Skip to main content
在 Manus 中运行任何 Skill
一键导入

mobile-android-hunter

星标15
分支7
更新时间2026年6月28日 16:46

Static security assessment of an authorized Android APK using MobSF (static engine), mobsfscan, and apkleaks. Covers hardcoded secrets / API keys, insecure data storage, exported components (activities / services / receivers / providers) and intent surface, weak crypto, cleartext traffic / network-security-config gaps, dangerous permissions, debuggable / backup-allowed flags, and embedded endpoint URLs. Net-new category - your stack has no mobile coverage. Static-only by default; dynamic instrumentation (Frida / emulator) is out of scope. Use when an Android client app is in scope. Requires .claude/security-scope.yaml with mobile_testing: approved and the artifact under mobile_artifacts. Maps findings to the OWASP MASVS / Mobile Top 10 and CWE-312/CWE-798/CWE-926. Defensive testing only.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly