
This is a full-featured Android pentesting framework that runs 50+ manifest checks, 70+ Semgrep rules, and comes with 37 Frida scripts for bypassing SSL pinning, root detection, and RASP protections. It handles the complete workflow from APK decompilation through MASVS compliance scoring and generates professional reports with CVSS ratings. The runtime defense analyzer catalogs 18 protection categories and the bypass runner uses reusable profiles so you're not writing the same Frida hooks over and over. Built for pentesters who need repeatable workflows rather than one-off scripts. Requires the usual suspects installed: apktool, jadx, frida-tools, and adb. The documentation is thorough with actual JSON output examples, which helps when you're trying to understand what findings look like before running it.
npx -y skills add aradotso/security-skills --skill dragonjar-android-pentesting-skill --agent claude-codeInstalls into .claude/skills of the current project.
Select a file.