Review a native iOS or Android application against current OWASP MASVS and relevant platform controls. Use before release and after changes to authentication, local storage, networking, WebViews, deep links, permissions, signing, privacy, resilience, or SDKs. Review backend and API surfaces separately with the web security skill.