Use when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases
日本語の概要は準備中です。原文の説明を表示しています。
Use when reviewing iOS (Swift), Android (Kotlin) or Flutter changes - token storage, ATS and cleartext config, TLS trust, exported components, deep links, WebView JavaScript bridges, certificate pinning claims, secrets bundled in the app, Firebase rules
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
The app binary is public and the device may belong to the attacker. Two consequences shape every mobile finding: anything shipped in the app is readable (a "hidden" server secret is leaked), and any check done only in the app can be skipped (the server is the boundary). What remains for the app is protecting its user from other apps, other networks and other web content.
Core principle: ask who the attacker is — another app on the device, someone on the network, a web page in a WebView, or the device owner. Findings against the device owner protecting their own data are usually not findings.
A server secret in BuildConfig, Info.plist, a bundled .env, strings.xml, Dart constants or an obfuscated string is a leaked secret — CRITICAL when live (secrets-and-crypto-review).
Not findings: Firebase google-services.json / GoogleService-Info.plist, Maps keys restricted by app signature, publishable payment keys. But the Firebase rules that protect the data are in scope:
// ❌ firestore.rules — every client reads and writes everything
match /{document=**} { allow read, write: if true; }
// ✅
match /users/{uid} { allow read, write: if request.auth != null && request.auth.uid == uid; }
| ❌ for tokens and credentials | ✅ |
|---|---|
Android SharedPreferences, plain files, SQLite, external storage | Keystore-backed encryption (Tink/AndroidX security), DataStore with an encrypted serializer |
iOS UserDefaults, plist files, unencrypted Core Data | Keychain with an appropriate kSecAttrAccessible…ThisDeviceOnly class |
Flutter shared_preferences, Hive unencrypted | flutter_secure_storage |
Severity follows the attacker: world-readable files (MODE_WORLD_READABLE, external storage) or data included in backups (android:allowBackup="true" without exclusions) → HIGH for credentials; private app storage on a non-rooted device → MEDIUM note. Tokens in Log.d/print/NSLog → readable by logcat tools and crash reporters → MEDIUM to HIGH.
<!-- ❌ AndroidManifest / network_security_config: cleartext everywhere, user-installed CAs trusted in release -->
<application android:usesCleartextTraffic="true" …>
<base-config cleartextTrafficPermitted="true"><trust-anchors><certificates src="user"/></trust-anchors></base-config>
<!-- ❌ iOS Info.plist: ATS off for every domain -->
<key>NSAppTransportSecurity</key><dict><key>NSAllowsArbitraryLoads</key><true/></dict>
// ❌ Flutter: any certificate accepted
client.badCertificateCallback = (cert, host, port) => true;
Also: a custom X509TrustManager or HostnameVerifier that accepts all; URLSession delegate calling completionHandler(.useCredential, URLCredential(trust:)) without evaluating the trust. A narrowly scoped exception for a local development host in a debug-only config is not a finding.
Certificate pinning claims. Missing pinning is hardening, not a finding. A diff that claims to add pinning gets checked: real SPKI hashes for the right hosts, a backup pin, not disabled in release builds, and — the real risk — no "pinning" implementation that replaces normal validation with a weaker check.
<!-- ❌ any app can start this and pass extras that drive a privileged action -->
<activity android:name=".AdminResetActivity" android:exported="true"/>
<!-- ✅ not exported, or protected by a signature-level permission -->
<activity android:name=".AdminResetActivity" android:exported="false"/>
exported="true" (or an intent filter) and no android:permission.Intent from extras and calls startActivity on it — reaches the app's private components.PendingIntent with FLAG_MUTABLE wrapping an implicit intent → another app fills in the target.ContentProvider.openFile building a path from the URI (traversal), grantUriPermissions on broad paths.Android BROWSABLE intent filters and App Links, iOS universal links and custom URL schemes (application(_:open:options:), onOpenURL), Flutter go_router/app_links handlers: any web page can fire them. A finding when a link's parameters trigger a privileged action without confirmation (auto-login with a token from the link, changing account settings, initiating payments), or load an arbitrary URL into a privileged WebView.
// ❌ an untrusted page gets a bridge into native code
webView.settings.javaScriptEnabled = true
webView.addJavascriptInterface(NativeBridge(tokenStore), "native")
webView.loadUrl(intent.getStringExtra("url")!!)
// ✅ bridge only for the app's own origin; external links open in the browser
if (Uri.parse(url).host == "app.example.com") webView.loadUrl(url) else openInBrowser(url)
addJavascriptInterface with remote content, setAllowFileAccessFromFileURLs(true), setAllowUniversalAccessFromFileURLs(true), shouldOverrideUrlLoading allowing intent:// or file://.WKWebView: a WKScriptMessageHandler that acts on messages without checking message.frameInfo.securityOrigin; loadFileURL with broad allowingReadAccessTo.webview_flutter: JavaScriptChannels on pages loaded from a user-supplied URL.onAuthenticationSucceeded/evaluatePolicy callback without a Keystore/Keychain key bound to it — bypassable on a compromised device; a MEDIUM note when it gates sensitive data.DexClassLoader from external storage or downloaded files; JavaScript bundles or Dart code pushed over the air without signature verification.Missing root/jailbreak detection, missing obfuscation, missing anti-tamper, screenshots in the app switcher, missing pinning, missing authorization checks in client code (judge the server).
allowBackup on an app that stores no credentials.exported="true" added to a component that performs account actions.addJavascriptInterface, JavaScriptChannel or a WKScriptMessageHandler next to a URL taken from an intent, a deep link or a server response.NSAllowsArbitraryLoads, usesCleartextTraffic="true", src="user" outside debug configs.badCertificateCallback, trust-all managers, allow read, write: if true.BuildConfig or Info.plist.OWASP MASVS v2 — MASVS-STORAGE, -CRYPTO, -AUTH, -NETWORK, -PLATFORM, -CODE · OWASP MASTG · Android app security best practices · Apple platform security
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases
日本語の概要は準備中です。原文の説明を表示しています。
Use when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level authorization, mass assignment and tenant scoping
日本語の概要は準備中です。原文の説明を表示しています。
Use on every UI change - semantic HTML, labels for controls, keyboard-navigable dialogs/menus, visible focus, and never color as the only signal
日本語の概要は準備中です。原文の説明を表示しています。
Use when a task changes any screen, form, dialog, menu or control - Lighthouse/axe scan of the changed screens, a keyboard walk, and the thresholds that fail a task
日本語の概要は準備中です。原文の説明を表示しています。
How to work a task returned with review, QA or UAT findings. Use when a task is in need_revision or PR review comments are in your context.
日本語の概要は準備中です。原文の説明を表示しています。
Use when deciding whether a request needs an analiz task before implementation - the conditions that require the architect's analysis versus going straight to implementation
日本語の概要は準備中です。原文の説明を表示しています。