Apk Redteam Pipeline (Grade A) logo

Apk Redteam Pipeline (Grade A)Security-tested testing-security skill for Claude AI. Grade A. End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, sec

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

The Apk Redteam Pipeline is an end-to-end Android APK red-team pipeline. It automates APK acquisition from sources like the Play Store, APKPure, and APKMirror. The pipeline also performs jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, and Frida runtime instrumentation templates. This tool is useful for security testing and bug bounty programs, particularly when the target has a mobile app catalogue. It was developed from an authorized external red-team engagement where 7 APKs were pulled manually, 4 download attempts were truncated, and a hardcoded JWT + 30 internal API endpoints were recovered from one of the apps.

Key features

  • Automated APK acquisition
  • jadx decompilation
  • secret/URL/JWT/Firebase grep
  • pinned-cert extraction
  • exported-component enumeration
  • Frida runtime instrumentation templates

Pricing

Model
Free
Category
Skills
Rating
No reviews yet

Use cases

Mobile App Security Testing

Use the Apk Redteam Pipeline when the target has a mobile app catalogue, and you need to test the security of their Android apps.

Bug Bounty Program

Use the Apk Redteam Pipeline for bug bounty programs that list Android as in scope.

Pros & Cons

Pros

  • Automates APK acquisition from multiple sources
  • Performs jadx decompilation and secret/URL/JWT/Firebase grep
  • Includes Frida runtime instrumentation templates
  • Useful for security testing and bug bounty programs

Cons

  • May not work for iOS-only targets
  • Not suitable for React Native/Flutter web apps or server-side only assessments

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

Why this exists?

Most bug‑hunting Claude setups are either too generic (one big "security" prompt) or too fragmented (you bookmark dozens of disclosed reports and re‑read them for each engagement). Neither scales beyond the second target. This bundle was built and validated through authorized engagements that exposed capability gaps: bug‑bounty work showed missing hypothesis discipline, lack of per‑program reporting tactics, poor engagement coordination, and insufficient evidence hygiene. External red‑team work revealed additional gaps such as conservative defaults that missed findings, no mid‑engagement situational awareness, and missing enterprise‑platform attack chains. The bundle addresses these gaps with structured methodology, automated reporting, coordinated evidence handling, and up‑to‑date platform‑specific tradecraft.

Asked by Wei Chen · Dec 14, 2025

How it works?

It follows a 6‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any submission. You can drive it either by describing your testing goals in plain English, which automatically loads the relevant skill set, or by using the /hunt scaffold and the cbh CLI, which provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a 6‑phase architecture diagram, and the cbh CLI reference.

Asked by Bruno Kaufmann · Oct 7, 2025

What's inside?

The bundle contains 82 skills, auto‑loaded by topic — no invocation by name. Coverage spans the external attack surface, including web‑application hunting (XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect), authentication & identity (auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO), API & infrastructure (GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE), advanced & concurrency (race‑condition, HTTP smuggling, deserialization, cache‑poison), framework‑specific (Next.js, Node.js, Laravel, Spring Boot), enterprise identity & cloud (M365/Entra, Okta, cloud‑IAM), infrastructure & appliance (VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM), red‑team tradecraft (redteam‑mindset, APK pipeline, supply‑chain recon, mid‑engagement IR), recon & OSINT, and workflow/reporting utilities. A full searchable catalog is in docs/skills.md, and the bundle also ships 15 slash commands and a deterministic engagement engine that maps a target's attack surface and routes each finding to the appropriate skill.

Asked by Hasan Demir · Oct 7, 2025

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads.

Asked by Quyen Tran · Aug 24, 2025

Ask a question

Skills alternatives

Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)

(0)
Free
D
Docs Writer (Grade A)Skills

Security-tested devops skill for Claude AI. Grade A. **WORKFLOW SKILL** — Maintains repository documentation accuracy and freshness across the docs site, agent files, and changelog. WHEN: "update docs

(0)
Free