performing-android-app-static-analysis-with-mobsf skill (Anthropic-Cybersecurity-Skills)
- Install
- SKILL.md (verbatim)
- When to Use
- Prerequisites
- Workflow
- Step 1: Deploy MobSF and Obtain API Key
- Step 2: Upload APK for Static Analysis
- Step 3: Trigger and Retrieve Static Scan Results
- Step 4: Analyze Critical Findings
- Step 5: Generate and Export Reports
- Step 6: Integrate into CI/CD Pipeline
- Key Concepts
- Tools & Systems
- Common Pitfalls
- Other files in this skill
- assets/template.md (verbatim)
- Engagement Information
- Executive Summary
- Findings Summary
- Manifest Analysis
- Exported Components
- Permissions Requested
- Manifest Flags
- Code Analysis Findings
- Finding [N]: [TITLE]
- Network Security Analysis
- Binary Analysis
- Recommendations
- Critical (Immediate Action Required)
- High (Fix Before Release)
- Medium (Address in Next Sprint)
- Low (Track in Backlog)
- OWASP Mobile Top 10 2024 Compliance
- references/api-reference.md (verbatim)
- Libraries Used
- Installation
- Authentication
- REST API v1 Endpoints
- Core Operations
- Upload an APK
- Trigger Static Analysis
- Retrieve JSON Report
- Extract Key Findings
- Download PDF Report
- Compare Two Applications
- Output Format
- references/standards.md (verbatim)
- OWASP Mobile Top 10 2024 Mapping
- OWASP MASVS v2.0 Control Mapping
- NIST SP 800-163 Rev 1: Vetting the Security of Mobile Applications
- CWE Mappings for Common MobSF Findings
- references/workflows.md (verbatim)
- Workflow 1: Standalone APK Assessment
- Workflow 2: CI/CD Pipeline Integration
- Workflow 3: Third-Party App Vetting
- Workflow 4: Comparative Analysis Across Versions
- Decision Matrix: When to Escalate
What it does. 'Performs automated static analysis of Android applications using Mobile Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/performing-android-app-static-analysis-with-mobsf/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-android-app-static-analysis-with-mobsf, or copy the skill folder into~/.claude/skills/performing-android-app-static-analysis-with-mobsf/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-android-app-static-analysis-with-mobsf/SKILL.md
SKILL.md (verbatim)
name: performing-android-app-static-analysis-with-mobsf
description: 'Performs automated static analysis of Android applications using Mobile
Security Framework (MobSF) to identify hardcoded secrets, insecure permissions,
vulnerable components, weak cryptography, and code-level security flaws without
executing the application. Use when assessing Android APK/AAB files for security
vulnerabilities before deployment, during penetration testing, or as part of CI/CD
security gates. Activates for requests involving Android static analysis, MobSF
scanning, APK security assessment, or mobile application code review.
'
domain: cybersecurity
subdomain: mobile-security
author: mahipal
tags:
- mobile-security
- android
- mobsf
- static-analysis
- owasp-mobile
- penetration-testing
version: 1.0.0
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.AA-05
- ID.RA-01
- DE.CM-09
mitre_attack:
- T1059
- T1056
- T1036
- T1078
Performing Android App Static Analysis with MobSF
When to Use
Use this skill when:
- Conducting security assessment of Android APK or AAB files before production release
- Integrating automated mobile security scanning into CI/CD pipelines
- Performing initial triage of Android applications during penetration testing engagements
- Reviewing third-party Android applications for supply chain security risks
Do not use this skill as a replacement for manual code review or dynamic analysis -- MobSF static analysis catches pattern-based vulnerabilities but misses runtime logic flaws.
Prerequisites
- MobSF v4.x installed via Docker (
docker pull opensecurity/mobile-security-framework-mobsf) or local setup - Target Android APK, AAB, or source code ZIP
- Python 3.10+ for MobSF REST API integration
- JADX decompiler (bundled with MobSF) for Java/Kotlin source recovery
- Network access to MobSF web interface (default: http://localhost:8000)
Workflow
Step 1: Deploy MobSF and Obtain API Key
Launch MobSF using Docker for isolated, reproducible scanning:
docker run -it --rm -p 8000:8000 opensecurity/mobile-security-framework-mobsf:latest
Retrieve the REST API key from the MobSF web interface at http://localhost:8000/api_docs or from the startup console output. The API key enables programmatic scanning.
