testing-mobile-applications

Automates end-to-end mobile app pentesting for Android and iOS.

109|11|Updated Nov 13, 2025
One-click install
npx skills add https://github.com/trilwu/secskills --skill testing-mobile-applications
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: testing-mobile-applications
Source: https://github.com/trilwu/secskills/tree/main/secskills/skills/mobile-pentesting
Command: npx skills add https://github.com/trilwu/secskills --skill testing-mobile-applications

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Mobile security teams need a structured, end-to-end approach to test Android and iOS apps, bypass common controls, and instrument apps for deeper vulnerability discovery.

Core Features & Use Cases

  • Android and iOS pentesting workflows
  • SSL pinning bypass, root/jailbreak evasion
  • Static/dynamic analysis, Frida instrumentation
  • Intercepting/network traffic and vulnerability discovery
  • Real-world mobile security assessment scenarios

Quick Start

Begin a mobile pentest by selecting Android or iOS analysis tasks and following the guided workflow.

Frequently Asked Questions about testing-mobile-applications

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I bypass SSL pinning during mobile app pentesting?

SSL pinning bypass during mobile app pentesting is automated through guided workflows applying Frida-based instrumentation to circumvent network traffic restrictions on Android and iOS. It provides step-by-step operational guidance for intercepting traffic using Burp and mitmproxy.

Can I use Frida and adb for dynamic analysis on both Android and iOS?

Yes, dynamic analysis using Frida and adb is fully supported for both Android and iOS platforms. The Skill integrates these tools to perform dynamic instrumentation, intercept network traffic, and execute real-world vulnerability discovery workflows during security assessments.

What is the best way to structure an end-to-end mobile application pentest?

An end-to-end mobile application pentest is structured by selecting either Android or iOS analysis tasks and following a guided workflow. This workflow satisfies requirements for static analysis, dynamic instrumentation, traffic interception, and vulnerability assessment in real-world security engagements.

How do I evade root and jailbreak detection when testing mobile apps?

Root and jailbreak evasion when testing mobile apps is handled through specialized dynamic analysis workflows. The Skill provides actionable steps to circumvent root detection on Android and jailbreak detection on iOS, allowing deeper Frida-based instrumentation and vulnerability assessment.

Does this mobile pentesting workflow include static APK analysis?

Yes, static APK analysis is explicitly included in the mobile pentesting workflow. The Skill automates both static analysis and dynamic testing for Android applications, covering SSL pinning bypass, root circumvention, and mobile vulnerability assessment.