mobile-pentest
shuvonsec/claude-bug-bountyMobile app pentest for bug bounty (Android APK + iOS IPA) — runtime-first workflow: install app, proxy through Burp/mitmproxy, drive the UI, capture packets,…
Scores out of 100 · grade A
2026-08-17Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score50/100
- 4,231 stars on the source repo.
Documented
15% of the score81/100
- 2,543 words with worked examples.
Install
npx skills add shuvonsec/claude-bug-bounty/mobile-pentestWhat it says it does
Mobile app pentest for bug bounty (Android APK + iOS IPA) — runtime-first workflow: install app, proxy through Burp/mitmproxy, drive the UI, capture packets, then test the API exactly like a web target; escalate to decompile (apktool/jadx) and Frida/objection only when traffic is SSL-pinned, encrypted, or absent. Covers APK/IPA decompile for hardcoded secrets + hidden API endpoints + base URLs the web app never exposes, exported-activity and deeplink intent injection, WebView addJavascriptInterface bridge abuse, SSL pinning bypass (objection patchapk / Frida CertificatePinner + checkServerTrusted hooks), OkHttp interceptor chain to recover request signing, JNI native-lib triage, and the quick apktool/grep secret + endpoint sweep. Use when the program scope includes a mobile app, when web recon dries up and you need a fresh attack surface, or when traffic is pinned and you must MitM it.
Also in shuvonsec/claude-bug-bounty
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| client-reverseshuvonsec/claude-bug-bounty | clean | Skill | 4.2k stars | 6 days ago | |
| bb-methodologyshuvonsec/claude-bug-bounty | clean | Skill | 4.2k stars | 6 days ago | |
| cicd-securityshuvonsec/claude-bug-bounty | clean | Skill | 4.2k stars | 6 days ago | |
| credential-attackshuvonsec/claude-bug-bounty | clean | Skill | 4.2k stars | 6 days ago | |
| graphql-auditshuvonsec/claude-bug-bounty | clean | Skill | 4.2k stars | 6 days ago | |
| meme-coin-auditshuvonsec/claude-bug-bounty | clean | Skill | 4.2k stars | 6 days ago |
Other security skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| release-openclaw-ciopenclaw/openclaw | No license | Security | 387k stars | today | |
| site-architecturecoreyhaines31/marketingskills | clean | Security | 94,902 installs | today | |
| cookbook-auditanthropics/claude-cookbooks | clean | Security | 52k stars | 2 days ago | |
| asocoreyhaines31/marketingskills | clean | Security | 46,665 installs | today | |
| openclaw-secret-scanning-maintaineropenclaw/openclaw | No license | Security | 387k stars | today | |
| graph-evolutiontrailofbits/skills | clean | Security | 2,860 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=shuvonsec%2Fclaude-bug-bounty)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