Step 2: Upload APK for Static Analysis
Upload the target APK using the MobSF REST API:
curl -F "file=@target_app.apk" http://localhost:8000/api/v1/upload \
-H "Authorization: <API_KEY>"
Response includes the hash identifier used for subsequent API calls. MobSF automatically decompiles the APK using JADX, extracts the AndroidManifest.xml, and indexes all resources.
Step 3: Trigger and Retrieve Static Scan Results
Initiate the static scan and retrieve results:
# Trigger scan
curl -X POST http://localhost:8000/api/v1/scan \
-H "Authorization: <API_KEY>" \
-d "scan_type=apk&file_name=target_app.apk&hash=<FILE_HASH>"
# Retrieve JSON report
curl -X POST http://localhost:8000/api/v1/report_json \
-H "Authorization: <API_KEY>" \
-d "hash=<FILE_HASH>"
Step 4: Analyze Critical Findings
MobSF static analysis covers these categories mapped to OWASP Mobile Top 10 2024:
Manifest Analysis (M8 - Security Misconfiguration):
- Exported activities, services, receivers, and content providers without permission guards
android:debuggable="true"left enabledandroid:allowBackup="true"enabling data extraction via ADB- Missing
android:networkSecurityConfigfor certificate pinning
Code Analysis (M1 - Improper Credential Usage):
- Hardcoded API keys, passwords, and tokens in Java/Kotlin source
- Insecure SharedPreferences usage for storing sensitive data
- Weak or broken cryptographic implementations (ECB mode, static IV, hardcoded keys)
Network Security (M5 - Insecure Communication):
- Missing certificate pinning configuration
- Custom TrustManagers that accept all certificates
- Cleartext HTTP traffic allowed without exception domains
Binary Analysis (M7 - Insufficient Binary Protections):
- Missing ProGuard/R8 obfuscation
- Native library vulnerabilities (stack canaries, NX bit, PIE)
- Debugger detection absence
Step 5: Generate and Export Reports
Export findings in multiple formats for stakeholder communication:
# PDF report
curl -X POST http://localhost:8000/api/v1/download_pdf \
-H "Authorization: <API_KEY>" \
-d "hash=<FILE_HASH>" -o report.pdf
# JSON for programmatic processing
curl -X POST http://localhost:8000/api/v1/report_json \
-H "Authorization: <API_KEY>" \
-d "hash=<FILE_HASH>" -o report.json
Step 6: Integrate into CI/CD Pipeline
Add MobSF scanning as a build gate:
# GitHub Actions example
- name: MobSF Static Analysis
run: |
UPLOAD=$(curl -s -F "file=@app/build/outputs/apk/release/app-release.apk" \
http://mobsf:8000/api/v1/upload -H "Authorization: $MOBSF_API_KEY")
HASH=$(echo $UPLOAD | jq -r '.hash')
curl -s -X POST http://mobsf:8000/api/v1/scan \
-H "Authorization: $MOBSF_API_KEY" \
-d "scan_type=apk&file_name=app-release.apk&hash=$HASH"
SCORE=$(curl -s -X POST http://mobsf:8000/api/v1/scorecard \
-H "Authorization: $MOBSF_API_KEY" -d "hash=$HASH" | jq '.security_score')
if [ "$SCORE" -lt 60 ]; then exit 1; fi
Key Concepts
| Term | Definition |
|---|---|
| Static Analysis | Examination of application code and resources without executing the program; catches structural and pattern-based vulnerabilities |
| APK Decompilation | Process of recovering Java/Kotlin source from compiled Dalvik bytecode using tools like JADX or apktool |
| AndroidManifest.xml | Configuration file declaring app components, permissions, and security attributes; primary target for manifest analysis |
| Certificate Pinning | Technique binding an app to specific server certificates to prevent man-in-the-middle attacks via rogue CAs |
| ProGuard/R8 | Code obfuscation and shrinking tools that make reverse engineering more difficult by renaming classes and removing unused code |
Tools & Systems
- MobSF: Automated mobile security analysis framework supporting static and dynamic analysis of Android/iOS apps
- JADX: Dex-to-Java decompiler for recovering readable source code from Android APK files
- apktool: Tool for reverse engineering Android APK files, decoding resources to near-original form
- Android Lint: Google's static analysis tool for Android-specific code quality and security issues
- Semgrep: Pattern-based static analysis engine with mobile-specific rule packs for custom vulnerability detection
Common Pitfalls
- Ignoring false positives: MobSF flags patterns like
passwordin variable names even when not storing actual credentials. Triage all HIGH findings manually before reporting. - Missing obfuscated code: Static analysis accuracy drops significantly against obfuscated apps. Supplement with dynamic analysis for apps using DexGuard or custom packers.
