Auditing Mobile Deeplink Trust

Audit how a mobile app handles a deep link, app link, or custom-scheme URL, so an attacker-supplied URL cannot drive a sensitive action or reach a trusted WebView context. Covers a custom scheme any app can register and hijack, an app link whose domain association is unverified so the link is not exclusively the app's, a deep-link parameter that flows unvalidated into a sensitive action, an attacker-controlled URL loaded into a WebView, and a JavaScript bridge exposed to a WebView that can load untrusted content. Use when reviewing deep-link routing, URL handling, and WebView configuration, not the manifest export state of the component that receives the link (that is the component-exposure skill). The attacker-supplied URL is the source, a sensitive action or a trusted WebView bridge acting on it is the sink, and a link parameter trusted without validation is the bug.

UnboundCompute a986a14 8.8 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-mobile-deeplink-trust commit a986a144e6

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-mobile-deeplink-trust