Observed arrival · 2026-09-06
Atomic, a mobile security scanner that reads the APK
Atomic scans Android APKs for 420+ OWASP mobile-security checks and returns severity-graded findings tied to code locations and suggested fixes.
Field notes
Atomic focuses on the shipped Android artifact rather than the development environment: the page says it decompiles an APK and examines its bytecode without source, instrumentation, an agent, or CI changes. Its stated coverage spans eight OWASP MASVS categories and 420+ checks, while the sample report shows a 12-second result with 41 findings, including an AWS credential located at ApiClient.java:42. Results are described as exportable to SARIF or CSV and suppressible when a finding is a false positive.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue