Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 CA injection, exported-component/content-provider abuse, deep-link/WebView chains, biometric bypass, Flutter/React-Native RE
npx skills add https://github.com/hypnguyen1209/offensive-claude --skill mobile-pentest
| Technique | ATT&CK | CWE | Reference | Script |
|-----------|--------|-----|-----------|--------|
| Lab build + Frida 17 server/gadget | T1635 | CWE-1188 | references/environment-interception.md | - |
| Android 14/15 Conscrypt-APEX CA injection | T1521.001 | CWE-295 | references/environment-interception.md | scripts/android_ca_inject.sh |
| SSL/cert-pinning bypass (Java TM/OkHttp/native) | T1521.001 | CWE-295 | references/environment-interception.md | scripts/universal_unpin.js |
| Root detection bypass (RootBeer/native stat) | T1633.001 | CWE-693 | references/environment-interception.md | scripts/universal_unpin.js |
| Exported activity/service/receiver abuse | T1626.001 | CWE-926 | references/android-component-attacks.md | scripts/manifest_attack_surface.py |
| Content-provider SQLi / path traversal (CVE-2025-48609) | T1409 | CWE-22, CWE-89 | references/android-component-attacks.md | scripts/component_fuzz.sh |
| Task hijacking / StrandHogg / TapTrap (USENIX '25) | T1517 | CWE-1021 | references/android-component-attacks.md | scripts/manifest_attack_surface.py |
| Deep-link / intent-redirect / scheme hijack | T1635, T1577 | CWE-939 | references/webview-deeplink-exploitation.md | scripts/component_fuzz.sh |
| WebView JS-interface RCE + file:// theft | T1577 | CWE-749 | references/webview-deeplink-exploitation.md | scripts/component_fuzz.sh |
| OAuth custom-scheme callback interception | T1635 | CWE-940 | references/webview-deeplink-exploitation.md | - |
| Insecure storage (SharedPrefs/SQLite/external) | T1409 | CWE-312 | references/insecure-storage-crypto.md | scripts/manifest_attack_surface.py |
| Keystore/Keychain misuse + dumping | T1634 | CWE-522 | references/insecure-storage-crypto.md | scripts/ios_bypass_suite.js |
| Biometric bypass (BiometricPrompt/LAContext) | T1634 | CWE-287 | references/insecure-storage-crypto.md | scripts/ios_bypass_suite.js |
| iOS jailbreak + JB-detection bypass | T1635 | CWE-693 | references/ios-offensive.md | scripts/ios_bypass_suite.js |
| IPA decrypt / class-dump / URL-scheme abuse | T1409, T1635 | CWE-200 | references/ios-offensive.md | scripts/ios_bypass_suite.js |
| Flutter RE / reFlutter pinning bypass | T1521.001 | CWE-295 | references/crossplatform-re-instrumentation.md | scripts/hermes_triage.py |
| React Native Hermes bytecode decompile | T1640 | CWE-656 | references/crossplatform-re-instrumentation.md | scripts/hermes_triage.py |
# ---- ANDROID ----
# 0. Pull + statically triage the APK (manifest, secrets, exported surface, framework ID)
adb shell pm path com.target.app # locate split APKs
adb pull /data/app/.../base.apk .
