LogoClawIndex
CasesSkillsAbout
LogoClawIndex

api-pivot - Map backend API risks from Android apps

Analyzes decompiled Android code and Burp traffic to identify API surfaces and guide authorized testing of server-side vulnerabilities.

Tags

Updated: 2026-10-02

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Scan decompiled API code
  • Extract endpoint templates
  • Identify authentication carriers
  • Map server-side bug classes
  • Seed Burp API testing
  • Check testing scope

Inputs

  • Decompiled Android sources
  • Burp proxy history
  • threat_model.json
  • inventory.json
  • Target SHA-256 hash
  • Authorized test accounts
  • In-scope API hosts

Outputs

  • api_surface.json static report
  • Candidate API hosts and endpoints
  • Authentication attachment locations
  • Server-side testing guidance

Requirements

  • Authorized security testing
  • Confirmed in-scope API hosts
  • Python runtime

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
mobile security
API security
Android
static analysis
Burp Suite
bug bounty
Scan decompiled API code
Extract endpoint templates
Identify authentication carriers
Map server-side bug classes
Decompiled Android sources
Burp proxy history
threat_model.json
api_surface.json static report
Candidate API hosts and endpoints
Authentication attachment locations