惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
Arctic Wolf
有赞技术团队
有赞技术团队
H
Help Net Security
N
Netflix TechBlog - Medium
G
Google Developers Blog
GbyAI
GbyAI
Jina AI
Jina AI
D
DataBreaches.Net
博客园 - Franky
Recent Announcements
Recent Announcements
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
N
News | PayPal Newsroom
S
SegmentFault 最新的问题
B
Blog RSS Feed
Google DeepMind News
Google DeepMind News
S
Schneier on Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
V
V2EX
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 【当耐特】
P
Privacy International News Feed
T
The Exploit Database - CXSecurity.com
云风的 BLOG
云风的 BLOG
F
Full Disclosure
Microsoft Security Blog
Microsoft Security Blog
MongoDB | Blog
MongoDB | Blog
V
Vulnerabilities – Threatpost
C
CERT Recently Published Vulnerability Notes
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
爱范儿
爱范儿
C
Cyber Attacks, Cyber Crime and Cyber Security
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
Spread Privacy
Spread Privacy
罗磊的独立博客
P
Proofpoint News Feed
The Last Watchdog
The Last Watchdog
S
Secure Thoughts
O
OpenAI News
P
Palo Alto Networks Blog
The Cloudflare Blog
Microsoft Azure Blog
Microsoft Azure Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
T
Tenable Blog
雷峰网
雷峰网
C
Cisco Blogs

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店 GitHub - EdoardoBambini/Agent-Armor-Iaga: AI agents are getting tool access — shell, file system, databases, APIs, secrets. But **nobody is governing what they actually do with it**. Frameworks like LangChain, CrewAI, AutoGen, and Claude Code give agents the power to execute. Agent Armor gives you the power to control, audit, and approve every single action before it happens. HN Vibes — Week 15, Apr 7–13 2026 GitHub - chojs23/ec: Easy terminal-native 3-way git mergetool vim-like workflow GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - JakOb-dotcom/cloud-sandbox-security-analysis: Technical analysis and Proof of Concept (PoC) regarding environment variable exfiltration in containerized cloud sandboxes via side-channel data leaks. Springboards - Flint Alpha Show HN: A simpler coding agent harness GitHub - audiodude/sudomake-friends GitHub - 256thFission/mini-mythos: OSS clone of Anthropic’s Mythos harness to locate C/C++ memory vulnerabilities Show HN: OpenParallax: OS-level privilege separation for AI agent execution Hacker News Sorted - Chrome 应用商店 Show HN: How to Install Docker on Ubuntu 24.04 LTS: Complete 2026 Guide GitHub - himanshudongre/smriti GitHub - sverrirsig/claude-control: macOS desktop dashboard for monitoring and managing multiple Claude Code sessions GitHub - ory/dockertest: Write better integration tests! Dockertest helps you boot up ephermal docker images for your Go tests with minimal work. Chiral - Chrome 应用商店 Show HN: Two Claudes collaborating through shared memory on a $100 mini-PC GitHub - pmichaillat/latex-cv: Minimalist LaTeX template for academic CVs GitHub - oguzbilgic/posse: A web UI for Anthropic Managed Agents. GitHub - sshiraz/depsly: Dependency risk analysis tool for npm packages ABI Add safari/agent-harness — Safari browser automation via safari-mcp by achiya-automation · Pull Request #212 · HKUDS/CLI-Anything GitHub - Halfblood-Prince/trustcheck: Verify PyPI package attestations and improve Python supply-chain security GitHub - oguzbilgic/kern-ai: Agents that do the work and show it. GitHub - bruits/satteri: High-performance Markdown and MDX processing for the JavaScript ecosystem GitHub - tylergibbs1/feedstock: High-performance web crawler and scraper for TypeScript, powered by Bun and Playwright GitHub - Grimm67123/grimmbot: The self-improving sandboxed and open-source AI agent. With persistent memory and scheduling. GitHub - whitevanillaskies/whitebloom: Local whiteboard that blooms. GitHub - hwdsl2/docker-whisper: