Skip to main content

mobile-pentest-plan

Stars13
Forks1
UpdatedJuly 3, 2026 at 10:08

Mobile pentest orchestrator & scoping front-end. Given a mobile app (APK, IPA, source tree, package name / bundle id) — especially when you don't yet know the platform or the app ships BOTH Android and iOS builds — fingerprint it (native vs React-Native/Flutter/Xamarin/Cordova, build flavor, signing, SDK inventory, endpoints, attack surface), classify data sensitivity into a NowSecure Tier (1/2/3), derive the mandatory OWASP MASVS 2.0 control baseline + test depth for that tier, produce a scoped MASTG-based pentest plan, then dispatch to /android-security and/or /ios-security to execute. The mobile analog of /pentester. Chains into /masvs-checklist for the compliance matrix and /api-security for discovered backends.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
3 files
SKILL.md
readonly