Dagfinn - Mobile Application Security Engineer AI Skill
# Dagfinn - Mobile Application Security Engineer
## Who Dagfinn Is
Drop Dagfinn into Claude and get a mobile application security engineer who has taken an app
whose team was proud of its root detection, its obfuscation and its jailbreak checks, and
bypassed all three in under twenty minutes with a public Frida script, then found the finding
that actually mattered: a session token written to an unencrypted SQLite file and included in
the device backup, which needed no bypass at all and no rooted device. He is candid that
client-side defences raise cost and do not create trust boundaries, and that a mobile team's
security budget is nearly always spent in the wrong ratio: too much on making reverse
engineering slower, too little on the server refusing to trust what the client says. Dagfinn
tests as an attacker with authorisation, then designs the controls that make that attacker's
work worthless rather than merely slower.
Dagfinn covers the whole mobile surface: MASVS-aligned assessment across storage,
cryptography, authentication, network, platform interaction, code quality and resilience;
Once the file is loaded, talk to it by name: “Serge, check this page.” That is what the name is for. It also keeps several skills apart in one chat.
You are Dagfinn, a Mobile Application Security Engineer who assesses iOS and Android apps against MASVS using MASTG procedures, with Frida, objection and jadx. You have been activated to find what your binary and storage reveal.
$4.92/mo, billed yearly. Works in Claude, ChatGPT, Claude Code, Codex and Cursor. Cancel anytime, 14-day refund on the first charge. After checkout we email your setup link.
Complete skill package instant downloaddagfinn-mobile-application-security-engineer.md
Pay once, keep foreverInstant download30-day money-back guarantee
Secure checkout by Shopify
Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.
Ask Dagfinn something hard.
Or have every skill inside your AI.
Questions before you buy? A person answers, usually the same day: hello@kissmyskills.com
// what's inside
What's inside this skill
- MASVS and MASTG assessment of iOS and Android builds
- Keychain, keystore and biometric binding done correctly
- Deep links, exported components and WebView hardening
- SDK supply chain, anti-tamper trade-offs and secure release
Mobile teams shipping a regulated or high-value app who need a real security assessment rather than a store checklist.
What you're actually buying
Drop Dagfinn into Claude and get a mobile security engineer who will tell you plainly that your app can be decompiled, then harden what actually matters.
Dagfinn secures iOS and Android applications end to end against MASVS and MASTG: static and dynamic analysis of mobile binaries, authorized reverse engineering of an APK or IPA with jadx, Frida, objection and Hopper and hardening against exactly those techniques, insecure local storage, keychain and keystore usage, biometric authentication bound to a cryptographic operation rather than a UI gate, certificate pinning and transport security with realistic bypass expectations, deep link and intent handling, exported components, WebView hardening and JavaScript bridges, third-party SDK and mobile supply chain risk, runtime protection, root and jailbreak detection and its genuinely limited value, obfuscation and anti-tamper trade-offs, mobile API abuse and client-side secrets that must not exist, permission hygiene and store privacy requirements, and secure release and code signing.
What you get
- →MASVS and MASTG assessment of iOS and Android builds
- →Keychain, keystore and biometric binding done correctly
- →Deep links, exported components and WebView hardening
- →SDK supply chain, anti-tamper trade-offs and secure release
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Dagfinn builds the answer. Includes a full worked example so you see exactly what you get.
Four steps. Any AI chat.
- 01Download the file
After checkout, the download link lands in your inbox. Save the file anywhere on your device.
- 02Open your AI chat
Claude, ChatGPT, Gemini, Grok, or Copilot - whichever one you already use.
- 03Paste the file contents
Drop it into the system prompt, Project instructions, or custom instructions field.
- 04Start working
Your AI is now configured as a specialist. Ask it anything inside its domain.
No technical knowledge required.
With Unlimited there is nothing to download. Connect your AI once, then just ask: "Load Dagfinn from KissMySkills."
Questions about this product
What does the Dagfinn skill do?+
Harden your mobile app where it counts: storage, keys, biometrics, transport, components and the client-side secrets that should not be there. Load it once into Claude Projects and you get a configured Mobile Application Security Engineer without re-explaining context at the start of every session. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
How do I install this skill file?+
Download the .skill package (it contains SKILL.md), paste the contents into Claude Projects Instructions or your AI's system prompt, add your own context and start your first session. Works with Claude, ChatGPT, or any AI chat that accepts system prompts.
Which AI tools does this skill work with?+
Works with Claude (recommended), ChatGPT, Gemini, Perplexity and Copilot, and any AI chat that accepts system prompts. Claude Projects gives the best results.
What is included in this download?+
One .skill package delivered instantly after purchase: the full SKILL.md role configuration plus a worked-example file with a real scenario so you see the quality before you rely on it. Pay once, keep forever, yours permanently.
How is this different from using Claude without the Dagfinn skill?+
Without a skill file your AI starts every session as a general assistant. With Dagfinn loaded it applies Mobile Application Security Engineer methodology from the first message, with consistent quality every time. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
Do I have to read it myself?+
No. The file is written for your AI to read, not for you. Upload it or paste it in once and the AI takes on the role. After that you just ask it questions the way you normally would. You're welcome to open it and read it, but nothing here depends on you doing that.