◆ OWASP MASVS v2.1 ◆ MASWE 117+ Weaknesses ◆ MASTG Testing Guide CC BY-SA 4.0 Claude AI Skill

Mobile Securitymeets Artificial Intelligence.

Der komplette OWASP Mobile Application Security Standard als KI-Skill für Claude. Gebaut für Auditoren, Entwickler, Architekten und Compliance-Teams.

Claude Chat
You › "Analyze this IPA for MASVS compliance."
You › "What is MASWE-0013?"
You › "Create a threat model for our banking app."
✓ Skill activated · 7 roles · 24 controls · 117 weaknesses
24
MASVS Controls
117+
MASWE Weaknesses
7
Specialized Roles
20+
Security Tools

One Skill. Three OWASP Sources.

Consolidated from three separate OWASP repos into a single, AI-ready knowledge package with end-to-end audit workflow.

🛡️

OWASP MASVS

What to verify · 24 controls · 8 categories

The verification standard – defines security requirements. Produces audit checklists, requirements matrices, and compliance evidence.

🔍

OWASP MASWE

What to look for · 117+ weaknesses

The weakness enumeration – catalogs mobile-specific vulnerabilities with CWE mappings, severity ratings, and correlation analysis.

⚙️

OWASP MASTG

How to test · Techniques & Tools

The testing guide – provides concrete test procedures, tool references, and platform-specific test steps for Android and iOS.

Built for your workflow.

The skill adapts to your role – just describe what you need.

🔐 Auditor
MASVS checklists, findings, risk assessments. Full pentest workflow from IPA/APK to report.
audit checklist pentest
💻 Developer
Platform-specific secure coding patterns for Kotlin, Java, and Swift. Anti-patterns and best practices.
secure coding code review
🏗️ Architect
STRIDE threat models, architecture reviews, requirements matrices, and security architecture decision records.
threat model architecture
📊 Reporter
5 report formats including executive summaries, technical assessments, and compliance reports.
report executive summary
🧬 Weakness Analyzer
Look up any MASWE ID for details, CWE mappings, detection strategies, and remediation guidance.
MASWE-ID weakness
🔄 Updater
Self-sync with OWASP GitHub repos. Delta reports, cascading updates, automatic reference regeneration.
update skill check updates
🤖 Agent Output
Machine-readable YAML/JSON for AI pipelines. 5 schemas, 10 downstream triggers, 3 output modes.
YAML JSON pipeline

MASVS v2.1 – All 8 Categories.

Every control, every category, every platform. Plus regulatory mappings to GDPR, PCI DSS, BSI, and ISO 27001.

Category Controls Focus
MASVS-STORAGE2Secure data storage (data at rest)
MASVS-CRYPTO2Cryptographic operations & key management
MASVS-AUTH3Authentication & authorization
MASVS-NETWORK2Network communication (data in transit)
MASVS-PLATFORM3Platform interaction & IPC
MASVS-CODE4Code quality & secure build practices
MASVS-RESILIENCE4Reverse engineering & tampering
MASVS-PRIVACY4Privacy & data protection

Built for AI Pipelines.

Machine-readable output schemas for downstream agents. Every output ends with an agent_summary block for orchestration.

finding

Findings

Structured findings with evidence, severity, and remediation for ticket agents and CI/CD gates.

compliance

Compliance Matrix

MASVS matrix with pass/fail verdicts for GRC systems and compliance agents.

threat_model

Threat Model

STRIDE analysis with risk ratings for architecture and risk management agents.

weakness

Weakness Lookup

MASWE entries with detection and fix guidance for vulnerability management.

secure_coding

Secure Coding

Platform code patterns for code generation agents and PR review bots.

Install in 30 seconds.

Build a .skill file or install manually – then drag into any Claude chat.

Option A: .skill File

Build a ZIP archive and drag it into Claude.
# Clone & build git clone https://github.com/GodModeAI2025/owasp-mas-ai-skill.git cd owasp-mas-ai-skill/skill zip -r ../owasp-mas.skill . # → Drag owasp-mas.skill into Claude chat

Option B: Manual Copy

Copy the skill directory directly to your skills path.
# Copy to skills directory cp -r skill/ /path/to/skills/user/owasp-mas/ # That's it. The skill auto-activates # when you mention mobile security topics.
Created by Mark Zimmermann · LinkedIn · Podcast

Ready to secure
mobile apps with AI?

Open source, CC BY-SA 4.0 licensed. Issues, PRs, and contributions are welcome.

Star on GitHub Contribute →