Run a MASTG-based mobile penetration test (Android/iOS) combining static and dynamic analysis: storage inspection, traffic interception, platform-interaction abuse, and resilience checks. Use to actively test a mobile app you're authorized to assess.
Scanned 9/19/2026
npx -y skills add jassics/awesome-claude-security --skill mobile-pentest --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Mobile Pentest?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/jassics-mobile-pentest)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: mobile-pentest
description: >-
Run a MASTG-based mobile penetration test (Android/iOS) combining static and
dynamic analysis: storage inspection, traffic interception, platform-interaction
abuse, and resilience checks. Use to actively test a mobile app you're authorized
to assess.
---
# Goal
Evidence-backed mobile findings from hands-on static + dynamic testing, mapped to
MASVS controls and ranked.
# Prerequisites
- Authorization to test; the app package; a test device/emulator; and a proxy for
traffic interception. Keep testing within scope and non-destructive.
# Methodology (MASTG-aligned)
1. **Recon & static** — unpack the app; review manifest/Info.plist, permissions,
exported components, secrets/keys in code or resources, and dependencies
(cross-ref `sast-sca`).
2. **Storage** — inspect on-device data: shared prefs/UserDefaults, databases,
files, keychain/keystore, caches, logs, backups, clipboard.
3. **Network** — intercept traffic; test TLS, certificate validation, and pinning
(including pinning-bypass to assess robustness); look for cleartext/sensitive data.
4. **Platform interaction** — exercise exported activities/services, deep links,
intent/IPC handling, WebView config (JS bridges, file access).
5. **Auth & session** — local auth/biometric bypass, token storage, session
handling against the backend (`api-security`).
6. **Resilience** (if in scope) — root/jailbreak detection, anti-tamper, debugging.
# Steps
Work the methodology; record per finding: control · technique · evidence · impact ·
remediation. Keep payloads benign and within scope.
# Output
A findings table mapped to MASVS groups, ranked by severity. Confirmed issues →
`security-reporting:finding`.
# Notes
Mobile risk usually concentrates at the client↔backend boundary — pair this with
`api-security` for the server side. Pinning-bypass and root-detection-bypass are to
assess control robustness, not to attack out-of-scope systems.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!