Aikido launches autonomous Android pentesting
Aikido now uses autonomous agents to test Android apps and their backend APIs together through real user flows and ADB. Findings require proof of exploitation and include reproducible steps, audit-ready reports, AutoFix, and retesting.
The important shift is treating the mobile client and its API as one attack surface, where authorization and business-logic flaws often hide. The approach is compelling, but its white-box requirements and need for specially configured APKs limit immediate adoption.
- –Agents map screens, permissions, and API endpoints before testing attack paths across the app and backend.
- –Exploit confirmation, agent traces, and exact ADB commands make findings more actionable than conventional scanner alerts.
- –AutoFix can generate a pull request, after which teams rebuild the APK and rerun the assessment.
- –Current testing requires source access and disables certificate pinning, root detection, emulator detection, and RASP in the test build.
- –Rightsized credit pricing and same-day results position this as a repeatable complement to annual manual pentests. [Product details](https://www.aikido.dev/attack/android-pentesting)
DISCOVERED
1h ago
2026-08-26
PUBLISHED
2h ago
2026-08-26
RELEVANCE
AUTHOR
AikidoSecurity