- Outdated MobSF rules: Security rules evolve with Android API levels. Ensure MobSF is updated to match the target app's
targetSdkVersion. - Skipping native code analysis: MobSF analyzes Java/Kotlin but has limited coverage of native C/C++ libraries. Use
checksecand manual review for.sofiles.
Other files in this skill
- LICENSE
- assets/template.md
- references/api-reference.md
- references/standards.md
- references/workflows.md
- scripts/agent.py
- scripts/process.py
assets/template.md (verbatim)
MobSF Static Analysis Report Template
Engagement Information
| Field | Value |
|---|---|
| Application Name | [APP_NAME] |
| Package Name | [PACKAGE_NAME] |
| Version | [VERSION] |
| Target SDK | [TARGET_SDK] |
| Min SDK | [MIN_SDK] |
| File Hash (SHA256) | [HASH] |
| Analysis Date | [DATE] |
| Analyst | [ANALYST] |
| MobSF Version | [MOBSF_VERSION] |
Executive Summary
Security Score: [SCORE]/100
Overall Risk Rating: [HIGH/MEDIUM/LOW]
[Brief narrative of key findings and overall security posture]
Findings Summary
| Severity | Count | Categories |
|---|---|---|
| Critical | [N] | [Categories] |
| High | [N] | [Categories] |
| Medium | [N] | [Categories] |
| Low | [N] | [Categories] |
| Info | [N] | [Categories] |
Manifest Analysis
Exported Components
| Component Type | Name | Permission Guard | Risk |
|---|---|---|---|
| Activity | [NAME] | [PERMISSION/None] | [RISK] |
| Service | [NAME] | [PERMISSION/None] | [RISK] |
| Receiver | [NAME] | [PERMISSION/None] | [RISK] |
| Provider | [NAME] | [PERMISSION/None] | [RISK] |
Permissions Requested
| Permission | Protection Level | Justification | Risk |
|---|---|---|---|
| [PERMISSION] | [dangerous/normal/signature] | [JUSTIFICATION] | [RISK] |
Manifest Flags
| Flag | Value | Expected | Status |
|---|---|---|---|
| android:debuggable | [VALUE] | false | [PASS/FAIL] |
| android:allowBackup | [VALUE] | false | [PASS/FAIL] |
| android:usesCleartextTraffic | [VALUE] | false | [PASS/FAIL] |
Code Analysis Findings
Finding [N]: [TITLE]
- Severity: [CRITICAL/HIGH/MEDIUM/LOW]
- CWE: [CWE-ID]
- OWASP Mobile: [M1-M10]
- MASVS: [MASVS-CATEGORY]
- Description: [DESCRIPTION]
- Affected Files:
- [FILE_PATH:LINE_NUMBER]
- Evidence: [CODE_SNIPPET]
- Recommendation: [REMEDIATION_STEPS]
Network Security Analysis
| Check | Result | Details |
|---|---|---|
| Certificate Pinning | [Present/Absent] | [DETAILS] |
| Network Security Config | [Present/Absent] | [DETAILS] |
| Cleartext Traffic | [Allowed/Blocked] | [DETAILS] |
| TLS Version | [VERSION] | [DETAILS] |
Binary Analysis
| Check | Result | Details |
|---|---|---|
| Code Obfuscation | [Yes/No] | [DETAILS] |
| Root Detection | [Present/Absent] | [DETAILS] |
| Debug Detection | [Present/Absent] | [DETAILS] |
| Emulator Detection | [Present/Absent] | [DETAILS] |
| Native Libraries (NX) | [Enabled/Disabled] | [DETAILS] |
| Native Libraries (PIE) | [Enabled/Disabled] | [DETAILS] |
| Native Libraries (Stack Canary) | [Present/Absent] | [DETAILS] |
Recommendations
Critical (Immediate Action Required)
- [RECOMMENDATION]
High (Fix Before Release)
- [RECOMMENDATION]
Medium (Address in Next Sprint)
- [RECOMMENDATION]
Low (Track in Backlog)
- [RECOMMENDATION]
OWASP Mobile Top 10 2024 Compliance
| ID | Risk | Status | Findings |
|---|---|---|---|
| M1 | Improper Credential Usage | [PASS/FAIL] | [DETAILS] |
