# alvinhayy

> Open-source publisher. Listings imported from github.com/alvinhayy — credited to the original author with their license.

- **Listings:** 3
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/alvinhayy
- **Website:** https://github.com/alvinhayy

## Published listings

- [Mobile Vuln Hunt](https://agentstack.voostack.com/l/skill-alvinhayy-mobile-reverseskill-mobile-vuln-hunt) — Skill · Free · security-reviewed — `agentstack add skill-alvinhayy-mobile-reverseskill-mobile-vuln-hunt`
  Hunt mobile vulnerability classes in decompiled Android (jadx/apktool) and iOS (class-dump/otool/nm) trees — ripgrep signature scan first (zero deps), optional semgrep taint analysis for dataflow classes, then triage (exported check, attacker-APK discipline) and pick the matching dynamic PoC (adb/drozer/Frida) per class from the bundled reference docs.
- [Afl Fuzzing](https://agentstack.voostack.com/l/skill-alvinhayy-mobile-reverseskill-afl-fuzzing) — Skill · Free · security-reviewed — `agentstack add skill-alvinhayy-mobile-reverseskill-afl-fuzzing`
  Greybox fuzz Android native libraries (.so) on-device with AFL++ — cross-compile the fuzzer for Android arm64, harness a JNI parser with a stub JNIEnv, detect memory bugs with ASan/libdislocator, and validate the harness actually reaches the target.
- [Reverse Engineer](https://agentstack.voostack.com/l/skill-alvinhayy-mobile-reverseskill-reverse-engineer) — Skill · Free · security-reviewed — `agentstack add skill-alvinhayy-mobile-reverseskill-reverse-engineer`
  Perform static analysis on Android APK, iOS IPA, or bundled web apps to extract endpoints, secrets, permissions, code flow, and other security-relevant data

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
