Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. Use when the user mentions 'mobile security,' 'iOS security,' 'Android security,' 'mobile audit,' 'mobile pentest,' 'MASVS,' 'MASTG,' 'certificate pinning,' 'jailbreak detection,' 'root detection,' 'deeplink,' 'URL scheme,' 'app transport security,' 'keychain,' 'keystore,' 'mobile reverse engineering,' or has a mobile app to review.
76
95%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Passed
No findings from the security scan
Audit mobile apps against the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Application Security Testing Guide (MASTG). Covers source code review, static analysis of compiled binaries, and runtime testing.
Scope: this skill covers the app and its interaction with the device, the backend, and other apps. For backend API security, pair with api-audit. For dependency CVEs (CocoaPods, SPM, Gradle), pair with dependency-audit.
Before reverse-engineering or runtime-testing a binary, confirm:
If unclear, ask before proceeding.
kSecAttrAccessible class — kSecAttrAccessibleWhenUnlockedThisDeviceOnly or kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly. Avoid Always and ThisDeviceOnly-less variantsNSUserDefaults, plist, or app bundle — strings <app>.ipa should not reveal API keys or secretsandroid:allowBackup="false" in the manifest (or backup rules carefully scoped) — otherwise adb backup extracts everythingpasteboard.expirationDate, Android ClipDescription.EXTRA_IS_SENSITIVE)applicationDidEnterBackground blur, Android FLAG_SECURE on the activitystrings, class-dump, apktool reveal embedded constantsSecRandomCopyBytes (iOS) / SecureRandom (Android) — not arc4random() for crypto, never Math.random()iv = "0000000000000000", that's worse than no encryption (reveals plaintext patterns)NSAllowsArbitraryLoads = true. If exceptions exist, they're specific domains, justified, and documentednetwork_security_config.xml exists and enforces cleartext-traffic refusal — <base-config cleartextTrafficPermitted="false">URLSessionDelegate + URLAuthenticationChallenge; Android: NetworkSecurityConfig <pin-set> or OkHttp CertificatePinnerWKWebView only (iOS, not UIWebView); JavaScript bridge audited; setJavaScriptEnabled(false) if the WebView doesn't need JSloadUrl with user-controlled URL — open redirect, intent-spoofing, phishing surfaceLAContext.evaluatePolicy (iOS) / BiometricPrompt (Android) — not the deprecated FingerprintManagerSecAccessControl.biometryAny, Android KeyGenParameterSpec.setUserAuthenticationRequired(true))android:exported="true") reviewed for parameter handlingmyapp://) which any app can registermyapp:// from a WebView to trigger an in-app action without user consent is an XSS-to-action chainandroid:exported="false" unless explicitly intended for cross-app access; if exported, every URI path validatedandroid:permission is callable by any appLocalBroadcastManager for in-app broadcasts; system broadcasts validatedUIApplication.openURL options include UIApplicationOpenURLOptionsSourceApplicationKey)otool -hv on iOS, readelf -h on Android .so)strip, ProGuard/R8)DEBUG flag, isDebuggable in manifest)This category is rated optional in MASVS — only required for high-risk apps (banking, DRM, government). For most apps, don't waste effort here; ship secure crypto and a proper backend.
If required:
ptrace self-attach (iOS / Linux), Debug.isDebuggerConnected (Android)Note: every resilience control will be bypassed by a determined attacker with physical device access. They buy time, they don't prevent.
| Tool | Platform | Use |
|---|---|---|
| MobSF | iOS + Android | Automated static + dynamic scanner; first-pass triage |
| nuclei + mobile templates | Both | Pattern-based scanner |
| semgrep + mobile rules | Both | AST-based rules |
| jadx | Android | Decompile APK to Java |
| apktool | Android | Disassemble APK |
| Hopper / Ghidra / IDA | iOS | Disassemble Mach-O |
| class-dump / nm / otool | iOS | Symbol and structure inspection |
strings | Both | First check — secrets, URLs, debug strings |
| Frida + objection | Both | Runtime instrumentation, SSL-pinning bypass, method tracing |
For grey/black-box assessment, use a non-personal device:
objection if you need to see encrypted traffic during testingapi-audit)# Mobile Application Security Audit
## App: [name + version]
## Platform: iOS / Android / both
## MASVS profile: L1 / L2 / R (resilience required)
## Date: [date]
### Executive summary
[2-3 paragraphs]
### MASVS category findings
| Category | Findings | Severity high-water mark |
|---|---|---|
| STORAGE | N | |
| CRYPTO | N | |
| NETWORK | N | |
| AUTH | N | |
| PLATFORM | N | |
| CODE | N | |
| RESILIENCE | N | (only if R-profile) |
### Per-finding detail
[Title, MASVS-ID, severity, description, location, evidence, remediation, verification]
### Backend API findings
[Cross-link to api-audit / owasp-audit output]
### Recommendations
[Prioritized 30/60/90 day fixes]c9ade03
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.