agentsclimarketplace

Mobile owasp masvs

Skill almasumdev/awesome-mobile-security-agent-skills/.github/skills/vuln/mobile-owasp-masvs

Agent skills for securing mobile apps: storage, transport, auth, obfuscation, and hardening.

Install
npx -y skills add almasumdev/awesome-mobile-security-agent-skills --skill mobile-owasp-masvs

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Aligning a mobile app against the OWASP Mobile Application Security Verification Standard (MASVS v2). Use as a review rubric and as the source of truth for which controls apply.

SKILL.md

5.2 KB, ~1.3k tokens by cl100k_base, as published. Nobody here has run it

OWASP MASVS Alignment

Instructions

MASVS v2 is the de-facto standard for mobile app security. Use it as a verification checklist, not as a wish list — not every control applies to every app.

1. The Eight Groups (MASVS v2)

GroupScope
MASVS-STORAGESensitive data at rest.
MASVS-CRYPTOCryptography usage.
MASVS-AUTHAuthentication and session management.
MASVS-NETWORKNetwork communication.
MASVS-PLATFORMPlatform interaction (IPC, WebViews, permissions).
MASVS-CODECode quality and update hygiene.
MASVS-RESILIENCEReverse-engineering and tampering resistance.
MASVS-PRIVACYPrivacy of user data.

Adopted in v2: RESILIENCE and PRIVACY are now explicit groups.

2. Pick a Profile

MASVS defines profiles, not a monolith:

  • L1 (baseline) — every mobile app.
  • L2 (defense-in-depth) — apps handling sensitive data (banking, health, enterprise).
  • R (resilience) — apps at material risk of client-side attacks (DRM, gambling, premium content).

A SaaS productivity app may be L1. A consumer bank is L2 + R. Document which profile applies per app and per feature.

3. Control Mapping to Practical Skills

MASVS groupMap to skill
STORAGEsecure-storage, keystore-keychain, encrypted-databases
CRYPTOkeystore-keychain
AUTHoauth-mobile, token-storage, biometric-auth, mfa-on-mobile
NETWORKtls-pinning, mitm-prevention, api-abuse-protection
PLATFORMmitm-prevention (WebView / deep links), secrets-management
CODEcode-obfuscation, dependency-scanning
RESILIENCEanti-tampering, root-jailbreak-detection
PRIVACYprivacy-by-design, consent-management, gdpr-mobile

4. Practical Verification — Quick Wins

Run these on every release:

  • Static: MobSF (open source) on the APK / IPA. Triage the findings — not every "HIGH" matters for your profile.
  • Dependency: see dependency-scanning.
  • Dynamic: run against Frida / Objection to validate root / debugger / pinning controls in a lab.
  • Binary: apkanalyzer, otool -L, strings — sanity-check that no hardcoded secrets slipped in.
# Example: fail CI if an expected-stripped symbol is present
if unzip -p app-release.aab AndroidManifest.xml | grep -i "DEBUG"; then
  echo "Debug symbol shipped in release bundle" && exit 1
fi

5. Evidence Package Per Release

For L2 / R apps, produce a short evidence bundle:

  • Which profile applies.
  • Which MASVS controls are in scope, and which skill / test proves each.
  • Exceptions, with a rationale and expiry date.
  • Sign-off from engineering + security owner.

This pays for itself on the first audit, SOC 2 report, or App Store rejection.

6. What MASVS Does Not Cover

  • Server-side authorization (covered by OWASP ASVS + API Security Top 10).
  • Business-logic fraud (rate limits, anomaly detection).
  • Supply-chain compromise of build tooling (covered by SLSA / in-toto).

Don't pretend MASVS compliance covers these — it doesn't.

7. Keep Up With the Standard

MASVS v2 is stable but the MASTG (Mobile Application Security Testing Guide) is updated continuously. Subscribe to releases; controls are refined as platforms change (e.g., iOS Privacy Manifests, Android 14 photo picker).

8. Using MASVS With AI Agents

When reviewing a PR, prompt the agent:

"Walk through this diff against MASVS-STORAGE and MASVS-NETWORK. List any control where you would fail or need more info."

Agents with these skills produce useful, specific findings — not generic "consider security" comments.

Checklist

  • A profile (L1 / L2 / R) is documented per app and per feature.
  • Each in-scope MASVS control maps to a specific skill or test.
  • MobSF (or equivalent) runs on every release build and findings are triaged.
  • Dynamic tests (Frida, Objection) verify resilience controls for R-profile features.
  • Binary sanity checks run in CI (no hardcoded secrets, no debug symbols).
  • Release produces an evidence bundle for L2 / R apps.
  • MASTG updates are reviewed at least quarterly.

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 326,970. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.