Overall score
Based on 16 findings across security, architecture and production-readiness checks.
4 critical
5 high
6 medium
1 low
Score by category
Requested permissions
READ_CONTACTSACCESS_FINE_LOCATIONREAD_SMSINTERNET
AI Agent Security Assessment
AI Security Score
56
HIGH Risk
Violated AI Security Controls
AI-SEC-002
API Key & Credential Management
Authentication
AI-SEC-007
Error Handling & Secure Failures
Error Handling
AI-SEC-008
Monitoring & Anomaly Detection
Monitoring
AI-SEC-003
Sensitive Data in Prompts
Privacy
AI-SEC-009
AI Service Authentication & Authorization
Authentication
AI-SEC-013
Data Retention & Deletion
Privacy
AI-SEC-010
Third-Party AI Service Risk Management
Third-Party Integration
OWASP MASVS Compliance
Level 1 (Basic)
8/18 controls met
Level 2 (Advanced)
9/20 controls met
Level R (Resilience)
3/4 controls met
Violated Controls (12)
MASVS-CODE-2MASVS-CODE-3MASVS-STORAGE-1MASVS-CRYPTO-1MASVS-STORAGE-2MASVS-NETWORK-1MASVS-NETWORK-2MASVS-PLATFORM-2MASVS-CODE-4MASVS-PRIVACY-1MASVS-PLATFORM-1MASVS-RESILIENCE-1
Findings (16)
App is debuggable in production
AndroidManifest.xml:1
android:debuggable="true"
Your app is shipping in debug mode. This lets anyone connect to your app, read its internal data, and inspect how it works. It must be turned off before release.
How to fix
Remove android:debuggable="true" from the <application> tag, or set debuggable false in your release build type.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Debug mode in production violates build configuration requirements
AI Security Risks
Debug mode in production → API keys, prompts, and responses visible in debug output
Google API Key found in source
res/values/strings.xml:4
AIzaSyD-…WY
A Google API Key is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.
How to fix
Remove the Google API Key from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Hardcoded secrets violate secure storage and encryption requirements
AI Security Risks
Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data
Stripe Secret Key found in source
res/values/strings.xml:8
sk_live_…dc
A Stripe Secret Key is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.
How to fix
Remove the Stripe Secret Key from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Hardcoded secrets violate secure storage and encryption requirements
AI Security Risks
Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data
Razorpay Key found in source
res/values/strings.xml:6
rzp_live…2P
A Razorpay Key is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.
How to fix
Remove the Razorpay Key from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Hardcoded secrets violate secure storage and encryption requirements
AI Security Risks
Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data
Cleartext (HTTP) traffic allowed
AndroidManifest.xml:1
android:usesCleartextTraffic="true"
Your app allows unencrypted network connections. Data sent over these connections can be read or modified by anyone on the same network (public WiFi, etc).
How to fix
Set android:usesCleartextTraffic="false" and ensure all API calls use HTTPS. Use a network security config to enforce it.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Unencrypted data transmission violates TLS/encryption requirements
AI Security Risks
Unencrypted API calls → AI credentials and prompts exposed in transit
Exported components without permission protection
AndroidManifest.xml:1
<activity android:name="com.testapp.MainActivity" android:exported="true">
A part of your app (MainActivity) is open to other apps on the device without any protection. Malicious apps could trigger it or send it data.
How to fix
Add android:permission to the activity, or set android:exported="false" if it doesn't need to be accessed by other apps.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Unprotected exported components violate platform security
AI Security Risks
Exported component with AI credentials → Third-party can access AI services
Exported components without permission protection
AndroidManifest.xml:1
<service android:name="com.testapp.SyncService" android:exported="true">
A part of your app (SyncService) is open to other apps on the device without any protection. Malicious apps could trigger it or send it data.
How to fix
Add android:permission to the service, or set android:exported="false" if it doesn't need to be accessed by other apps.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Unprotected exported components violate platform security
AI Security Risks
Exported component with AI credentials → Third-party can access AI services
Hardcoded JWT found in source
assets/config.json:4
eyJhbGci…5N
A Hardcoded JWT is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.
How to fix
Remove the Hardcoded JWT from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Hardcoded secrets violate secure storage and encryption requirements
AI Security Risks
Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data
Hardcoded Secret / Token found in source
assets/config.json:4
auth_tok…N"
A Hardcoded Secret / Token is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.
