$npx skillfedfor your agent

mobsfscan

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code.

Worth itPyPI Quality AssuranceReleased Aug 2026140.0K downloads / mocopyleft licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — mobsfscan-1.0.0-py3-none-any.whl
v1.0.0 · released 2026-08-10 · Python >=3.10 · 7 runtime deps: colorama, libsast, semgrep, sarif-om, jschema-to-python, tabulate, xmltodict

Yes. mobsfscan is a mature, actively maintained security scanner with low install friction, no known vulnerabilities, and broad language support for Android and iOS development. The copyleft license (LGPLv3+) is standard for security tools and poses no barrier to internal use. Install it if you develop mobile apps and want automated pattern-based vulnerability detection integrated into your workflow.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; semgrep and libsast are runtime dependencies that may require system libraries.
  • Low install friction with a pure Python wheel and seven runtime dependencies.
  • Actively maintained with a recent release (4 days old) and steady repository activity; supports Python 3.10–3.14.

License · maintenance · safety

copyleft license (copyleft) — Licensed under LGPLv3+, a copyleft license requiring derivative works to be distributed under the same terms; acceptable for internal security tooling but constrains commercial redistribution.

last release 2026-08-10 (4 days) · last repo commit 2026-08-10 · 779 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 139,966 downloads/mo, #11,283 on PyPI

Verify before relying

pip install mobsfscan
mobsfscan /path/to/android/or/ios/source
mobsfscan --json --output results.json /path/to/source
  • Whether semgrep and libsast system dependencies are automatically resolved on all platforms or require manual setup.
  • Performance characteristics when scanning large codebases or the effectiveness of multiprocessing strategies (default, billiard, thread).
  • Accuracy and false-positive rates compared to other mobile security static analysis tools.
Same gist for agents: .md · .json

What it is and what it does

mobsfscan is a command-line static analysis tool designed to scan Android and iOS source code for security vulnerabilities and insecure coding patterns. It works by applying pattern-matching rules from the MobSF (Mobile Security Framework) project, powered by semgrep and libsast engines. The tool supports multiple languages—Java, Kotlin, Swift, Objective-C, Android XML, and iOS Info.plist—making it useful for teams developing cross-platform mobile applications.

The tool outputs findings in multiple formats (JSON, SARIF, SonarQube, GitLab SAST, HTML) and integrates with CI/CD pipelines through command-line options. It can be configured to treat warnings as failures, supports multiprocessing for faster scans, and includes detailed rule metadata (CVSS scores, CWE references, OWASP-MOBILE mappings, MASVS links). The package is actively maintained, supports modern Python versions, and has no known security vulnerabilities.

Use it for

  • Scan Android Java/Kotlin codebases for insecure WebView implementations, hardcoded credentials, and certificate validation bypasses.
  • Integrate into CI/CD pipelines to automatically detect mobile security issues before code merges using JSON or SARIF output formats.
  • Audit iOS Swift/Objective-C projects for common security misconfigurations and insecure API usage patterns.
  • Generate compliance reports in SonarQube or GitLab SAST formats for security teams and auditors.
  • Enforce security standards across teams by running mobsfscan as a pre-commit or build-time check with configurable exit codes.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

mobsfscan is a mature, actively maintained security scanner with low install friction, no known vulnerabilities, and broad language support for Android and iOS development. The copyleft license (LGPLv3+) is standard for security tools and poses no barrier to internal use. Install it if you develop mobile apps and want automated pattern-based vulnerability detection integrated into your workflow.

Install

mobsfscan on PyPI

Before you install

Low install friction with a pure Python wheel and seven runtime dependencies. Actively maintained with a recent release (4 days old) and steady repository activity; supports Python 3.10–3.14.

Requires Python 3.10 or later; semgrep and libsast are runtime dependencies that may require system libraries.

License in practice

Licensed under LGPLv3+, a copyleft license requiring derivative works to be distributed under the same terms; acceptable for internal security tooling but constrains commercial redistribution.

Quickstart

pip install mobsfscan
mobsfscan /path/to/android/or/ios/source
mobsfscan --json --output results.json /path/to/source

Verify before relying

  • Whether semgrep and libsast system dependencies are automatically resolved on all platforms or require manual setup.
  • Performance characteristics when scanning large codebases or the effectiveness of multiprocessing strategies (default, billiard, thread).
  • Accuracy and false-positive rates compared to other mobile security static analysis tools.

Package facts

Licensecopyleft license copyleft
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
7 packages
coloramalibsastsemgrepsarif-omjschema-to-pythontabulatexmltodict
MaintenanceActively maintained 4 days since the last release
Last repo commit
First released
Downloads139,966 / month, #11,283 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: GNU Lesser General Public License v3 or later (LGPLv3+)Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14

Evidence: mobsfscan-1.0.0-py3-none-any.whl

Tags

Capabilities
android ios static analysis securitymobile app code vulnerability scannerinsecure code pattern detectionjava kotlin swift objective-c lintermobile security static analysisandroid webview ssl certificate checksemgrep libsast pattern matching
Topics
mobile-securitystatic-analysisci-cd-integration

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “android ios static analysis security”

  • mobsfscanmobsfscan is a static analysis tool that detects insecure code…
  • apkInspectorParses APK files according to the zip specification, extracts…
  • androguardAndroguard is a Python tool for analyzing, disassembling, and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also njsscan · libsast · semgrep · androguard · skylos · kingfisher-bin · ai-edge-litert · trufflehog3 · mnn · codeshield