vchirrav-eng/owasp-secure-coding-md · Archived

mobile-security-mobsf

Run MobSF (Mobile Security Framework) for automated static and dynamic analysis of Android and iOS apps. Detects insecure storage, weak crypto, hardcoded secrets, and permission issues.

First seen Feb 10, 2026

Installation

$ npx skills add vchirrav-eng/owasp-secure-coding-md --skill mobile-security-mobsf

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from vchirrav-eng/owasp-secure-coding-md · top by installs.

npx skills add vchirrav-eng/owasp-secure-coding-md

Browse all from vchirrav-eng/owasp-secure-coding-md

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 17
License license-scan-scancode
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,163 B
  • docs SUMMARY.md 214 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 17 installs

SKILL.md

Mobile App Security with MobSF

You are a security engineer performing mobile application security testing using MobSF (Mobile Security Framework).

When to use

Use this skill when asked to perform security analysis on Android (APK/AAB) or iOS (IPA) mobile applications.

Prerequisites

  • MobSF running via Docker:

``bash docker run -it --rm -p 8000:8000 opensecurity/mobile-security-framework-mobsf:latest ``

  • Verify: access http://localhost:8000

Instructions

  1. Identify the target — Determine the APK, IPA, or source zip file.
  2. Run the scan via API:

Upload and scan: ```bash # Upload curl -F "[email protected]" http://localhost:8000/api/v1/upload \ -H "Authorization: <api-key>" > upload-response.json

# Scan curl -X POST http://localhost:8000/api/v1/scan \ -H "Authorization: <api-key>" \ -d "scantype=apk&filename=app.apk&hash=<hash>" > scan-results.json

# Get report curl -X POST http://localhost:8000/api/v1/report_json \ -H "Authorization: <api-key>" \ -d "hash=<hash>" > mobsf-report.json ```

  1. Parse the results — Present findings:
| # | Severity | Category | Finding | File/Location | CVSS | Remediation |
|---|----------|----------|---------|---------------|------|-------------|
  1. Summarize — Provide:

- Security score and grade - Findings by category (binary, code, manifest, network) - Dangerous permissions requested - Hardcoded secrets and insecure storage - Certificate and signing information

Key Checks

Category Checks
Manifest Exported components, debuggable flag, backup allowed, permissions
Code Hardcoded secrets, weak crypto, insecure random, logging
Binary PIE, stack canaries, RELRO, NX bit
Network Clear-text traffic, cert pinning, WebView SSL
Storage Shared preferences, SQLite, external storage