Unused Code
Find dead code across languages
Per-language parsing with three-level reference counting (file, package, project) and a confidence score on every finding.
What Cacomi can do
A detailed look at the static analysis, code-cleanup and security capabilities shipping in Cacomi today, across native iOS and Android, Flutter and Python, including AI usage detection. Everything runs locally on your Mac and is delivered as a static security assessment aligned with OWASP MASVS, MASTG and ASVS.
Unused Code
Per-language parsing with three-level reference counting (file, package, project) and a confidence score on every finding.
Prints & Sensitive Logs
Language-aware detection of print, NSLog, os_log, Log.*, console.* and more, flagging tokens, keys and PII inside log statements.
Hardcoded Secrets
Pattern and entropy detection across source, config and binary strings, including concatenated secrets, with values always masked.
Mobile Static Security
Weak crypto, insecure storage, cleartext / disabled TLS, WebView misuse, injection and taint flows. Cacomi reads bytes; it never executes, decrypts, re-signs or modifies your binaries.
Python & Backend
Web exposure, access control and insecure patterns across Django, Flask and FastAPI, mapped to OWASP ASVS 5.0 with a 4.0.3 cross-reference at Level 3 (L3).
Binary Analysis
Mach-O hardening, entitlements and Info.plist on iOS; binary manifest, DEX strings, native ELF and signing block on Android; plus Dart AOT bundles for Flutter.
Malicious AI & ML
Magic-byte classification (TFLite, GGUF, ONNX, CoreML, pickle, PyTorch) and an allowlist-first pickle opcode walker that flags malicious models without ever deserializing them.
AI Usage & Privacy
Discovery of AI service calls (OpenAI, Anthropic, Gemini, Hugging Face), undisclosed AI usage, user data sent to AI providers and prompt handling, all collected into an AI BOM inventory.
Reports
A structured PDF report aligned with OWASP MASVS/MASTG where applicable, with severity, confidence, evidence and remediation per finding. Secrets stay masked.
Safety & Control
Runs locally with safe archive extraction (path-traversal and zip-bomb safe). Destructive actions always show a preview before you confirm.
Standards coverage
Cacomi maps its findings to recognized security standards, OWASP MASVS, MASTG, MASWE, the MAS Checklist and MASA readiness for mobile, and OWASP ASVS for Python, so reports are actionable and easy to validate.
Cacomi is a pre-release application and a work in progress. As a static analysis tool it may produce false positives or miss issues (false negatives), and it is not 100% accurate or complete.
Cacomi provides a static mobile security assessment aligned with OWASP MASVS/MASTG. It does not replace dynamic testing, penetration testing, runtime instrumentation, manual security review or any official certification, and it does not claim to prove that an app is secure.
The report is aligned with OWASP MASVS/MASTG where applicable. The assessment is based on static analysis unless otherwise stated and does not replace a full manual penetration test.
All findings should be independently reviewed and verified. Use of the tool, and any decision made based on its results, is the sole responsibility of the user.