Review a mobile app (Android/iOS) against the OWASP MASVS control groups — storage, crypto, auth, network, platform, code quality, and resilience — producing a per-control finding set. Use for a structured mobile security assessment or design review. Authorized testing only.
Scanned 9/19/2026
npx -y skills add jassics/awesome-claude-security --skill masvs-review --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Masvs Review?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/jassics-masvs-review)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: masvs-review
description: >-
Review a mobile app (Android/iOS) against the OWASP MASVS control groups —
storage, crypto, auth, network, platform, code quality, and resilience —
producing a per-control finding set. Use for a structured mobile security
assessment or design review. Authorized testing only.
---
# Goal
A MASVS-aligned assessment: each control group examined, with applicability,
evidence, severity, and remediation.
# MASVS control groups
- **MASVS-STORAGE** — sensitive data at rest, leakage via logs/backups/IPC/clipboard.
- **MASVS-CRYPTO** — key management and correct, current cryptography.
- **MASVS-AUTH** — authentication and authorization, biometrics, session handling.
- **MASVS-NETWORK** — TLS, certificate validation/pinning, no cleartext.
- **MASVS-PLATFORM** — IPC, WebViews, deep links, permissions, platform APIs.
- **MASVS-CODE** — input handling, dependencies, build/hardening settings.
- **MASVS-RESILIENCE** — anti-tampering, anti-reversing, integrity (defense-in-depth,
not a substitute for the above).
# Steps
1. Gather artifacts: the app package (APK/IPA), and source if available.
2. Walk each control group; for static checks, cross-ref `sast-sca`; for runtime,
use `mobile-pentest`.
3. Record per control: applicable? · finding · evidence · severity · remediation.
4. Score (`security-reporting:cvss`) and rank.
# Output
A per-control table grouped by MASVS category + ranked top risks. Confirmed issues →
`security-reporting:finding`.
# Notes
The highest-frequency mobile issues are insecure data storage and weak network/TLS
handling (broken cert validation, no pinning where warranted). Treat RESILIENCE as
defense-in-depth — never as a replacement for fixing storage/crypto/auth. Test only
apps you're authorized to assess.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!