| M2 | Inadequate Supply Chain Security | [PASS/FAIL] | [DETAILS] |
| M3 | Insecure Authentication/Authorization | [PASS/FAIL] | [DETAILS] |
| M4 | Insufficient Input/Output Validation | [PASS/FAIL] | [DETAILS] |
| M5 | Insecure Communication | [PASS/FAIL] | [DETAILS] |
| M6 | Inadequate Privacy Controls | [PASS/FAIL] | [DETAILS] |
| M7 | Insufficient Binary Protections | [PASS/FAIL] | [DETAILS] |
| M8 | Security Misconfiguration | [PASS/FAIL] | [DETAILS] |
| M9 | Insecure Data Storage | [PASS/FAIL] | [DETAILS] |
| M10 | Insufficient Cryptography | [PASS/FAIL] | [DETAILS] |
references/api-reference.md (verbatim)
API Reference: MobSF Android Static Analysis
Libraries Used
| Library | Purpose |
|---|---|
requests |
HTTP client for MobSF REST API v1 |
json |
Parse scan reports and finding data |
os |
Read MOBSF_URL and MOBSF_API_KEY environment variables |
Installation
pip install requests
# MobSF server (Docker)
docker pull opensecurity/mobile-security-framework-mobsf
docker run -it -p 8000:8000 opensecurity/mobile-security-framework-mobsf
Authentication
MobSF uses API key authentication. The default key is shown on the MobSF dashboard:
import requests
import os
MOBSF_URL = os.environ.get("MOBSF_URL", "http://localhost:8000")
MOBSF_KEY = os.environ["MOBSF_API_KEY"]
headers = {"Authorization": MOBSF_KEY}
REST API v1 Endpoints
| Method | Endpoint | Description |
|---|---|---|
| POST | /api/v1/upload |
Upload APK, IPA, ZIP, or APPX for analysis |
| POST | /api/v1/scan |
Trigger static analysis on uploaded file |
| GET | /api/v1/report_json |
Get full JSON analysis report |
| POST | /api/v1/download_pdf |
Download PDF report |
| GET | /api/v1/scans |
List recent scans |
| POST | /api/v1/delete_scan |
Delete a scan and its data |
| POST | /api/v1/search |
Search scans by hash or filename |
| POST | /api/v1/compare |
Compare two app scans |
| GET | /api/v1/scorecard |
Get app security scorecard |
| GET | /api/v1/scan_logs |
View live scan logs |
Core Operations
Upload an APK
def upload_apk(file_path):
with open(file_path, "rb") as f:
resp = requests.post(
f"{MOBSF_URL}/api/v1/upload",
files={"file": (os.path.basename(file_path), f, "application/octet-stream")},
headers=headers,
timeout=120,
)
resp.raise_for_status()
result = resp.json()
return result["hash"], result["scan_type"], result["file_name"]
# hash: SHA-256 of the uploaded file
# scan_type: "apk", "ipa", "zip", "appx"
Trigger Static Analysis
def start_scan(file_hash, scan_type, file_name):
resp = requests.post(
f"{MOBSF_URL}/api/v1/scan",
data={
"hash": file_hash,
"scan_type": scan_type,
"file_name": file_name,
},
headers=headers,
timeout=600, # Scans can take several minutes
)
resp.raise_for_status()
return resp.json()
Retrieve JSON Report
def get_report(file_hash):
resp = requests.post(
f"{MOBSF_URL}/api/v1/report_json",
data={"hash": file_hash},
headers=headers,
timeout=60,
)
resp.raise_for_status()
return resp.json()
Extract Key Findings
def extract_findings(report):
findings = {
"security_score": report.get("security_score", "N/A"),
"app_name": report.get("app_name"),
"package_name": report.get("package_name"),
"target_sdk": report.get("target_sdk"),
"min_sdk": report.get("min_sdk"),
"permissions": {
"dangerous": [],
"normal": [],
},
"manifest_issues": [],
"code_issues": [],
"binary_issues": [],
}