Docker image for a self-hosted Whisper speech-to-text server with speaker diarization and OpenAI-compatible transcription and translation APIs. Powered by faster-whisper. Supports all Whisper models, NVIDIA GPU (CUDA) acceleration, JSON/SRT/VTT output, SSE streaming, offline mode, and multi-arch (amd64, arm64). GitHub - yisding/reviewwiggum GitHub - MarwanAlsoltany/serrors: Structured errors for Go: sentinel hierarchies, typed data, custom formatting, and slog integration. GitHub - soatok/age-php GitHub - Luthiraa/markitme GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits GitHub - tombedor/excalicharts GitHub - wh1le/excalidraw-edit: Open and edit .excalidraw files from the terminal. Offline, auto-saves to disk. MalExt Sentry - Malicious Extension Scanner - Chrome 应用商店 GitHub - syi0808/asciianimesvg: Generate animated ASCII art SVGs from text. CLI, Rust library, WASM, and web editor. GitHub - zaina-ml/ml_forge: A visual-based graph node editor for training computer vision models. GitHub - anakin87/llm-rl-environments-lil-course: 🌱 A little course on Reinforcement Learning Environments for evaluating and training Language Models GitHub - takaakit/superpowers-uml: Superpowers-UML modifies Superpowers to ensure a software development workflow in which AI agents design through UML modeling. AdriByte Studio - Sviluppo Web e Soluzioni Digitali GitHub - chouligi/angel-copilot: Your personalized Angel Investment Advisor Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 GitHub - agenteractai/lodmem: Level Of Detail Context Management for Agents GitHub - ostefani/subnetlens: A fast, concurrent network scanner with a TUI and plain-text CLI, built in Go. It discovers live hosts on your network, scans their open ports, resolves hostnames, and fingerprints operating systems—delivered. Cyber Pulse: Agentic Intel - Apps on Google Play Whisper API: Self-Hostable Speech to Text Transcription The Agent-Web Protocol Stack: A Research Thesis GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Show HN: Provepy – A Python decorator that proves your code using Lean and LLMs Show HN: Pardonned.com – A searchable database of US Pardons GitHub - patrickdappollonio/dux: Dux is a terminal UI that lets you run multiple AI coding agents side by side, each in its own git worktree, with full companion terminals, macros, commit generation, and a command palette that knows more tricks than you do. kMC Crystal Simulator Show HN: HyperFlow – A self-improving agent framework built on LangGraph GitHub - stef41/vibescore: 🎵 Grade your vibe-coded project. One command, instant letter grade across security, quality, dependencies, and testing. GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. imgur.com GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. GitHub - nowork-studio/toprank: Open-source Claude Code skills for SEO, SEM, Google Ads GitHub - tacomanator/sash: Lightweight macOS menu bar app for reliably cycling through windows of the current application. Appents | Social Media Management for Product-First Teams GitHub - pnhoang/youtube-spam-blocker: Automatically detects and hides spam messages in YouTube Live chat. Set rate limits, keyword filters, and block repeat offenders. GitHub - decisionnode/DecisionNode: CLI + Local MCP - A shared structured memory store across Claude Code, Cursor, Windsurf, Antigravity, and every MCP client. Semantically queryable. GitHub - AvaCodeSolutions/django-email-learning: An open source Django app for creating email-based learning platforms with IMAP integration and React frontend components. The $100K Gap in Kubernetes Security Tooling Function Calling Harness: From 6.75% to 100%
GitHub - sterrasec/apk-interceptor: Android deeplink, Intent, and WebView bridge assessment helper for ethical hacking
tkmru · 2026-06-20 · via Hacker News: Show HN

