
Apk Redteam Pipeline (Grade A)Security-tested testing-security skill for Claude AI. Grade A. End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, sec
Overview
Key features
- Automated APK acquisition
- jadx decompilation
- secret/URL/JWT/Firebase grep
- pinned-cert extraction
- exported-component enumeration
- Frida runtime instrumentation templates
Pricing
- Model
- Free
- Category
- Skills
- Rating
- No reviews yet
Use cases
Mobile App Security Testing
Use the Apk Redteam Pipeline when the target has a mobile app catalogue, and you need to test the security of their Android apps.
Bug Bounty Program
Use the Apk Redteam Pipeline for bug bounty programs that list Android as in scope.
Pros & Cons
Pros
- Automates APK acquisition from multiple sources
- Performs jadx decompilation and secret/URL/JWT/Firebase grep
- Includes Frida runtime instrumentation templates
- Useful for security testing and bug bounty programs
Cons
- May not work for iOS-only targets
- Not suitable for React Native/Flutter web apps or server-side only assessments
Reviews
Sign in to leave a review.
No reviews yet. Be the first!
Q&A
Why this exists?
Most bug‑hunting Claude setups are either too generic (one big "security" prompt) or too fragmented (you bookmark dozens of disclosed reports and re‑read them for each engagement). Neither scales beyond the second target. This bundle was built and validated through authorized engagements that exposed capability gaps: bug‑bounty work showed missing hypothesis discipline, lack of per‑program reporting tactics, poor engagement coordination, and insufficient evidence hygiene. External red‑team work revealed additional gaps such as conservative defaults that missed findings, no mid‑engagement situational awareness, and missing enterprise‑platform attack chains. The bundle addresses these gaps with structured methodology, automated reporting, coordinated evidence handling, and up‑to‑date platform‑specific tradecraft.
Asked by Wei Chen · Dec 14, 2025
How it works?
It follows a 6‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any submission. You can drive it either by describing your testing goals in plain English, which automatically loads the relevant skill set, or by using the /hunt scaffold and the cbh CLI, which provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a 6‑phase architecture diagram, and the cbh CLI reference.
Asked by Bruno Kaufmann · Oct 7, 2025
What's inside?
The bundle contains 82 skills, auto‑loaded by topic — no invocation by name. Coverage spans the external attack surface, including web‑application hunting (XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect), authentication & identity (auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO), API & infrastructure (GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE), advanced & concurrency (race‑condition, HTTP smuggling, deserialization, cache‑poison), framework‑specific (Next.js, Node.js, Laravel, Spring Boot), enterprise identity & cloud (M365/Entra, Okta, cloud‑IAM), infrastructure & appliance (VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM), red‑team tradecraft (redteam‑mindset, APK pipeline, supply‑chain recon, mid‑engagement IR), recon & OSINT, and workflow/reporting utilities. A full searchable catalog is in docs/skills.md, and the bundle also ships 15 slash commands and a deterministic engagement engine that maps a target's attack surface and routes each finding to the appropriate skill.
Asked by Hasan Demir · Oct 7, 2025
What is this?
claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads.
Asked by Quyen Tran · Aug 24, 2025
Ask a question
Skills alternatives

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)
Security-tested devops skill for Claude AI. Grade A. **WORKFLOW SKILL** — Maintains repository documentation accuracy and freshness across the docs site, agent files, and changelog. WHEN: "update docs
Trending now

Accurate Homework Help with Full Explanations

Document intelligence API that parses, splits, OCRs, and extracts structured data from complex PDFs, slides, and spreadsheets.

Open multimodal 12B model handling interleaved images and text with a 128K context window.

Sponsored answers, paid per click.