# Dangerous permissions
for perm, details in report.get("permissions", {}).items():
status = details.get("status", "normal")
if status == "dangerous":
findings["permissions"]["dangerous"].append(perm)
else:
findings["permissions"]["normal"].append(perm)
# Manifest analysis
for issue in report.get("manifest_analysis", []):
if issue.get("severity") in ("high", "warning"):
findings["manifest_issues"].append({
"title": issue["title"],
"severity": issue["severity"],
"description": issue["description"],
})
# Code analysis
for issue_key, issue_data in report.get("code_analysis", {}).items():
findings["code_issues"].append({
"rule": issue_key,
"severity": issue_data.get("level"),
"description": issue_data.get("description"),
"files": issue_data.get("path", [])[:5],
})
return findings
Download PDF Report
def download_pdf(file_hash, output_path):
resp = requests.post(
f"{MOBSF_URL}/api/v1/download_pdf",
data={"hash": file_hash},
headers=headers,
timeout=120,
)
resp.raise_for_status()
with open(output_path, "wb") as f:
f.write(resp.content)
Compare Two Applications
resp = requests.post(
f"{MOBSF_URL}/api/v1/compare",
data={"hash1": hash_v1, "hash2": hash_v2},
headers=headers,
timeout=120,
)
comparison = resp.json()
# Shows permission changes, new vulnerabilities, code changes
Output Format
{
"file_name": "app-debug.apk",
"app_name": "TestApp",
"package_name": "com.example.testapp",
"security_score": 42,
"target_sdk": "33",
"min_sdk": "24",
"permissions": {
"android.permission.INTERNET": {"status": "normal", "description": "..."},
"android.permission.READ_CONTACTS": {"status": "dangerous", "description": "..."}
},
"manifest_analysis": [
{"title": "Application is debuggable", "severity": "high", "description": "..."}
],
"code_analysis": {
"android_insecure_random": {
"level": "high",
"description": "Insecure Random Number Generator",
"path": ["com/example/CryptoUtils.java"]
}
},
"binary_analysis": [
{"title": "NX bit not set", "severity": "high"}
]
}
references/standards.md (verbatim)
Standards Reference: Android Static Analysis with MobSF
OWASP Mobile Top 10 2024 Mapping
| OWASP ID | Risk | MobSF Coverage |
|---|---|---|
| M1 | Improper Credential Usage | Detects hardcoded API keys, passwords, tokens in source code and resources |
| M2 | Inadequate Supply Chain Security | Identifies third-party library versions with known CVEs |
| M5 | Insecure Communication | Flags missing certificate pinning, cleartext traffic, weak TLS |
| M7 | Insufficient Binary Protections | Checks ProGuard/R8 obfuscation, native binary protections |
| M8 | Security Misconfiguration | Analyzes AndroidManifest.xml for exported components, debug flags, backup settings |
| M9 | Insecure Data Storage | Detects SharedPreferences misuse, world-readable files, SQLite without encryption |
| M10 | Insufficient Cryptography | Identifies ECB mode, static IV, hardcoded encryption keys, weak algorithms |
OWASP MASVS v2.0 Control Mapping
| MASVS Category | Controls | MobSF Static Checks |
|---|---|---|
| MASVS-STORAGE | Sensitive data storage | SharedPreferences analysis, file permission checks, database encryption |
| MASVS-CRYPTO | Cryptographic implementations | Algorithm strength, key management, IV randomness |
| MASVS-AUTH | Authentication mechanisms | Credential storage, biometric implementation review |
