api-pivot - Map backend API risks from Android apps
Analyzes decompiled Android code and Burp traffic to identify API surfaces and guide authorized testing of server-side vulnerabilities.
Tags
Updated: 2026-10-02Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Scan decompiled API code
- Extract endpoint templates
- Identify authentication carriers
- Map server-side bug classes
- Seed Burp API testing
- Check testing scope
Inputs
- Decompiled Android sources
- Burp proxy history
- threat_model.json
- inventory.json
- Target SHA-256 hash
- Authorized test accounts
- In-scope API hosts
Outputs
- api_surface.json static report
- Candidate API hosts and endpoints
- Authentication attachment locations
- Server-side testing guidance
Requirements
- Authorized security testing
- Confirmed in-scope API hosts
- Python runtime
