Evaluates third-party dependencies, cross-platform framework risks, and the mobile build pipeline from source to distribution.
•
Supply chain integrity - SDK provenance, dependency-confusion, and malicious package detection
•
Cross-platform frameworks - Flutter, React Native, and Kotlin Multiplatform-specific security gaps
•
Third-party SDK risk - data-collection behaviour, permissions scope, and embedded tracker analysis
•
Build & distribution - signing-key management, store-deployment hygiene, and sideloading exposure
•
Security misconfiguration - exported components, debug flags, and overly broad permission requests