Back to skill

Security audit

mobile-master

Security checks for vulnerabilities and agentic risk

Overview

This Android reverse-engineering skill appears purpose-aligned, but it needs Review because it runs powerful Frida/ADB/root actions with weak scoping and unsafe argument handling.

Install only if you intend to use this in an authorized Android security lab and are comfortable with Frida, ADB, rooted devices, and local extraction of APK/DEX files. Before running it, fix or restrict the script argument handling, use only trusted bundled Frida scripts, avoid untrusted package/script inputs, and stop frida-server/port forwarding after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/Spawn-app.sh:12
Finding

Frida Argument and Script-Path Injection in Spawn Launcher

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi cmd=(frida -U -f "$package") if [[ -n "$script" ]]; then base_dir=$(realpath -- "$FRIDA_SCRIPT_DIR") || exit 1 script_path=$(realpath -- "$FRIDA_SCRIPT_DIR/$script") || exit 1 case "$script_path" in "$base_dir"/*) ;; *) echo "Script path is outside the permitted directory" >&2 exit 1 ;; esac [[ -f "$script_path" ]] || exit 1 cmd+=(-l "$script_path") fi "${cmd[@]}" ``` Where practical, accept only a fixed allowlist of bundled Frida scripts rather than arbitrary paths. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/Attach-app.sh:24
Finding

Frida Script-Path and Option Injection in Attach Launcher

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac [[ -f "$script_path" ]] || exit 1 cmd+=(-l "$script_path") fi "${cmd[@]}" ``` Continue enforcing a digits-only PID when a PID is supplied directly. Prefer selecting bundled scripts from a fixed allowlist, and add `--` before user-controlled positional values where the invoked utility supports it. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/Dexdump.sh:62
Finding

Frida-Dexdump Argument and Script-Path Injection

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac [[ -f "$script_path" ]] || exit 1 cmd+=(-l "$script_path") fi "${cmd[@]}" ``` Verify that the installed `frida-dexdump` version actually supports script-loading options. If custom scripts are unnecessary for DEX dumping, remove the second argument and `-l` functionality entirely. Retain strict numeric PID validation and use a fixed, permission-controlled output directory. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

cd mobile-master

Install manually

mkdir -p ~/.claude/skills/mobile-master/ cp -r ./* ~/.claude/skills/mobile-master/

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

cd mobile-master

Install manually

mkdir -p ~/.claude/skills/mobile-master/ cp -r ./* ~/.claude/skills/mobile-master/

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and links to shell-backed scripts that start frida-server, extract APKs, dump dex files, and attach to running apps, but it declares no explicit tool scope or permissions boundary. This creates an authorization and containment gap: an agent could invoke powerful shell actions without clear policy constraints, increasing the risk of unintended device tampering, data extraction, or abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown content is written entirely in Chinese, including the description and command explanations, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This may violate language/locale policy where user opt-in or documented locale constraints are required.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description exposes a broad set of mobile-reversing and bypass capabilities, including frida detection bypass, unpacking, attach/spawn hooking, and installation restriction bypass, without defining when these actions are appropriate or what prerequisites and approvals are required. In an agent setting, vague activation boundaries can cause overbroad use of sensitive offensive techniques and make misuse easier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script constructs a shell command string from user-controlled input and executes it via $cmd, which causes the shell to re-parse the string. Because script is appended without quoting or validation, an attacker can inject shell metacharacters (for example through the script name) and execute arbitrary local commands, not merely attach Frida to a target process. In a mobile reverse-engineering skill, users are already expected to run privileged tooling against connected devices, which increases the danger of command injection on the analyst workstation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script constructs a shell command string with untrusted values and executes it via $cmd, allowing shell metacharacters in pid or script to be interpreted by the shell. Because package is derived from grep output influenced by user input and script comes directly from the command line, an attacker could trigger command injection and execute arbitrary commands on the analyst’s host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script copies the extracted AndroidManifest.xml into the current directory using cp ... ./, which can overwrite an existing file of the same name. Although the script prints progress messages, it does not warn the user about this data-affecting write or ask for confirmation before replacing a local file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments and console output are written in Chinese throughout, with no opt-in or indication that the skill is intended only for Chinese-speaking users. This can violate language/locale policy when a skill imposes a specific language without user choice or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code performs a file-copy operation from a device to the local machine using adb pull, which affects user data and the local filesystem. Although it prints status messages, there is no explicit warning, confirmation, or explanatory comment disclosing that the script will extract and save an installation package locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script builds a shell command string from untrusted positional arguments and then executes it via $cmd, which causes the shell to re-parse the contents. If package or script contains shell metacharacters such as ;, $(), or backticks, an attacker can inject arbitrary commands on the analyst's machine. In a mobile-reversing skill, these inputs are likely user-supplied, so the context makes this more dangerous rather than less.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/Start-frida-server.sh (reported line 56)May include surrounding context.

sh
else
    echo "⚠️  Could not verify frida-server status. You may need to:"
    echo "  1. Ensure frida-server is pushed to /data/local/tmp/"
    echo "  2. Run: adb shell chmod 755 /data/local/tmp/frida-server"
    echo "  3. Check if your device is rooted"
fi

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The command descriptions are presented only in Chinese, which imposes a language choice on users without any opt-in or alternative locale. This is a natural-language policy concern because the file does not offer an English equivalent or indicate that the skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

User-facing output includes Chinese-only text such as "PID/包名/应用名" and "未找到进程", which imposes a specific language on users. There is no opt-in, fallback language, or documented justification that this skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description frames the skill as assisting reverse engineering, which aligns with dex dumping, but the script goes beyond passive analysis by actively starting applications via adb when they are not running. Launching an app on the device is an operational control capability not implied by the brief description alone.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Using adb shell am start or monkey gives the skill the ability to trigger execution of arbitrary installed apps on a connected device. That capability is not inherently required for all reverse-engineering assistance and is not explicitly justified by the manifest's narrow description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

At L60-L62 the script creates ./dexdump/ and configures frida-dexdump to write output there, but the user is not explicitly warned that filesystem changes will occur and where artifacts will be stored. The existing progress messages cover process lookup and app launch, not the data-writing behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and all user-visible output strings are written in Chinese, forcing a specific language for usage, errors, and status messages. This can violate language/locale policy when no user opt-in or documented locale scope is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The usage text includes Chinese-only wording ("包名", "脚本名"), which imposes a specific language on users without opt-in or explanation. This can violate language/locale policy when the skill does not clearly state that it is intended only for a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes the skill broadly as assisting mobile security reverse engineering, while this script specifically hooks android_dlopen_ext to monitor shared library load paths at runtime. Although related to reverse engineering, this is a narrower and more invasive dynamic instrumentation behavior than the description makes explicit.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.