Screened · automated checks passed

offensive-mobile

from SnailSploit/Claude-Red · ★ 2,705 on GitHub · found by our crawler 2026-07-07

What the author says it does

Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with Frida and Objection, SSL pinning bypass strategies, root/jailbreak detection bypass, deep-link / URL-scheme abuse, exported component attacks (Android activities, services, providers, receivers; iOS XPC, URL schemes, universal links), insecure data storage (SharedPrefs, KeyStore misuse, NSUserDefaults, Keychain ACL bypass), IPC / Intent redirection, WebView vulnerabilities (JavaScriptInterface, file:// access), Firebase/AWS/Azure misconfiguration leakage, mobile API testing, biometric/Face ID/Touch ID bypass, app-cloning and runtime patching, and mobile malware/RAT analysis primitives. Use for mobile pentest, bug bounty mobile triage, or app-store reconnaissance.

Quoted from the skill's own SKILL.md trigger description — this is what tells Claude when to activate it. Not yet verified by us.

Automated screening

100/100 validator score

Scored by the same rules as our free SKILL.md validator: trigger description quality, body substance, structure. Automated — a human bench test is the next step in the pipeline.

Install (unverified — review first)

git clone https://github.com/SnailSploit/Claude-Red
# skill lives at: Skills/mobile/offensive-mobile/SKILL.md

SkillProof status

This skill is in our test queue. We install every skill in a clean environment, run a trigger battery and score output against a baseline before it earns a catalog page — the full protocol is public. Until then, treat it like any unreviewed dependency: read the SKILL.md and any scripts before installing.

Already tested in Testing & QA

  • Screen Reader Testing ★ 9.6/10 Screen reader testing playbook for VoiceOver, NVDA, and JAWS with ARIA fixes.
  • Skill Security Auditor ★ 9.6/10 OWASP-mapped code/secrets/config audit with working bundled scan scripts
  • Web Quality Audit ★ 9.6/10 Lighthouse-style audit across Performance, Accessibility, SEO, and Best Practices with severity tiers.
  • OSINT Methodology ★ 9.6/10 Structured 5-stage external recon methodology with confidence levels, severity rubric, and OpSec rules.

Top 10 Testing skills, ranked →