analysis
β β βββ cordova-analysis.sh
β β βββ flutter-analysis.sh
β β βββ react-native-analysis.sh
β β βββ unity-analysis.sh
β β βββ dotnet-maui-analysis.sh # MAUI / Xamarin: managed DLL extraction + decompilation
β βββ 02-rasp/ # Runtime Defense Analysis (RDA)
β β βββ detector-catalog.json # 18 detector registry
β β βββ runtime-defense-analyzer.sh # Phase 4 RDA entry point
β β βββ rasp-bypass-runner.sh # Authorized bypass stack runner
β β βββ bypass-profiles.json # DRY detector-to-bypass profile map
β β βββ findings-schema.json # Shared findings schema
β β βββ rasp-detectors/ # 14 Frida detector scripts + 4 not-applicable catalog entries
β β βββ rootbeer.js
β β βββ safetynet.js
β β βββ emulator.js
β β βββ debug.js
β β βββ frida-detect.js
β β βββ screenshot.js
β β βββ screenrecorded.js
β β βββ custom.js
β βββ 03-static-analysis/ # Semgrep SAST + merge
β β βββ semgrep-scan.py # semgrep wrapper
β β βββ merge-findings.py # Deduplication
β β βββ update-rules.sh # Upstream rule sync
β β βββ advanced-static-checks.sh # Beyond-semgrep static hardening probes
β β βββ version-diff-audit.sh # Cross-version regression diff
β β βββ semgrep-rules/ # 70+ MASTG rules
β βββ 04-android-15-16/ # Android 15/16 specific scripts
β β βββ android15-apis.js
β β βββ passkey-test.js
β β βββ privacy-sandbox-test.sh
β βββ 05-scoring/ # MASVS compliance scoring
β β βββ calculate-score.py # Score engine (0-100 + A-F)
β β βββ masvs-matrix.json # 23 MASVS v2 controls
β β βββ masvs-mapping.json # Finding-to-control mapping
β β βββ update-coverage.py # Coverage table generator
β βββ 06-setup/ # Preflight checks & validation
β β βββ preflight-check.sh
β β βββ preflight-check.py
β β βββ preflight-check.ps1
β β βββ validate-frida-scripts.sh
β β βββ validate-shell-scripts.sh
β βββ 07-tools/ # Core analysis tools
β β βββ frida-exploit-helper.py
β β βββ generate-report.py
β β βββ rop-helper.py
β β βββ correlate-findings.py
β β βββ mobsf-api-scan.py
β β βββ burp-findings-export.py
β β βββ adb-backup-extract.sh # Pull /data/data via adb backup (no root)
β β βββ drozer-automated.sh # Drozer IPC automation
β β βββ firebase-check.sh # Firebase misconfiguration sweep
β β βββ inspect-app-sandbox.sh # /data/data audit (rooted device/emulator)
β β βββ live-logcat-analyzer.py # Streaming logcat leak detector (tokens/PII/stack traces)
β βββ lib/ # Shared library (DRY helpers, severity, paths, MASVS)
β βββ auto-audit-static.sh # Main workflow orchestrator
β βββ audit-android-components.sh # Component security audit
β βββ test-findings.json # Sample report input
βββ references/schemas/ # 2 JSON schemas for report/finding contracts
βββ references/ai-prompts/ # AI-powered analysis prompts
βββ java-security-analyzer.md # Java code analysis prompts
βββ native-binary-analyzer.md # Native binary analysis prompts
βββ exploit-generator.md # Exploit PoC generation prompts
βββ report-enhancer.md # Report enhancement prompts
The skill activates when the user says:
- "audit this APK"
- "analyze android app"
- "mobile pentest"
- "APK security"
- "decompile APK"
- "android vulnerability assessment"
- "reverse engineer android"
- "modify APK"
- "bypass SSL pinning"
- "bypass root detection"
- "intent injection"
- "deep link abuse"
- Dynamic analysis requires a device or emulator β Frida needs a running Android system
- Some packers require manual unpacking β DexGuard 9+, Arxan may need interactive debugging
- Android 14+ restrictions β Certain Intent behaviors require explicit
-n package/activityflags - Frida version matching β frida-server on device must match frida-tools on host exactly
- Flutter uses BoringSSL natively β Java SSL hooks don't work, need native hooks
This skill is aligned with:
- OWASP MASTG β Mobile Application Security Testing Guide
- OWASP MASVS β Mobile Application Security Verification Standard
- Passive OSINT enrichment β Scope-controlled public evidence correlation for APK findings
- OWASP Mobile Top 10 2024 β Top 10 mobile risks
- CVSS 4.0 β Common Vulnerability Scoring System
| ID | Category |
|---|---|
| M1 | Improper Credential Usage |
| M2 | Inadequate Supply Chain Security |
| M3 | Insecure Authentication/Authorization |
| M4 | Insufficient Input/Output Validation |
| M5 | Insecure Communication |
| M6 | Inadequate Privacy Controls |
| M7 | Insufficient Binary Protections |
| M8 | Security Misconfiguration |
| M9 | Insecure Data Storage |
| M10 | Insufficient Cryptography |
Contributions are welcome! Please see the references/ directory for areas that need expansion.
Apache License 2.0 β See LICENSE for details.
DragonJAR SAS β https://www.DragonJAR.org
Experts in IT security services, proactive validation, and offensive security.
This repository (main branch) is the canonical source of the skill. If you keep copies in agent skill directories (e.g. ~/.agents/skills/android-pentesting-skill/ or ~/.config/opencode/skills/android-pentesting-skill/), resync them after pulling:
git -C /path/to/Android-Pentesting-Skill pull
rsync -a --delete --exclude '.git' --exclude '__pycache__' --exclude '.pytest_cache' \
/path/to/Android-Pentesting-Skill/ ~/.agents/skills/android-pentesting-skill/Unsynchronized copies will drift and silently serve outdated references.