Build Check

Android deeplink, Intent, and WebView bridge assessment helper

apk-interceptor is a portable Android testing APK for authorized application security assessments. It helps security engineers verify how an Android app handles external entry points such as custom URI schemes, deeplinks, exported Activities, and WebView JavaScript bridges.

The tool is intentionally constrained:

  • It does not declare android.permission.INTERNET
  • It does not send data to external servers
  • It does not execute shell commands
  • It does not require root, Magisk, Frida, or runtime instrumentation
  • It serves only one local content:// payload file
  • It registers one custom URI scheme fixed at build time

Motivation

During Android application security assessments, many findings from static analysis still need a small on-device proof of concept before they can be confirmed: registering a custom URI scheme, sending an explicit Intent, serving a local content:// payload, or checking whether JavaScript can reach a WebView bridge.

Building a new throwaway test app for each case is repetitive and error-prone. Small differences in manifest entries, authorities, URI grants, package names, or Intent construction can slow down verification and make results harder to reproduce.

apk-interceptor was created to make that confirmation step repeatable. Instead of writing a new PoC APK for every assessment, you build this tool with the authorized scheme or application ID you need, run the test on-device, and keep the workflow constrained by design: no INTERNET permission, no external data transmission, no shell execution, and no root dependency.

What You Can Test

apk-interceptor is useful for these assessment tasks:

Scenario Module What It Helps Verify
Custom URI scheme hijacking Interceptor Whether another app can register the same custom scheme and receive links
Deeplink parameter handling Sender Whether the assessed app accepts unsafe query/path parameters
Exported Activity exposure Sender Whether an exported Activity can be launched directly by another app
WebView bridge exposure via content:// Payload + Sender Whether a local HTML payload can reach a WebView JavaScript bridge
Local payload syntax check Payload Whether your HTML/JS payload runs in the self-test WebView

Detailed vulnerability walkthroughs:

The app keeps an in-memory assessment log for sent Intents, received deeplinks, bridge callbacks, JavaScript results, and errors. Logs disappear when the app process is killed. Because logs are not persisted, capture evidence with screenshots or screen recording as you work.

How It Compares

apk-interceptor is a confirmation tool, not a discovery or exploitation framework. It assumes you already know what to test (scheme, Activity class, bridge name) from static analysis, and gives you a safe, on-device way to verify reachability and capture evidence. It is built to be installed on an assessment device and even shared with a client, so it ships no INTERNET permission, no shell execution, no data exfiltration, and no root requirement.

Where it sits next to the usual Android tooling:

Tool Role How apk-interceptor differs
jadx / MobSF / QARK / Semgrep Find vulnerable entry points (static) apk-interceptor does not scan or decompile; it confirms a finding you already have
deep-C / NSdeepLink / adb am start Enumerate and send deeplinks apk-interceptor can also send, but its differentiator is receiving a hijacked scheme and showing the exact URI and parameters
drozer General on-device attack framework (agent + often root) apk-interceptor is a single lightweight APK with deliberate safety guardrails, narrower scope, and easier client-safe distribution
Metasploit / Frida Weaponize or hook (e.g. addJavascriptInterface RCE) apk-interceptor only checks bridge reachability with a harmless payload; it never exfiltrates or executes shell commands

The two areas where apk-interceptor has the clearest edge over the alternatives:

  • Scheme-hijack evidence — acting as the second app that actually registers the scheme and logging every received parameter, which adb/static analysis cannot show.
  • content:// → WebView bridge verification — a non-exported, single-file provider whose payload is delivered only through a temporary Intent read grant, plus a local self-test WebView to validate payload syntax first.

Sending Versus Intercepting

apk-interceptor treats sending and intercepting differently, and this is the most important thing to understand before using it:

Action Module Custom scheme needed at build time?
Send an Intent or deeplink to another app Sender No — type any URI, package, or Activity at runtime
Intercept (receive) a deeplink for a custom scheme Interceptor Yes — the scheme is fixed into the APK at build time

To send a crafted deeplink to the assessed app, you do not need to rebuild: use the Sender tab's Implicit Deeplink mode and type any URI.

To intercept a deeplink — that is, to make Android route a custom scheme to apk-interceptor so you can observe a possible scheme-hijack — you must build the APK with that scheme via --scheme. The scheme is fixed at build time on purpose (a design guardrail); apk-interceptor never registers arbitrary schemes at runtime. If you change the scheme you are assessing, rebuild and reinstall.

Requirements

  • Android Studio with Android SDK 35
  • Android 12+ device or emulator
  • JDK 17+
  • adb for device installation and optional command-line testing

Build And Install

Build the APK with the custom URI scheme you are authorized to assess:

./build-interceptor.sh --scheme <authorized_custom_scheme>
adb install ./out/apk-interceptor-<authorized_custom_scheme>-debug.apk

Optional build flags:

./build-interceptor.sh \
  --scheme <authorized_custom_scheme> \
  --app-id <custom.application.id> \
  --output ./out

--app-id sets the installed application ID (the package identity on the device and the content://<applicationId>.payload authority) at build time. The default is com.sterrasec.apkinterceptor. Override it with --app-id when you need multiple separately installable builds for different assessments. The Windows equivalent is build-interceptor.bat.

The default scheme intercept-poc-example is a harmless placeholder. The build script refuses to produce an assessment APK with that default scheme.

First Launch

On first launch for each app version, apk-interceptor shows an authorized-use dialog. After you tap I understand, the same version does not show the dialog again. The Sender tab still shows a persistent warning because it can send Intents to other apps.

Authorized use dialog

Screenshots

Sender Payload Interceptor
Sender tab Payload tab Interceptor tab

App Modules

Interceptor

Use this tab to verify custom URI scheme interception.

What it shows:

  • The scheme compiled into this APK
  • A warning if the dummy default scheme is still in use
  • Received deeplink logs
  • A test query parameter field
  • Send Test Deeplink
  • Clear

Basic workflow:

  1. Build the APK with the assessed custom scheme.
  2. Install it alongside the assessed app.
  3. Trigger a deeplink for that scheme from the assessed flow, browser, adb, or the built-in Send Test Deeplink button.
  4. If Android routes the link to apk-interceptor, open the Interceptor tab and review the received URI and query parameters.

