DragonJAR Android Pentesting Skill
Skill by ara.so — Security Skills collection.
This skill provides comprehensive Android APK security analysis capabilities for AI agents, combining static analysis, dynamic instrumentation with Frida, RASP detection, authorized bypass validation, source-to-sink tracing, MASVS scoring, and professional reporting in a unified workflow.
What This Skill Does
Transforms an AI agent into an expert Android security auditor capable of:
- APK Analysis: Decode APKs with APKTool, decompile with JADX, detect frameworks with APKiD
- Static Security Analysis: 50+ manifest checks, 70+ Semgrep MASTG rules, secret detection, obfuscation analysis
- Dynamic Instrumentation: 37 Frida scripts for SSL pinning bypass, root detection bypass, crypto interception
- Runtime Defense Analysis (RDA): Detect 18 protection categories (RootBeer, SafetyNet, Frida detection, RASP, etc.)
- RASP Bypass: Authorized bypass runner with reusable profiles, DRY workflow
- Data Flow Tracing: Source-to-sink methodology with confidence levels
- MASVS Compliance: Automated scoring against OWASP MASVS controls with CVSS 4.0
- APK Modification: Smali patching, repackaging, signing, validation
Installation
Prerequisites
Install required tools (Linux/macOS):
Skill Installation
Verification
Core Workflows
1. Basic APK Security Audit
Example findings output:
2. Runtime Defense Analysis (RASP Detection)
RDA output structure:
3. RASP Bypass Workflow (DRY Pattern)
Important: Client-side bypasses do NOT forge server-side attestation. For Play Integrity, SafetyNet, Approov, or similar backend-enforced controls, use an authorized test tenant, backend allowlist, or approved lab configuration.
4. SSL Pinning Bypass
5. Framework-Specific Analysis
React Native
Hook React Native bridge:
Flutter
6. Data Flow Tracing
Flow confidence levels:
CONFIRMED: Direct observable flow without conditionsLIKELY: Flow with minimal conditional branchesPOSSIBLE: Flow through complex logic, needs dynamic validation
7. MASVS Compliance Scoring
8. APK Modification Workflow
Frida Script Library
Common Frida Operations
Frida Exploit Helper
Custom Frida Script Example
Configuration
Environment Variables
Bypass Profiles Configuration
Common Patterns
Pattern 1: Full Security Assessment
Pattern 2: Traffic Interception
Pattern 3: Root Detection Bypass Stack
Pattern 4: Automated Secret Extraction
Troubleshooting
Issue: APKTool Decode Fails
Issue: Frida Server Connection Failed
Issue: SSL Pinning Bypass Not Working
Issue: Runtime Defense Analysis Returns Empty Results
Issue: MASVS Scorer Shows Low Score
Agent Usage Examples
Example 1: Quick APK Audit
User: "Audit this APK: ~/Downloads/banking-app.apk"
Agent Actions:
Agent Response: "Found 8 security issues: 2 CRITICAL (hardcoded API keys), 3 HIGH (exported activities without permissions), 2 MEDIUM (weak crypto), 1 LOW (debug logs). MASVS score: 68.2/100 (Grade: D). Report saved to findings-merged.json."
Example 2: Bypass SSL Pinning
User: "This banking app has SSL pinning. I need to intercept the login request."
Agent Actions:
Agent Response: "SSL pinning bypassed (OkHttp3 CertificatePinner detected). Configure your proxy (Burp/ZAP) to 127.0.0.1:8080. Restart the app and attempt login."
Example 3: Detect RASP Protections
User: "Check what runtime protections this app has."
Agent Actions:
Agent Response: "Detected 4 protections: RootBeer (root detection), custom emulator checks, Frida detection (anti-instrumentation), DexGuard obfuscation. Bypass profiles available: rootbeer_standard, frida_detection, emulator_detection. Run rasp-bypass-runner.sh to generate bypass command."
Example 4: Find Hardcoded Secrets in React Native
User: "This is a React Native app. Find any hardcoded API keys in the JavaScript bundle."
Agent Actions:
Agent Response: "Found 3 hardcoded secrets in assets/index.android.bundle: Firebase API key (line 4521), Stripe publishable key (line 8912), AWS access key ID (line 12045). Evidence saved to findings-merged.json with MASVS-STORAGE-1 control failure."
Advanced Topics
Native Code Analysis
Attestation Bypass Limitations
Custom Semgrep Rules
References
- OWASP MASVS: https://mas.owasp.org/MASVS/
- OWASP MASTG: https://mas.owasp.org/MASTG/
- Frida Documentation: https://frida.re/docs/
- APKTool Documentation: https://apktool.org/docs/
- DragonJAR Community: https://www.dragonjar.org/
License
Apache 2.0 - See LICENSE file for details.


