Hunting Mobile Secret And Storage Exposure

Hunt a mobile app for a real credential shipped in the binary or written to storage another party can read, scoped strictly to mobile-specific sinks. Covers a live secret embedded in the app package or its resources, sensitive data written to world-or-sandbox-readable storage without encryption, a secret placed outside the platform keystore where a weaker guard protects it, data cached or logged where another app or a device-level reader reaches it, and a backup or debug path that carries sensitive data off the device. Use when reviewing the app package, its storage writes, and its logging, distinguishing a public identifier from a credential and judging whether the platform sandbox already contains the data. The embedded or stored secret is the source, a party that can read it is the sink, and a real credential exposed beyond its intended reader is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-mobile-secret-and-storage-exposure commit 89ea330877

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-mobile-secret-and-storage-exposure