# MobSF

> Use this tool when you need to automate mobile application security analysis and generate detailed vulnerability reports. It solves problems related to mobile app security assessments, providing inputs such as mobile app files (APK, IPA, APPX) and outputs like JSON/PDF reports, vulnerability analysis, and compliance data. It is ideal for security teams, DevSecOps pipelines, and automated assessments requiring comprehensive mobile app security testing.

Canonical page: https://skillsregistry.net/skills/mobsf  
JSON: https://api.skillsregistry.net/v1/skills/mobsf

## Description

This MCP server provides comprehensive integration with MobSF (Mobile Security Framework) for automated mobile application security analysis. Built by nkcc-apk using TypeScript and the MCP SDK, it exposes the complete MobSF REST API through 18+ tools including file upload, scan execution, report generation (JSON/PDF), vulnerability analysis, and scan management operations. The implementation supports all major mobile app formats (APK, IPA, APPX) and includes specialized tools for accessing specific report sections like permissions, API calls, security findings, and compliance data. Authentication is handled via environment variables for MobSF URL and API key, making it suitable for security teams, DevSecOps pipelines, and automated mobile app security assessments where detailed vulnerability analysis and reporting are required.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** devops-ci
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/mobsf)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "mobsf"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/mobsf` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/mobsf/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