| MASVS-NETWORK | Network security | Network security config, certificate pinning, cleartext detection |
| MASVS-PLATFORM | Platform interaction | Intent filter analysis, content provider security, WebView configuration |
| MASVS-CODE | Code quality | Code obfuscation, debug symbols, error handling |
| MASVS-RESILIENCE | Reverse engineering resistance | Root detection, tamper detection, debugger detection |
NIST SP 800-163 Rev 1: Vetting the Security of Mobile Applications
- Section 4.1: Static analysis as mandatory step in mobile app vetting process
- Section 4.2: Automated tools should check for known vulnerability patterns
- Section 5: Integration of vetting into enterprise mobile device management
CWE Mappings for Common MobSF Findings
| CWE ID | Title | MobSF Finding Category |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | Hardcoded credentials in source |
| CWE-319 | Cleartext Transmission of Sensitive Information | Missing HTTPS enforcement |
| CWE-327 | Use of Broken Cryptographic Algorithm | Weak crypto detection |
| CWE-330 | Use of Insufficiently Random Values | Static IV, predictable random |
| CWE-532 | Insertion of Sensitive Information into Log File | Logging sensitive data |
| CWE-749 | Exposed Dangerous Method or Function | Exported components without guards |
| CWE-919 | Weaknesses in Mobile Applications | General mobile-specific checks |
| CWE-925 | Improper Verification of Intent by Broadcast Receiver | Unprotected broadcast receivers |
references/workflows.md (verbatim)
Workflows: Android Static Analysis with MobSF
Workflow 1: Standalone APK Assessment
[Obtain APK] --> [Deploy MobSF Docker] --> [Upload via API] --> [Run Static Scan]
| |
v v
[Verify APK integrity] [Review Manifest Analysis]
[Check signing certificate] [Review Code Analysis]
[Review Binary Analysis]
[Review Network Analysis]
|
v
[Triage HIGH/CRITICAL findings]
[Validate false positives]
[Generate PDF report]
Workflow 2: CI/CD Pipeline Integration
[Developer pushes code] --> [Build APK] --> [Upload to MobSF] --> [Static Scan]
|
+-----------+-----------+
| |
[Score >= 60] [Score < 60]
| |
[Pass gate] [Fail build]
[Archive report] [Notify developer]
[Continue pipeline] [Block deployment]
Workflow 3: Third-Party App Vetting
[Receive third-party APK] --> [MobSF Static Scan] --> [Automated scoring]
|
v
[Manual review of:]
- Excessive permissions
- Data exfiltration indicators
- Known malware signatures
- C2 communication patterns
|
v
[Risk assessment report]
[Approve/Reject for enterprise use]
Workflow 4: Comparative Analysis Across Versions
[APK v1.0] --> [MobSF Scan] --> [Baseline report]
|
[APK v2.0] --> [MobSF Scan] --> [Compare findings] --> [New vulnerabilities introduced?]
| |
v [Yes: Block release]
[Regression report] [No: Approve release]
Decision Matrix: When to Escalate
| Finding Severity | MobSF Category | Action |
|---|---|---|
| CRITICAL | Hardcoded production API keys | Immediate key rotation, block release |
| HIGH | Exported activity with sensitive data | Manual verification, fix before release |
| MEDIUM | Missing certificate pinning | Add to sprint backlog, risk acceptance if internal app |
| LOW | Debug logging of non-sensitive data | Track in issue tracker, fix in next release |
| INFO | Missing ProGuard rules | Recommend but do not block |
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.