
from android-pentesting-skill319
Comprehensive Android APK security audit with static/dynamic analysis, source-to-sink tracing, and CVSS 4.0 reporting.
This skill provides a deterministic 6-phase workflow for conducting thorough security audits of Android APKs. It combines static analysis (decompilation, manifest audit, secrets detection) with dynamic instrumentation to identify vulnerabilities, from simple hardcoded secrets to complex IPC and intent injection flaws.
Use this skill when a user provides an APK for review, asks to analyze decompiled Android source, needs help with mobile vulnerability assessments, or wants to bypass runtime protections like SSL pinning and root detection.
scope.json and findings.json to ensure reproducible and high-quality audits.Designed for agents with shell access and tool execution capabilities, such as Codex, Claude Code, or any agent capable of running the Android SDK, Frida, and Objection.
This skill has not been reviewed by our automated audit pipeline yet.