Skip to content
Back to skills

Ashrafiucse Mobile Security

ASecurity

Audits mobile app security — Android (AndroidManifest.xml: exported components, allowBackup, debuggable, cleartext traffic, network security config; WebView misconfigurations; hardcoded keys), iOS (Info.plist ATS exceptions, secrets in UserDefaults, keychain accessibility), and React Native/Flutter storage pitfalls. Use when the project contains AndroidManifest.xml, Info.plist, or Kotlin/Java/Swift/Dart/RN code.

  • 76 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
developmentjavascriptrustgojavaswiftkotlinbashsqlreactapi

Works with

  • api

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned September 26, 2026

npx -y skills add jiayaoqijia/cryptoskill --skill ashrafiucse-mobile-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ashrafiucse Mobile Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ashrafiucse Mobile Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jiayaoqijia-ashrafiucse-mobile-security/badge)](https://www.skillsdirectory.com/skills/jiayaoqijia-ashrafiucse-mobile-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mobile-security
description: Audits mobile app security — Android (AndroidManifest.xml: exported components, allowBackup, debuggable, cleartext traffic, network security config; WebView misconfigurations; hardcoded keys), iOS (Info.plist ATS exceptions, secrets in UserDefaults, keychain accessibility), and React Native/Flutter storage pitfalls. Use when the project contains AndroidManifest.xml, Info.plist, or Kotlin/Java/Swift/Dart/RN code.
license: MIT
---

# Mobile Security

## Step 0 — Detect

```bash
rg --files -g 'AndroidManifest.xml' -g 'Info.plist' -g '*.kt' -g '*.java' -g '*.swift' -g '*.m' -g '*.dart' -g 'pubspec.yaml' -g 'Podfile' -g 'app/build.gradle*' | head
```

## Step 1 — Android manifest

```bash
rg -n "android:exported|allowBackup|debuggable|usesCleartextTraffic|networkSecurityConfig|protectionLevel|grantUriPermissions" -g 'AndroidManifest.xml' -g '*.xml'
```

**Component census (don't eyeball):** enumerate exported components BY TYPE — agents reliably spot activities and providers while services/receivers get skipped. Four separate passes, one table row each:
```bash
rg -n "<activity[^>]*android:exported=\"true\"" -g 'AndroidManifest.xml'
rg -n "<service[^>]*android:exported=\"true\"" -g 'AndroidManifest.xml'
rg -n "<receiver[^>]*android:exported=\"true\"" -g 'AndroidManifest.xml'
rg -n "<provider[^>]*android:exported=\"true\"" -g 'AndroidManifest.xml'
```

| Flag | Finding | Severity |
|---|---|---|
| `android:allowBackup="true"` (or omitted — it's the default) | data extractable via `adb backup` | Medium |
| `android:debuggable="true"` in release manifest | debug bridge on prod devices | High |
| exported `activity`/`service`/`receiver`/`provider` without `android:permission` | component hijacking — any app invokes it | High |
| component with `<intent-filter>` and no explicit `exported` | filters imply exported (API ≤30 rules) | High |
| `usesCleartextTraffic="true"` / `cleartextTrafficPermitted="true"` | HTTP downgrade/MITM | Medium |
| custom permission `protectionLevel="normal"` guarding sensitive ops | any app can request it | Medium |
| exported `provider` + `grantUriPermissions` | URI grant to malicious apps | High |

Note: cleartext is blocked by default since API 28 — check `minSdkVersion`; below 28
without a `network_security_config` = de facto cleartext allowed.

## Step 2 — Android code

```bash
rg -n "addJavascriptInterface|setJavaScriptEnabled|setAllowFileAccess|loadUrl|setAllowUniversalAccessFromFileURLs" -g '*.kt' -g '*.java'
rg -n -i "(api[_-]?key|secret|token)\s*=\s*[\"'][^\"']{8,}" -g '*.kt' -g '*.java' -g 'strings.xml' -g 'build.gradle*'
```

- `addJavascriptInterface` + JS enabled → classic RCE bridge (High; Critical with file access + user URL)
- `loadUrl(intent.dataString)` / loading `http://` update URLs with JS on → High
- Hardcoded keys in code/`strings.xml`/`BuildConfig` → **Critical** (decompiling is trivial)
- `sharedPreferences` storing tokens unencrypted → Medium

## Step 3 — iOS

```bash
rg -n "NSAllowsArbitraryLoads|NSAllowsLocalNetworking|NSExceptionDomains" -g 'Info.plist'
rg -n "UserDefaults|kSecAttrAccessible|Keychain" -g '*.swift' -g '*.m' | head -20
```

- `NSAllowsArbitraryLoads=true` (ATS off) → Medium; `NSExceptionDomains` list → review each
- Tokens/PII in `UserDefaults` (plist, unencrypted, included in backups) → Medium/High
- Keychain items without `kSecAttrAccessible...ThisDeviceOnly` for sensitive items → Low/Medium
- Hardcoded secrets in Swift/ObjC → **Critical**

## Step 4 — Cross-platform

- React Native: tokens in `AsyncStorage` (unencrypted) → Medium; dev deps (`flipper`, `react-devtools-core`) reachable in release builds → Medium
- Flutter: tokens outside `flutter_secure_storage` → Medium; disabling certificate validation (`badCertificateCallback => true`) → High. Full Dart-side shapes (storage census, dio/adapter cert bypass, WebView channels, platform channels, deep-link routes, `--dart-define` secrets, Random()/md5): `../flutter-security/SKILL.md` — this skill keeps the platform/manifest half
- Kotlin/Java app-code shapes (EncryptedSharedPreferences, execSQL/rawQuery, TrustManager/HostnameVerifier bypass, `@JavascriptInterface` bodies, PendingIntent immutability, Keystore/ECB, logcat tokens, google-services.json): `../android-code-security/SKILL.md` — this skill keeps the manifest half; the WebView-bridge greps above stop at existence, that skill opens the method bodies

## Reporting

Manifest findings cite the XML line; code findings cite `file:line`. Fixes are usually
one attribute (`allowBackup="false"`, `exported="false"` + permission) — give the exact line.
Cross-reference hardcoded keys with `../secrets-detection/SKILL.md` for rotation guidance.

Files in this skill

  • LICENSE1 KB
  • SKILL.md4.1 KB
  • SOURCE.md372 B
  • TRUST.auto.yaml2.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…