# Ios Security Auditor

> A Claude skill from gygantskiyMatilyock/ios-developer-agents.

- **Type:** Skill
- **Install:** `agentstack add skill-gygantskiymatilyock-ios-developer-agents-ios-security-auditor`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [gygantskiyMatilyock](https://agentstack.voostack.com/s/gygantskiymatilyock)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [gygantskiyMatilyock](https://github.com/gygantskiyMatilyock)
- **Source:** https://github.com/gygantskiyMatilyock/ios-developer-agents/tree/master/.claude/skills/ios-security-auditor

## Install

```sh
agentstack add skill-gygantskiymatilyock-ios-developer-agents-ios-security-auditor
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# iOS Security Auditor

Use this skill to perform comprehensive security audits of iOS applications against OWASP Mobile Top 10 2024 and Apple security best practices.

## When to Use

- Before releasing to production
- After implementing authentication or payment features
- When handling sensitive user data
- During security review sprints
- After adding third-party SDKs
- When preparing for security certifications

## How to Apply

Read the full agent prompt from `agents/security-auditor/security-auditor.md` in the ios-developer-agents repository.

Follow the audit process covering OWASP Mobile Top 10 2024:

1. **M9: Data Storage Security** - Keychain, UserDefaults, file protection
2. **M1: Hardcoded Secrets** - API keys, tokens, credentials in code
3. **M5: Network Security** - ATS, TLS, certificate pinning
4. **M3: Authentication/Authorization** - Session management, token handling
5. **M4: Input Validation** - SQL injection, XSS, path traversal
6. **M7: Binary Protections** - Build settings, anti-tampering
7. **M2: Supply Chain** - Dependency vulnerabilities
8. **M6: Privacy/Data Leakage** - Logging, pasteboard, screenshots
9. **M8: Security Misconfiguration** - Info.plist, entitlements, WebViews

## Output Format

Provide structured findings with:
- OWASP Mobile Top 10 2024 coverage table
- Critical vulnerabilities (immediate action)
- High/Medium/Low risk issues
- Hardcoded secrets scan results
- Data storage audit
- Network security checklist
- Third-party dependencies review

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [gygantskiyMatilyock](https://github.com/gygantskiyMatilyock)
- **Source:** [gygantskiyMatilyock/ios-developer-agents](https://github.com/gygantskiyMatilyock/ios-developer-agents)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-gygantskiymatilyock-ios-developer-agents-ios-security-auditor
- Seller: https://agentstack.voostack.com/s/gygantskiymatilyock
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
