AT

abisheikm1/tribunal

开发工具
48 stars 质量 40 趋势 40

An Android app pentest pipeline built as a small set of . Drop an APK in apk/; every finding that survives static review, dynamic verification, and API testing goes through an adversarial...

概览

An Android app pentest pipeline built as a small set of . Drop an APK in apk/; every finding that survives static review, dynamic verification, and API testing goes through an adversarial prosecution/defense/judge trial before it's written up — no finding reaches report/ without standing up to cross-examination. Skills pass structured JSON through targets/ / and keep raw decompiled output (apktool/, jadx/) on disk for manual pivoting. apk/ the scope boundary — an APK physically placed there is your own assertion that you own it or are authorized to test it. No package registry to maintain; scripts fail closed on the resolved path (see CLAUDE.md). Methodology + standard tooling only — writing a custom Frida pinning bypass for your own emulated app is expected; building tools that attack apps outside the apk/-is-scope model is not. - (bundled scripts; standard library only).

README

Tribunal

An authorized-testing Android app pentest pipeline built as a small set of agentic skills. Drop an APK in apk/; every finding that survives static review, dynamic verification, and API testing goes through an adversarial prosecution/defense/judge trial before it’s written up — no finding reaches report/ without standing up to cross-examination. Skills pass structured JSON through targets// and keep raw decompiled output (apktool/, jadx/) on disk for manual pivoting.

 APK ─▶ 1. decompile-threat-review ─▶ 2. dynamic-verify ─▶ 3. api-vuln-test ─▶ 4. courtroom-verdict
         (static, autonomous)          (your emulator+Burp)  (server-side API)   (prosecution/defense/judge)
         threat_model.json             evidence/, status      api_findings.json   report//-.md
         report.json (candidates)      frida/bypass.js

Authorized use only. apk/ is the scope boundary — an APK physically placed there is your own assertion that you own it or are authorized to test it. No package registry to maintain; scripts fail closed on the resolved path (see CLAUDE.md). Methodology + standard tooling only — writing a custom Frida pinning bypass for your own emulated app is expected; building tools that attack apps outside the apk/-is-scope model is not.

Requirements

  • Python 3.10+ (bundled scripts; standard library only). Java (any recent JRE) to run apktool/jadx — vendored under tools/ (Windows + Linux launchers), no separate install needed; scripts prefer PATH if you already have your own.
  • On PATH: adb, frida + frida-server (pip install frida-tools objection); Burp Suite and the Android Studio emulator for the dynamic stages. Scripts degrade gracefully if a tool is missing.

Run it like this

Clone the repo, drop an APK in apk/, and trigger the pipeline — that’s the whole setup. Under the hood:

# 1. Decompile (scope-checks the path against apk/ automatically) + build the threat model
python skills/decompile-threat-review/scripts/inventory.py --apk apk/app.apk
#    -> targets//{apktool,jadx}/, inventory.json, evidence/, frida/
#    Then a main agent fans out subagents (default, not opt-in) -- one builds the structural
#    threat model, four review disjoint rubric slices in parallel, skeptics try to refute each
#    candidate -- and writes targets//threat_model.json + report.json/report.md.

# 2. Verify on your emulator  (skill: dynamic-verify) -- preflight-checked first
python scripts/preflight_check.py --stage dynamic --check-frida-server
adb -s  install -r apk/app.apk
python skills/dynamic-verify/scripts/verify_runner.py --hash       # scaffolds evidence + prints plans
#    wire Burp (references/proxy-ca-setup.md); bypass pinning if needed:
#      objection -g com.example.app explore -s "android sslpinning disable"
#      # if generic fails: spawn a dedicated subagent to read threat_model.json.pinning's
#      # actual source (not just the class name) and write a tailored hook -- see
#      # dynamic-verify SKILL.md §4c / references/pinning-bypass.md
#      cp skills/dynamic-verify/scripts/frida/bypass_template.js targets//frida/bypass.js
#      frida -U -f com.example.app -l targets//frida/bypass.js --no-pause
python skills/dynamic-verify/scripts/verify_runner.py --hash  --set-status F-001 confirmed --note "..."

# 3. Test the API  (skill: api-vuln-test)  — after HTTPS flows in Burp
#    Save Burp proxy history (Save items -> XML), then:
python skills/api-vuln-test/scripts/extract_endpoints.py --hash  --burp burp_export.xml
#    -> targets//api_findings.json ; test IDOR/BOLA/auth/BFLA/injection/business-logic

# 4. courtroom-verdict (skill: courtroom-verdict) -- every status=confirmed finding goes to trial
#    A main agent invokes the Workflow tool: name "android-courtroom-verdict", args {hash, package}.
#    Prosecution argues it's real+exploitable, defense rebuts, judge independently checks the
#    evidence and rules. Guilty verdicts get written to report//-.md;
#    every verdict is recorded so a finding is never re-tried. Fully agent-driven, no script.

Or drive the whole thing via skills/pentest-runbook/SKILL.md — runs 1→2→3→4 back-to-back with no manual gate in between, once the APK is in apk/.

Layout

CLAUDE.md                     lean project rules (loads every session)
README.md                     this file
docs/
  vuln-catalog.md             13-category rubric for stage 1 (source of truth)
  DESIGN.md                   pipeline rationale + stage-by-stage detail
apk/                          drop APKs here -- this directory IS the scope gate
report//             final write-ups that won courtroom-verdict (git-ignored)
tools/                        vendored apktool + jadx (Windows + Linux launchers)
scripts/
  harness.py                  shared: sha256, targets dir, apk/-path scope gate, JSON IO
  scope_gate.py               the shared scope gate CLI (apk/-path containment + emulator check)
  preflight_check.py          adb/emulator/Frida/Objection readiness gate for dynamic stages
skills/
  decompile-threat-review/    SKILL.md + references/ + scripts/{inventory.py, coverage.py, chain_graph.py}
  dynamic-verify/             SKILL.md + references/ + scripts/{verify_runner.py, fuzz_surface.py, frida/bypass_template.js}
  api-vuln-test/              SKILL.md + references/ + scripts/extract_endpoints.py
  courtroom-verdict/          SKILL.md (fully agent-driven, no bundled script)
  native-audit/                SKILL.md + scripts/{inventory_native.py, triage_native.py}
  pentest-runbook/            SKILL.md (orchestrator)
.claude/workflows/
  android-adversarial-review.js   default multi-agent stage-1 review
  android-courtroom-verdict.js    stage-4 prosecution/defense/judge trial
targets//         per-APK state: JSON + apktool/ + jadx/ + evidence/ + frida/  (git-ignored)
tests/                        fixtures + smoke test for the deterministic scripts
legacy-harness/               earlier per-category harness (superseded; safe to delete)

Tests

python tests/test_pipeline.py     # scope gate, inventory, endpoint extraction, fuzz surface, etc.
View this README on GitHub

推荐工具

换一个关键词,或者移除筛选条件。

安装

npx skillfish add abisheikm1/tribunal