AgentReadyHomeAgent ListingRuntimePricing

← Agent Listing

apk-redteam-pipeline (Claude-BugHunter)

Agent SkillsFreeOpen Source

End-to-end Android APK red-team pipeline: acquire, decompile, secret-grep, and Frida-instrument.

🛡️ AgentReady threat assessment

MAESTRO 7-layer threat model + OWASP AIVSS risk score for apk-redteam-pipeline (Claude-BugHunter), derived from its capabilities.

AIVSS 9.0 · Critical
View MAESTRO 7-layer threat model →

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.

Overview

An offensive mobile skill that automates APK acquisition (Play Store + apkpure/apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, and intent-injection probes. Built from an authorized engagement that recovered a hardcoded JWT and 30 internal API endpoints. Surface: downloads and decompiles APKs and runs runtime instrumentation.

Key features and capabilities

Use cases