High
Release build is debuggable
app/build.gradle.kts:10Debug interfaces and inspection behavior do not belong in a production artifact.
Founding audit: 3 slots
Android release risks, surfaced before your users find them.
Local-only scan / zero dependencies / no source upload
Actual sample output
ShipSentry Lite points to the file and line that deserve review. The sample project ships with the repo, so every finding is reproducible.
High
app/build.gradle.kts:10Debug interfaces and inspection behavior do not belong in a production artifact.
High
AndroidManifest.xml:2Unencrypted traffic expands interception risk and can hide environment-specific mistakes.
Medium
MainActivity.kt:10WebView bridges need narrow interfaces, trusted content, and deliberate navigation controls.
Free in under a minute
curl -fsSLO https://raw.githubusercontent.com/adamglin0/shipsentry/main/scan.sh
chmod +x scan.sh
./scan.sh /path/to/android-project shipsentry-report.md
uses: adamglin0/shipsentry@v0.2.0Download one readable Bash script.
Scan locally. Nothing leaves the machine.
Review a portable Markdown report.
Founding offer
For one Android app module up to 30,000 source lines: prioritized findings, file-level evidence, fix guidance, and one clarification round.
TRON network (TRC20)
TSg3cFixQzkczF9BJ5DqHCnE3AP3AjRhgiAudit payment: submit a request and wait for scope acceptance before paying. Send USDT only on TRON (TRC20).
Using Lite? Optional tips to the same address are welcome. A tip does not purchase a service or reserve an audit slot.
Request an audit