domain-mobile

Guides iOS and Android security assessments toward client, transport, storage, and backend findings.

Updated Apr 10, 2026
One-click install
npx skills add https://github.com/Balthael/ciberbal-ai --skill domain-mobile-balthael
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: domain-mobile
Source: https://github.com/Balthael/ciberbal-ai/tree/main/internal/assets/skills/domain-mobile
Command: npx skills add https://github.com/Balthael/ciberbal-ai --skill domain-mobile-balthael

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Mobile penetration tests often drift into device-only trivia that misses real user and backend impact. This Skill keeps iOS and Android assessments focused on meaningful findings across local storage, transport security, and app-to-backend trust boundaries. ## Core Features & Use Cases - Structured Assessment Checklist: Reviews local storage, secrets handling, jailbreak/root assumptions, certificate trust, network protections, and API interaction. - Impact Classification: Distinguishes purely local compromise from issues that create broader account or server-side impact, preventing overstated findings. - Evidence and Reporting Guidance: Defines expected outputs including screenshots, intercepted flows, storage artifacts, device state assumptions, and app build identifiers. - Use Case: During an authorized mobile app pentest, use this Skill to structure the engagement so findings tie directly to user risk and backend implications, with a documented reproduction path. ## Quick Start Ask the agent to assess this Android or iOS application using the mobile domain checklist and report findings with backend impact and reproduction steps.

Frequently Asked Questions about domain-mobile

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a mobile app penetration test?

Structure a mobile pentest around four areas: local storage and secrets handling, transport and certificate trust behavior, API and backend interaction, and jailbreak/root assumptions. Document device state, app build identifiers, and a reproduction path for each finding.

What should a mobile security assessment checklist cover?

Cover local storage review, secrets handling, certificate trust validation, network protections, and app-to-backend trust boundaries. Also record what required device compromise versus what worked with ordinary user context.

How do I avoid overstating local-only mobile vulnerabilities?

Classify each finding by whether it requires device compromise or works in an ordinary user context, and whether it creates broader account or server impact. Only report remote or account-level impact when the evidence supports it.

What evidence should mobile pentest findings include?

Include screenshots, intercepted traffic flows, storage artifacts, and instrumentation output. Also document device state assumptions, app version and build identifiers, and the tooling and environment used for reproduction.

Does this apply to both iOS and Android testing?

Yes, the checklist applies to both iOS and Android assessments. It addresses platform-relevant concerns like jailbreak and root assumptions while keeping the focus on user risk and backend implications rather than platform trivia.