An Android app pentest pipeline built as a small set of . Drop an APK in apk/; every finding that survives static review, dynamic verification, and API testing goes through an adversarial...
개요
An Android app pentest pipeline built as a small set of . Drop an APK in apk/; every finding that survives static review, dynamic verification, and API testing goes through an adversarial prosecution/defense/judge trial before it's written up — no finding reaches report/ without standing up to cross-examination. Skills pass structured JSON through targets/ / and keep raw decompiled output (apktool/, jadx/) on disk for manual pivoting. apk/ the scope boundary — an APK physically placed there is your own assertion that you own it or are authorized to test it. No package registry to maintain; scripts fail closed on the resolved path (see CLAUDE.md). Methodology + standard tooling only — writing a custom Frida pinning bypass for your own emulated app is expected; building tools that attack apps outside the apk/-is-scope model is not. - (bundled scripts; standard library only).
README
Tribunal
An authorized-testing Android app pentest pipeline built as a small set of agentic skills.
Drop an APK in apk/; every finding that survives static review, dynamic verification, and API
testing goes through an adversarial prosecution/defense/judge trial before it’s written up — no
finding reaches report/ without standing up to cross-examination. Skills pass structured JSON
through targets// and keep raw decompiled output (apktool/, jadx/) on disk for
manual pivoting.
APK ─▶ 1. decompile-threat-review ─▶ 2. dynamic-verify ─▶ 3. api-vuln-test ─▶ 4. courtroom-verdict
(static, autonomous) (your emulator+Burp) (server-side API) (prosecution/defense/judge)
threat_model.json evidence/, status api_findings.json report//-.md
report.json (candidates) frida/bypass.js
Authorized use only.
apk/is the scope boundary — an APK physically placed there is your own assertion that you own it or are authorized to test it. No package registry to maintain; scripts fail closed on the resolved path (seeCLAUDE.md). Methodology + standard tooling only — writing a custom Frida pinning bypass for your own emulated app is expected; building tools that attack apps outside theapk/-is-scope model is not.
Requirements
- Python 3.10+ (bundled scripts; standard library only). Java (any recent JRE) to run
apktool/jadx— vendored undertools/(Windows + Linux launchers), no separate install needed; scripts preferPATHif you already have your own. - On PATH:
adb,frida+frida-server(pip install frida-tools objection); Burp Suite and the Android Studio emulator for the dynamic stages. Scripts degrade gracefully if a tool is missing.
Run it like this
Clone the repo, drop an APK in apk/, and trigger the pipeline — that’s the whole setup. Under
the hood:
# 1. Decompile (scope-checks the path against apk/ automatically) + build the threat model
python skills/decompile-threat-review/scripts/inventory.py --apk apk/app.apk
# -> targets//{apktool,jadx}/, inventory.json, evidence/, frida/
# Then a main agent fans out subagents (default, not opt-in) -- one builds the structural
# threat model, four review disjoint rubric slices in parallel, skeptics try to refute each
# candidate -- and writes targets//threat_model.json + report.json/report.md.
# 2. Verify on your emulator (skill: dynamic-verify) -- preflight-checked first
python scripts/preflight_check.py --stage dynamic --check-frida-server
adb -s install -r apk/app.apk
python skills/dynamic-verify/scripts/verify_runner.py --hash # scaffolds evidence + prints plans
# wire Burp (references/proxy-ca-setup.md); bypass pinning if needed:
# objection -g com.example.app explore -s "android sslpinning disable"
# # if generic fails: spawn a dedicated subagent to read threat_model.json.pinning's
# # actual source (not just the class name) and write a tailored hook -- see
# # dynamic-verify SKILL.md §4c / references/pinning-bypass.md
# cp skills/dynamic-verify/scripts/frida/bypass_template.js targets//frida/bypass.js
# frida -U -f com.example.app -l targets//frida/bypass.js --no-pause
python skills/dynamic-verify/scripts/verify_runner.py --hash --set-status F-001 confirmed --note "..."
# 3. Test the API (skill: api-vuln-test) — after HTTPS flows in Burp
# Save Burp proxy history (Save items -> XML), then:
python skills/api-vuln-test/scripts/extract_endpoints.py --hash --burp burp_export.xml
# -> targets//api_findings.json ; test IDOR/BOLA/auth/BFLA/injection/business-logic
# 4. courtroom-verdict (skill: courtroom-verdict) -- every status=confirmed finding goes to trial
# A main agent invokes the Workflow tool: name "android-courtroom-verdict", args {hash, package}.
# Prosecution argues it's real+exploitable, defense rebuts, judge independently checks the
# evidence and rules. Guilty verdicts get written to report//-.md;
# every verdict is recorded so a finding is never re-tried. Fully agent-driven, no script.
Or drive the whole thing via skills/pentest-runbook/SKILL.md — runs 1→2→3→4 back-to-back with
no manual gate in between, once the APK is in apk/.
Layout
CLAUDE.md lean project rules (loads every session)
README.md this file
docs/
vuln-catalog.md 13-category rubric for stage 1 (source of truth)
DESIGN.md pipeline rationale + stage-by-stage detail
apk/ drop APKs here -- this directory IS the scope gate
report// final write-ups that won courtroom-verdict (git-ignored)
tools/ vendored apktool + jadx (Windows + Linux launchers)
scripts/
harness.py shared: sha256, targets dir, apk/-path scope gate, JSON IO
scope_gate.py the shared scope gate CLI (apk/-path containment + emulator check)
preflight_check.py adb/emulator/Frida/Objection readiness gate for dynamic stages
skills/
decompile-threat-review/ SKILL.md + references/ + scripts/{inventory.py, coverage.py, chain_graph.py}
dynamic-verify/ SKILL.md + references/ + scripts/{verify_runner.py, fuzz_surface.py, frida/bypass_template.js}
api-vuln-test/ SKILL.md + references/ + scripts/extract_endpoints.py
courtroom-verdict/ SKILL.md (fully agent-driven, no bundled script)
native-audit/ SKILL.md + scripts/{inventory_native.py, triage_native.py}
pentest-runbook/ SKILL.md (orchestrator)
.claude/workflows/
android-adversarial-review.js default multi-agent stage-1 review
android-courtroom-verdict.js stage-4 prosecution/defense/judge trial
targets// per-APK state: JSON + apktool/ + jadx/ + evidence/ + frida/ (git-ignored)
tests/ fixtures + smoke test for the deterministic scripts
legacy-harness/ earlier per-category harness (superseded; safe to delete)
Tests
python tests/test_pipeline.py # scope gate, inventory, endpoint extraction, fuzz surface, etc.
추천 도구
다른 키워드를 입력하거나 필터를 제거해 보세요.
설치
npx skillfish add abisheikm1/tribunal