About Send Test Deeplink: it always sends <scheme>://test?<your params> with a fixed test host, so it is meant for confirming that apk-interceptor receives and logs the scheme — not for driving the assessed app's specific deeplink routes. To send a crafted deeplink that matches the assessed app's required host or path, use the Sender tab's Implicit Deeplink mode instead.

adb example:

adb shell am start -W \
  -a android.intent.action.VIEW \
  -d 'my-authorized-scheme://test?source=adb\&message=hello%20world'

Use \& when sending multiple query parameters through adb shell; otherwise the device shell may treat & as a command separator.

Expected result:

  • apk-interceptor opens to the Interceptor tab
  • A RECEIVED log entry appears
  • Tapping the log entry expands the full URI and parameter list

Sender

Use this tab to send controlled Intents during an authorized test.

Modes:

  • Implicit Deeplink: sends Intent(ACTION_VIEW, Uri.parse(uri))
  • Explicit Activity: sends an Intent to a specific package and Activity class

Fields and controls:

  • URI for implicit deeplink mode
  • Package name for explicit Activity mode
  • Activity class for explicit Activity mode
  • Attach content:// URI to set the local payload URI as Intent data (shown in Explicit Activity mode only — see note below)
  • FLAG_GRANT_READ_URI_PERMISSION to grant read access to the attached payload URI
  • Send Intent

Implicit deeplink workflow:

  1. Select Implicit Deeplink.
  2. Enter a URI that matches the assessed app's deeplink pattern.
  3. Tap Send Intent.
  4. Observe the assessed app behavior and the apk-interceptor log.

Explicit Activity workflow:

  1. Confirm the target Activity is exported and covered by your authorization.
  2. Select Explicit Activity.
  3. Enter the assessed app's package name.
  4. Enter the exported Activity class name.
  5. Optionally enable Attach content:// URI.
  6. Tap Send Intent.

Notes:

  • apk-interceptor does not know whether the assessed app handled the Intent safely. You must observe the assessed app behavior, logs, or test harness.
  • The content:// attachment is useful when testing whether a target Activity passes untrusted Intent data to a WebView.
  • Attach content:// URI is offered only in Explicit Activity mode. The payload is delivered as the Intent's data, which would overwrite the URI you type in Implicit Deeplink mode, so the option is hidden there.
  • PayloadProvider is not exported. The assessed app can read the attached content:// payload only because the Intent grants it temporary read access via FLAG_GRANT_READ_URI_PERMISSION. Keep that flag enabled, and deliver the URI through the Intent — a content:// URI opened any other way will not be readable by another app.

Payload

Use this tab to create a local HTML payload and validate JavaScript bridge syntax in apk-interceptor's own self-test WebView.

What it contains:

  • HTML editor
  • JavaScript evaluated after page load editor
  • Bridge object name
  • Generated content:// URI
  • Save Payload
  • Run Self-Test
  • Self-test WebView
  • Bridge result and console logs

Generated payload URI format:

content://<applicationId>.payload/current.html

The provider serves only this fixed file:

filesDir/payloads/current.html

Payload self-test workflow:

  1. Enter or paste HTML in the HTML field.
  2. Enter the bridge object name you want to test locally, for example localBridge.
  3. Add JavaScript either inside your HTML or in the JavaScript editor.
  4. Tap Save Payload.
  5. Tap Run Self-Test.
  6. Review BRIDGE_RESULT, console.log, and evaluateJavascript result entries in the log.

Example self-test JavaScript:

console.log("payload loaded");
window.localBridge.logResult(window.localBridge.getInfo());

The self-test bridge exposes:

window.<bridgeName>.logResult("message");
window.<bridgeName>.getInfo();

Important limitation:

The self-test WebView confirms that your local payload and bridge-call syntax work inside apk-interceptor. It cannot observe whether another app's WebView executed your payload or called its own bridge. For the assessed app, verify through that app's UI, logs, test hooks, or Chrome DevTools if the app is debuggable.

Vulnerability-Oriented Workflows

1. Custom URI Scheme Hijacking

Risk:

An Android app registers a custom URI scheme instead of a verified App Link. Any other app can register the same scheme, so Android may show an app chooser or route links to a different app.

