| name | android-app-security |
| description | Android application security workflows: threat modeling, secure SDLC, testing, and OWASP MASVS alignment. Use when assessing or improving Android app security, adding security requirements, reviewing Android code for vulnerabilities, or planning secure release checklists. |
Android App Security
Use this skill to plan, implement, and verify Android app security.
Workflow
- Confirm app context: target SDK, data types, auth, and dependencies.
- Map threats and risks using MASVS categories and data flows.
- Review architecture boundaries and async lifecycle risks with the references below.
- Define security requirements and add them to the backlog.
- Apply secure SDLC checkpoints during design, build, test, and release.
- Run security testing: static analysis, dynamic testing, dependency review.
- Produce a release security checklist and monitor post-release.
References
- references/security-notes.md
- references/clean-architecture-notes.md
- references/coroutines-confidence-notes.md
- references/clean-architecture-layers.md
- references/clean-architecture-usecases-repositories.md
- references/clean-architecture-boundaries-mappers.md
- references/clean-architecture-data-datasource.md
- references/clean-architecture-app-module-di-navigation.md
- references/clean-architecture-presentation-ui-guidelines.md
- references/clean-architecture-migration-testing.md
- references/coroutines-structured-concurrency.md
- references/coroutines-scope-ownership.md
- references/coroutines-dispatchers-context.md
- references/coroutines-error-propagation.md
- references/coroutines-supervision.md
- references/coroutines-cancellation.md