{"id":50203453,"url":"https://github.com/s7safe/android-h1","last_synced_at":"2026-06-11T16:00:30.424Z","repository":{"id":333427623,"uuid":"1137265152","full_name":"s7safe/android-h1","owner":"s7safe","description":"移动安全漏洞挖掘专家SKILL，基于 HackerOne 真实报告的移动安全漏洞挖掘知识库，提供 Android 和 iOS 应用的漏洞挖掘手法、技术细节和代码模式分析。","archived":false,"fork":false,"pushed_at":"2026-02-10T03:14:06.000Z","size":1453,"stargazers_count":99,"open_issues_count":1,"forks_count":27,"subscribers_count":2,"default_branch":"main","last_synced_at":"2026-02-10T08:34:31.999Z","etag":null,"topics":["android","android-app","bug-bounty","bugbounty","hackerone","skill"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/s7safe.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-01-19T06:26:02.000Z","updated_at":"2026-02-10T07:27:45.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/s7safe/android-h1","commit_stats":null,"previous_names":["s7safe/android-h1"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/s7safe/android-h1","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/s7safe%2Fandroid-h1","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/s7safe%2Fandroid-h1/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/s7safe%2Fandroid-h1/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/s7safe%2Fandroid-h1/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/s7safe","download_url":"https://codeload.github.com/s7safe/android-h1/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/s7safe%2Fandroid-h1/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34206492,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-11T02:00:06.485Z","response_time":57,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["android","android-app","bug-bounty","bugbounty","hackerone","skill"],"created_at":"2026-05-26T00:00:42.983Z","updated_at":"2026-06-11T16:00:30.406Z","avatar_url":"https://github.com/s7safe.png","language":null,"funding_links":[],"categories":["📱 Android / IOS 安全分析"],"sub_categories":[],"readme":"移动安全漏洞挖掘专家 (Mobile Security Expert)\n一句话介绍\n基于 HackerOne 真实报告的移动安全漏洞挖掘知识库，提供 Android 和 iOS 应用的漏洞挖掘手法、技术细节和代码模式分析。\n\n\n**注意：在ai 并行进行收集元数据的时候并未禁止推测功能 有的报告是通过标题，进一步通过博客和多语种进行推测得出的测试过程**\n\n**注意：作为知识库进行学习，或者加入ai辩论进行总结训练价值最好**\n\n\n适用人群\n\n    移动应用安全研究员\n    渗透测试工程师\n    Bug Bounty 猎人（特别是 HackerOne 平台）\n    应用开发人员（用于安全审计）\n    移动安全学习者\n\n核心能力\n1. Android 漏洞挖掘\n\n    业务逻辑缺陷（2FA 逻辑漏洞、权限绕过）\n    组件安全（Activity/Service 不安全暴露）\n    数据存储安全\n    API 接口安全\n\n2. iOS 漏洞挖掘\n\n    URL Scheme 处理漏洞\n    Deep Link CSRF 攻击\n    WebView 信息泄露\n    数据保护问题\n\n3. 智能分析\n\n    代码模式识别：对比已知漏洞模式，快速定位风险点\n    挖掘手法指导：提供详细的步骤和工具使用方法\n    技术细节讲解：深入解释漏洞原理和利用方式\n    真实案例参考：基于 HackerOne 公开报告\n\n使用场景\n\n    \"如何挖掘 Android 应用的 Activity 认证绕过漏洞？\"\n    \"帮我分析这段 iOS 代码是否存在 URL Scheme 漏洞\"\n    \"HackerOne 上关于 2FA 漏洞的经典案例有哪些？\"\n    \"使用什么工具可以检测移动应用的安全问题？\"\n\n特色优势\n\n✅ 真实案例：所有内容来自 HackerOne 公开报告，实战价值高\n\n✅ 结构化知识：每个案例包含挖掘手法、技术细节、代码模式三部分\n\n✅ 智能体驱动：无需复杂工具配置，直接对话获取指导\n\n✅ 持续扩展：可不断添加新的漏洞类型和案例\n\n\n技术实现\n\n    完全基于智能体的自然语言理解能力\n    无需安装额外脚本或工具\n    支持代码分析和漏洞模式识别\n    提供详细的挖掘步骤和命令参考\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fs7safe%2Fandroid-h1","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fs7safe%2Fandroid-h1","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fs7safe%2Fandroid-h1/lists"}