How to fix
Remove the Hardcoded Secret / Token from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Hardcoded secrets violate secure storage and encryption requirements
AI Security Risks
Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data
Auto backup enabled — app data exposed
AndroidManifest.xml:1
android:allowBackup="true"
Your app's data can be copied off the device through Android backup. If it stores anything sensitive (tokens, user data), that data leaves the device unprotected.
How to fix
Set android:allowBackup="false" in the <application> tag unless you specifically need backups.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Sensitive data exposed to unauthorized parties
AI Security Risks
Sensitive data exposure → Including via error messages leaking to LLM or exposed in logs
Sensitive permissions requested
AndroidManifest.xml:1
android.permission.READ_CONTACTS
android.permission.ACCESS_FINE_LOCATION
android.permission.READ_SMS
Your app requests permissions to: read all contacts, precise GPS location, read SMS messages. Each sensitive permission you request that isn't strictly needed increases privacy risk and can hurt Play Store approval. Review whether all of these are required.
How to fix
Remove any permission from AndroidManifest.xml that your app does not actively use. Request sensitive permissions at runtime, only when the feature is used.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Excessive permissions violate principle of least privilege
AI Security Risks
Excessive permissions → AI service can access more data/features than needed
Target SDK version is outdated
AndroidManifest.xml:1
targetSdkVersion="28"
Your app targets an older Android version (API 28). Google Play requires recent target versions for new apps and updates. An old target also misses newer security protections.
How to fix
Update targetSdkVersion to 34 or higher in build.gradle and test thoroughly.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Dependencies with known vulnerabilities bypass security controls
AI Security Risks
Vulnerable AI SDK or dependency → Compromise of LLM integration layer
Firebase Database URL found in source
assets/config.json:5
https://…om
A Firebase Database URL is stored directly in your app's files. Anyone can extract this from your published app in minutes and use it — potentially running up bills on your account or accessing your backend. This is the most common serious issue we find.
How to fix
Remove the Firebase Database URL from the code. Store secrets on your backend server and have the app request them at runtime, or use a secrets manager. If this key was exposed, rotate (regenerate) it immediately.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Hardcoded secrets violate secure storage and encryption requirements
AI Security Risks
Hardcoded API keys for AI services → Anyone with code access can use your API quota and access sensitive data
No certificate pinning detected
Certificate pinning configuration
1 dex file and 0 res/xml files scanned — no pin-set element or known pinning library found
The app does not appear to pin certificates — neither a Network Security Config <pin-set> nor a known pinning library (OkHttp, TrustKit) was found. Without pinning, a compromised or coerced Certificate Authority (or a device with a malicious root CA installed) can intercept the app's traffic even over HTTPS.
How to fix
Add a Network Security Config with a <pin-set> for your API domains, or use a library like OkHttp's CertificatePinner or TrustKit.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Improper TLS validation allows MITM attacks, violates network security
AI Security Risks
MITM attacks possible → API credentials and sensitive data intercepted
No root detection found
Root detection
1 dex file scanned — no known root-detection library found
The app does not appear to check whether it is running on a rooted device — no known root-detection library (RootBeer, Play Integrity, SafetyNet, freeRASP) was found. On a rooted device, an attacker with elevated privileges can bypass app-level protections, extract secrets from memory, or tamper with the app at runtime.
How to fix
Integrate a root-detection library (Play Integrity API is Google's current recommendation) and respond appropriately (warn, restrict functionality, or block) on rooted devices for sensitive features.
Violated MASVS Controls
Missing anti-tampering protection allows attackers to bypass app-level security controls
No network security config defined
AndroidManifest.xml:1
networkSecurityConfig not set
Your app has no network security configuration. This is a missed opportunity to enforce HTTPS-only connections and certificate pinning at the system level.
How to fix
Add a network_security_config.xml restricting cleartext traffic and reference it via android:networkSecurityConfig in the <application> tag.
Defensive Measures (D3FEND)
Apply these MITRE D3FEND techniques to mitigate similar vulnerabilities
Violated MASVS Controls
Improper TLS validation allows MITM attacks, violates network security
AI Security Risks
MITM attacks possible → API credentials and sensitive data intercepted
Scope: This is an automated audit based on static analysis of your app. It catches common security, quality and production-readiness issues but is not a substitute for a full manual security review for apps handling sensitive financial or health data. Findings marked “suspected” are strong signals to confirm against your live setup.
Your data: uploaded code is processed in memory and never written to disk. This report is kept only so you can view it, and auto-deletes after 24 hours.