What Cacomi can do

Technical features

A detailed look at the static analysis, code-cleanup and security capabilities shipping in Cacomi today, across native iOS and Android, Flutter and Python, including AI usage detection. Everything runs locally on your Mac and is delivered as a static security assessment aligned with OWASP MASVS, MASTG and ASVS.

Unused Code

Find dead code across languages

Per-language parsing with three-level reference counting (file, package, project) and a confidence score on every finding.

Swift / Kotlin / Java 170+ FP guards Confidence scoring

Prints & Sensitive Logs

Catch risky debug logs before release

Language-aware detection of print, NSLog, os_log, Log.*, console.* and more, flagging tokens, keys and PII inside log statements.

#if DEBUG wrap / unwrap Sensitive value scan Undo

Hardcoded Secrets

Detect exposed keys and credentials

Pattern and entropy detection across source, config and binary strings, including concatenated secrets, with values always masked.

Masked evidence High-entropy OWASP M1

Mobile Static Security

Static mobile security aligned with OWASP MASVS/MASTG

Weak crypto, insecure storage, cleartext / disabled TLS, WebView misuse, injection and taint flows. Cacomi reads bytes; it never executes, decrypts, re-signs or modifies your binaries.

OWASP Mobile Top 10 MASVS v2.1.0 Taint analysis

Python & Backend

Static analysis for Python backends

Web exposure, access control and insecure patterns across Django, Flask and FastAPI, mapped to OWASP ASVS 5.0 with a 4.0.3 cross-reference at Level 3 (L3).

Django / Flask / FastAPI OWASP ASVS 5.0 ASVS L3

Binary Analysis

Scan .ipa, .app and .apk

Mach-O hardening, entitlements and Info.plist on iOS; binary manifest, DEX strings, native ELF and signing block on Android; plus Dart AOT bundles for Flutter.

Mach-O DEX / ELF Obfuscation-aware

Malicious AI & ML

Inspect embedded AI models

Magic-byte classification (TFLite, GGUF, ONNX, CoreML, pickle, PyTorch) and an allowlist-first pickle opcode walker that flags malicious models without ever deserializing them.

Pickle opcode walk CWE-502 / 506

AI Usage & Privacy

See where your app talks to AI

Discovery of AI service calls (OpenAI, Anthropic, Gemini, Hugging Face), undisclosed AI usage, user data sent to AI providers and prompt handling, all collected into an AI BOM inventory.

AI discovery Data exposure AI BOM

Reports

Export a static mobile security assessment

A structured PDF report aligned with OWASP MASVS/MASTG where applicable, with severity, confidence, evidence and remediation per finding. Secrets stay masked.

PDF report OWASP mapping Masked secrets

Safety & Control

Local-first and untrusted-input hardened

Runs locally with safe archive extraction (path-traversal and zip-bomb safe). Destructive actions always show a preview before you confirm.

Local-first Preview before changes

Standards coverage

Aligned with what the industry expects

Cacomi maps its findings to recognized security standards, OWASP MASVS, MASTG, MASWE, the MAS Checklist and MASA readiness for mobile, and OWASP ASVS for Python, so reports are actionable and easy to validate.

10/10
OWASP Mobile Top 10 (2024) categories
24
OWASP MASVS v2.1.0 controls mapped
110+
Detection rules across 57 detectors
PDF
Export a report of findings
OWASP Mobile Top 10 MASVS v2.1.0 MASTG MASWE MAS Checklist MASA readiness OWASP ASVS 5.0 CWE Top 25

Terms & Conditions

Cacomi is a pre-release application and a work in progress. As a static analysis tool it may produce false positives or miss issues (false negatives), and it is not 100% accurate or complete.

Cacomi provides a static mobile security assessment aligned with OWASP MASVS/MASTG. It does not replace dynamic testing, penetration testing, runtime instrumentation, manual security review or any official certification, and it does not claim to prove that an app is secure.

The report is aligned with OWASP MASVS/MASTG where applicable. The assessment is based on static analysis unless otherwise stated and does not replace a full manual penetration test.

All findings should be independently reviewed and verified. Use of the tool, and any decision made based on its results, is the sole responsibility of the user.