python3 scripts/manifest_attack_surface.py base.apk -o surface.json
jadx -d src base.apk & apktool d base.apk -o decoded
# 1. Frida 17: match server to host tools; push + run
frida --version # e.g. 17.x -> use matching server
adb push frida-server-17.x-android-arm64 /data/local/tmp/frida-server
adb shell "su -c 'chmod 755 /data/local/tmp/frida-server && /data/local/tmp/frida-server &'"
# 2. Trust Burp CA on Android 14/15 (APEX is immutable -> Zygote namespace bind-mount)
bash scripts/android_ca_inject.sh 9a5ba575.0 cacert.pem # see reference for cert hashing
# 3. Spawn target with universal unpinning + root-detection bypass
frida -U -f com.target.app -l scripts/universal_unpin.js --no-pause
# 4. Hit the exported attack surface from surface.json
bash scripts/component_fuzz.sh com.target.app surface.json
# ---- iOS ----
frida-ios-dump -o app.ipa com.target.app # decrypt + pull (jailbroken)
frida -U -f com.target.app -l scripts/ios_bypass_suite.js --no-pause # JB + pinning + biometric + keychain
# ---- HYBRID ----
file decoded/assets/index.android.bundle # "Hermes JavaScript bytecode" => RN
python3 scripts/hermes_triage.py base.apk # detect Flutter/RN, drive reFlutter/hermes-dec
| Technique | Telemetry / IOC | Detection (Sigma / app-side) | OPSEC note |
|-----------|-----------------|------------------------------|------------|
| Frida instrumentation | frida-server/gadget ports (27042), re.frida.server, suspicious maps regions, named pipes linjector | App scans /proc/self/maps for frida, checks D-Bus port, thread gum-js-loop; Play Integrity | Use frida-gadget renamed lib, custom port frida-server -l 0.0.0.0:1337, magisk-hide / Shamiko |
| CA injection (APEX) | New trust anchor in process trust store; cert CN mismatch on pinned hosts | Network Security Config <trust-anchors> excludes user store; pinning catches it | Mount lives only in Zygote ns, vanishes on Zygote crash — re-inject; nothing written to /system |
| SSL-pinning bypass | TLS handshake to proxy IP; cert chain not app-pinned cert | App-side pin failure callbacks fire (if logged); telemetry SDK sees proxy cert | Hook before first request; for Flutter prefer reFlutter patch over runtime to avoid crash loops |
| Root/JB bypass | getprop ro.debuggable, su binaries, magisk paths queried | RootBeer/iXGuard SDK reports; SafetyNet/Play Integrity attestation server-side | Bypass client checks only; server-side attestation (Play Integrity / DeviceCheck) is unaffected |
| Exported component abuse | am start/startservice/broadcast from adb; foreign UID intent | App logs unexpected caller UID; Binder.getCallingUid() checks | Use on-device malicious app for realism; adb leaves shell history |
| Content-provider traversal | content query with ../; openFile on out-of-dir path | FileProvider canonical-path check; CVE-2025-48609 patched Mar 2026 SPL | URL-encode ..%2f to dodge naive filters; read-only first |
| TapTrap / task hijack | Transparent activity transition, taskAffinity overlap, animationScale abuse | TapTrap fixed Dec 2025 SPL; check targetSdk, taskAffinity="" | Zero-permission; works <Dec-2025 patch; user study: 100% missed at least one variant |
| Keychain/Keystore dump | keychain_dumper, frida memory scrape, SecItemCopyMatching hooks | Keychain items with .biometryCurrentSet resist hooking; SE-backed keys unextractable | JB device dumps keychain plaintext regardless of ACL; flag SE vs SW keys in report |
| Biometric bypass | LAContext evaluatePolicy / BiometricPrompt callback hook | Only works on boolean-result pattern, NOT SecAccessControl-gated crypto | Report root cause: auth result not bound to a crypto/keychain operation |
intent:// redirection to non-exported components, task hijacking (StrandHogg 1.0/2.0 CVE-2020-0096) and TapTrap animation-driven tapjacking (USENIX Security '25), drozer + adb workflows.addJavascriptInterface RCE, setAllowUniversalAccessFromFileURLs/file:// local-file theft, deep-link → WebView open-redirect/XSS chains, intent:// browsable-activity pivots, OAuth custom-scheme callback hijack (RFC 8252), iOS URL-scheme & Universal Link abuse, one-click browser-to-WebView exploitation.setUserAuthenticationRequired), iOS Keychain ACLs & keychain_dumper, NSUserDefaults/plist leaks, biometric bypass (BiometricPrompt CryptoObject vs result-only, LAContext evaluatePolicy), hardcoded secrets & Firebase/S3 misconfig, MASVS-STORAGE mapping.libflutter.so patch of ssl_crypto_x509_session_verify_cert_chain, iptables/proxydroid fallback), React Native Hermes bytecode RE (hermes-dec, hbctool patch/reassemble, hermes-decomp, CatalystInstanceImpl.loadScriptFromAssets Frida hook), native .so JNI/JNI_OnLoad analysis in Ghidra/IDA.Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
Automatically creates user-facing changelogs from git commits by analyzing commit history, categorizing changes, and transforming technical commits into clear, customer-friendly release notes. Turns hours of manual changelog writing into minutes of automated generation.
Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup
Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
React Native and Expo best practices for building performant mobile apps. Use when building React Native components, optimizing list performance, implementing animations, or working with native modules. Triggers on tasks involving React Native, Expo, mobile performance, or native platform APIs.
React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.
Next.js best practices - file conventions, RSC boundaries, data patterns, async APIs, metadata, error handling, route handlers, image/font optimization, bundling
Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktrees with smart directory selection and safety verification
Take hypnguyen1209/mobile-pentest from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.