Use apk-interceptor to check:

  • Whether the scheme can be registered by another app
  • Whether Android offers apk-interceptor as a handler
  • Whether sensitive values appear in deeplink parameters

Steps:

  1. Identify the assessed app's custom scheme from its manifest or documentation.
  2. Build apk-interceptor with that scheme.
  3. Install apk-interceptor and the assessed app on the same test device.
  4. Trigger a deeplink from the authorized test flow.
  5. If apk-interceptor receives it, inspect the Interceptor log.

Evidence to capture:

  • OS chooser behavior, if shown
  • Full received URI
  • Query parameters and whether they contain sensitive values
  • User interaction needed to route the link

2. Deeplink Parameter Injection

Risk:

The assessed app trusts deeplink parameters for navigation, URL loading, feature flags, account selection, or rendering without sufficient validation.

Use apk-interceptor to check:

  • Whether crafted parameters are accepted
  • Whether the app navigates to an unintended screen
  • Whether unsafe URL/path/content values are used

Steps:

  1. Identify the assessed app's deeplink format.
  2. Open Sender.
  3. Select Implicit Deeplink.
  4. Enter an authorized test URI with controlled parameters.
  5. Tap Send Intent.
  6. Observe the assessed app behavior.

Example placeholder:

my-authorized-scheme://open?next=https%3A%2F%2Fauthorized-test.example%2Flanding

Do not use real third-party domains or accounts unless they are explicitly in scope.

3. Exported Activity Access Control

Risk:

An exported Activity performs sensitive actions or displays sensitive data without verifying the caller, user state, or required authorization.

Use apk-interceptor to check:

  • Whether the exported Activity launches from another app
  • Whether it performs sensitive behavior without expected checks
  • Whether Intent data changes its behavior

Steps:

  1. Confirm the Activity is exported and in scope.
  2. Open Sender.
  3. Select Explicit Activity.
  4. Enter package name and Activity class.
  5. Optionally attach the local content:// payload URI.
  6. Tap Send Intent.
  7. Observe whether the assessed app enforces access control.

Evidence to capture:

  • Activity launched or blocked
  • Any authentication or authorization prompt
  • Sensitive action or data exposure
  • Intent data used by the Activity

4. WebView JavaScript Bridge Exposure Via content://

Risk:

The assessed app loads untrusted content:// Intent data into a WebView that also exposes a JavaScript bridge via addJavascriptInterface.

Use apk-interceptor to check:

  • Whether a local HTML payload can be delivered as content://
  • Whether the target WebView loads the payload
  • Whether JavaScript from that source can reach the bridge

Steps:

  1. Identify the target Activity and bridge object name during authorized analysis.
  2. Open Payload.
  3. Create HTML/JS that calls the expected bridge.
  4. Use Run Self-Test to validate your syntax locally.
  5. Open Sender.
  6. Select Explicit Activity.
  7. Enter the target package and Activity class.
  8. Enable Attach content:// URI and keep FLAG_GRANT_READ_URI_PERMISSION enabled.
  9. Tap Send Intent.
  10. Observe the assessed app to determine whether its WebView loaded the payload and bridge calls executed.

Important limitation:

apk-interceptor cannot receive results from another app unless that app explicitly returns or displays them. The tool is designed to deliver a local payload and validate syntax, not to exfiltrate data.

Command-Line Checks

Verify the APK does not request network access:

aapt dump permissions ./out/apk-interceptor-<scheme>-debug.apk

Expected: no android.permission.INTERNET.

Trigger a deeplink explicitly to apk-interceptor:

adb shell am start -W \
  -n com.sterrasec.apkinterceptor/.InterceptActivity \
  -a android.intent.action.VIEW \
  -d 'my-authorized-scheme://test?source=adb'

Trigger a deeplink through Android's resolver:

adb shell am start -W \
  -a android.intent.action.VIEW \
  -d 'my-authorized-scheme://test?source=adb'

The explicit command confirms InterceptActivity behavior. The implicit command confirms the manifest intent-filter and resolver behavior.

Tests

Unit tests run on the JVM with Robolectric — no device or emulator is required. They cover PayloadProvider, including the path-whitelisting and traversal checks that keep the provider from serving anything other than the single current.html payload.

./gradlew testDebugUnitTest

Test results are written to app/build/reports/tests/testDebugUnitTest/index.html. The same task runs in CI on every push and pull request to main.

Design Guardrails

  • No android.permission.INTERNET
  • No external data transmission or automated exfiltration
  • No shell command execution feature
  • No root, Magisk, Frida, or instrumentation dependency
  • No runtime registration of arbitrary schemes
  • No generic file-serving provider
  • Only /current.html is served by PayloadProvider

License

MIT