{"repo":"actuator/pSlip","free":true,"listed":false,"github":"https://github.com/actuator/pSlip","clone":"git clone https://github.com/actuator/pSlip.git","description":"pSlip is an Android static analysis tool kit designed to find potentially vulnerable escalation paths by analyzing exported components, intent filters, provider permissions and cryptographic misuse","language":"Python","stars":27,"topics":["android","exploitation-framework","mobile","python","application-security","hardcoded-credentials","intent-injection","vulnerability-scanners","mobile-security-testing","pslip"],"license":"Apache-2.0","category":"mobile-apps","readme_excerpt":"--- What's New (v1.4.0) Report-layer release. The HTML report engine was rewritten; the detection, manifest, OAuth, and crypto-recovery passes are byte-identical to v1.3.5, so scan behavior and findings are unchanged. Searchable HTML report The report search box is now a field-scoped query language instead of a package-name filter, and a match returns the findings that match, not just the app name: - Scopes: pkg: issue: comp: conf: details: adb: sev: key: - Presence tests: has:key , has:adb , has:poc - \"quoted phrases\" , -negation (scopeable, e.g. -sev:info ), and /regex/ (scopeable, e.g. pkg:/^com\\.(samsung sec)\\./ ; invalid regex is ignored rather than thrown) - Terms are ANDed, matching is case-insensitive, 160 ms debounce - An issue-type dropdown ANDs with the severity chips. A filtered app shows only its matching findings, with a \"Show all N\" escape. - Keyboard: / focuses search, Esc clears, ? toggles the syntax help panel. Key material extraction and export Recovered crypto/OAuth values are now pulled out of each finding's Details and surfaced as structured artifacts ( aes-key , des-key , iv , segment-write-key , oauth-client-id , oauth-client-secret ; the OAuth secret stays redacted in the report): - A dedicated Key Material & Secrets section, filterable by kind and scopeable to the current search. - One-click export of the current view, a single app, or all key material as CSV (RFC-4180 with a UTF-8 BOM for Excel), JSON, Markdown, or clipboard copy - including \"Export","default_branch":null,"files":null,"tree":[],"storefront":"/r/actuator","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/actuator/pSlip/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}