CtrlK
BlogDocsLog inGet started
Tessl Logo

mobile-audit

Audit iOS and Android mobile applications against OWASP MASVS / MASTG — insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance. Use when the user mentions 'mobile security,' 'iOS security,' 'Android security,' 'mobile audit,' 'mobile pentest,' 'MASVS,' 'MASTG,' 'certificate pinning,' 'jailbreak detection,' 'root detection,' 'deeplink,' 'URL scheme,' 'app transport security,' 'keychain,' 'keystore,' 'mobile reverse engineering,' or has a mobile app to review.

76

Quality

95%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, actionable audit skill that assumes Claude's expertise and provides concrete commands, API identifiers, and a structured output template. The main gaps are the absence of an explicit numbered workflow with validation feedback loops and the opportunity to split the category checklists into reference files.

Suggestions

Add a short numbered workflow at the top (e.g., 1. confirm authorization, 2. select MASVS profile, 3. run static analysis, 4. run runtime tests, 5. verify each finding, 6. produce output) with explicit validation checkpoints.

Move the per-category MASVS checklists into separate reference files (e.g., references/masvs-storage.md) referenced one level deep from SKILL.md to improve progressive disclosure and reduce the inline density.

Add a brief verification/feedback loop note per checklist category so findings are re-checked after remediation rather than reported once.

DimensionReasoningScore

Conciseness

Lean checklist-style body that assumes Claude's competence — it lists concrete checks and commands without explaining what MASVS, crypto, or IPC are, and every section earns its tokens.

5 / 5

Actionability

Highly actionable with specific commands ("strings <app>.ipa", "otool -hv", "readelf -h", "adb backup"), concrete API identifiers (kSecAttrAccessible, EncryptedSharedPreferences, BiometricPrompt), and a tool table covering common cases.

5 / 5

Workflow Clarity

Clear section sequence (authorization gate → MASVS checklists → static tools → runtime testing → output format) with an authorization checkpoint and per-finding verification field, but lacks an explicit numbered end-to-end sequence with validation feedback loops.

4 / 5

Progressive Disclosure

Well-organized single-file overview with clearly signaled sections and external-standard references, but the per-category checklists are dense and could be split into one-level-deep reference files for easier navigation.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that crisply states the skill's purpose and provides an exhaustive set of natural trigger phrases. It answers both what and when with concrete, domain-specific language and minimal conflict risk.

DimensionReasoningScore

Specificity

Lists multiple concrete capability domains — "insecure storage, weak crypto, certificate pinning, deeplinks, IPC, jailbreak/root detection, reverse-engineering resistance" — giving comprehensive coverage rather than vague abstraction.

5 / 5

Completeness

Explicitly answers both what ("Audit iOS and Android mobile applications against OWASP MASVS / MASTG") and when ("Use when the user mentions ... or has a mobile app to review") with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural trigger coverage including synonyms and platform specifics ("mobile security," "iOS security," "Android security," "mobile audit," "mobile pentest," "MASVS," "MASTG," "certificate pinning," "jailbreak detection," "root detection," "deeplink," "URL scheme," "keychain," "keystore").

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (mobile app security auditing against MASVS/MASTG) with distinct, domain-specific triggers that are unlikely to fire for non-mobile skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.