f*** your
app.
POINT IT AT YOUR APP. IT TRIES TO BREAK IT.
THAT IS THE WHOLE THING.
non-destructive. receipts, not he-said.
real output from a real scan. every line above is fya talking, not the website.
Wanted in three forms.
one command, auto-detectedFuzzes inputs, walks the routes, probes access control. Injections proven by an arithmetic oracle.
Unpacks the manifest and the DEX. Exported providers, deep-link hijacking, v1 signing, debug certs.
Reads the code and the infrastructure. Hardcoded secrets, SQL by concatenation, weak IaC.
The catalog. 91 felonies.
every check maps to OWASP and a CWE- injection
Command injection, XXE, boolean-blind SQLi, SSTI, LFI wrappers, NoSQL operators.
- exposure
Actuators and heap dumps, phpinfo, the Werkzeug console, backup copies of live source.
- secrets
Keys in client JavaScript, source maps, dumpable .git, leaked config.
- apk
Network security config, exported providers, deep-link hijacking, v1 signing, debug certs.
- whitebox
Hardcoded secrets, committed key material, SQL by concatenation, verify disabled.
- iac
Dockerfile and Compose hardening, Kubernetes workloads, Terraform exposure, Actions.
- api
OpenAPI and Swagger exposure, GraphQL introspection, OIDC discovery, SOAP and WSDL.
- tls
Certificate trust and expiry, weak protocols, key size, mixed content.
- tools
Nuclei, Nikto, nmap, sqlmap, and testssl folded into one report when installed.
An APK is a target too.
Manifest and DEX, no androguard required. Export surface, deep links, signing scheme, debug certs. Found on the spot, proven in the report.
The sequence.
six stages, self-throttleda server, an APK, or a source tree
the stack, from the first responses
only the checks that fit the target
non-destructive probes, paced to what it tolerates
dedup, OWASP and CWE, receipts kept
console, JSON, SARIF, Markdown, or HTML
Tell Claude to break it.
fya ships as a Claude skill. Drop it in, say what to scan, and Claude confirms you own the target, runs the same non-destructive checks, and reports back in the chat with no package to install.
git clone https://github.com/ayam04/fya
cp -r fya/skills/fya ~/.claude/skills/fyascan http://localhost:3000 for vulnerabilities
check ./app-release.apk for security issuesBreak your app before
someone else does.
start with your localhost right now. one command, a couple of seconds, receipts included. no accounts, no agents. just you, your terminal, and a stack of receipts.
--i-am-authorized flag. Test only what you own.