ShortScan - Shortcut Security
2 Sept 2026launched 29 days ago
0.00 ratings
n/aApple doesn’t publish installs
WorldwideSold in 50+ App Store storefronts
1.0latest version · 28 days ago
Screenshots
About
Worried a third-party shortcut might hide something nasty? Run it through ShortScan first. Paste an iCloud link or open a .shortcut / .json file, and see in seconds what the shortcut really does: which privacy permissions it touches, whether it sends data to unknown servers, and whether it contains hardcoded keys or backdoor logic. Risks are color-coded by severity, each with a clear explanation and recommendation. KEY FEATURES • One-tap import: paste an iCloud link or pick a .shortcut / .json file • Permission audit: contacts, photos, location, camera, microphone, health, keychain and more • Network risks: URL requests, short links, tracking services, data uploads • Secrets detection: API keys, tokens, passwords, private keys - masked on screen • Malicious logic: dynamic execution, auto-opening apps, loop abuse, script execution • Deep analysis: phishing, hidden backdoors, data exfiltration, social engineering • Node locator: jump straight to the risky node in the shortcut's JSON and copy its path • History: scan reports saved automatically, up to 100 entries • Fully offline: no network except iCloud link import WHEN YOU NEED IT • Scan a shortcut from the internet before installing it • Check whether a shared shortcut reads your contacts or clipboard and uploads them • Find keys or tokens accidentally left in your own shortcuts PRIVACY No accounts, no cloud storage, zero data collected. All analysis happens on your device. The only network request is fetching the shortcut file from Apple's servers when you paste an iCloud link. Every feature is free forever, no paywall. Requires iOS 16 or later (deep analysis requires iOS 17). Sichuan Yujiarui Software Technology Co., Ltd. https://www.haoqibit.com/shortscanRead more
Worried a third-party shortcut might hide something nasty? Run it through ShortScan first.
Paste an iCloud link or open a .shortcut / .json file, and see in seconds what the shortcut really does: which privacy permissions it touches, whether it sends data to unknown servers, and whether it contains hardcoded keys or backdoor logic. Risks are color-coded by severity, each with a clear explanation and recommendation.
KEY FEATURES
• One-tap import: paste an iCloud link or pick a .shortcut / .json file
• Permission audit: contacts, photos, location, camera, microphone, health, keychain and more
• Network risks: URL requests, short links, tracking services, data uploads
• Secrets detection: API keys, tokens, passwords, private keys - masked on screen
• Malicious logic: dynamic execution, auto-opening apps, loop abuse, script execution
• Deep analysis: phishing, hidden backdoors, data exfiltration, social engineering
• Node locator: jump straight to the risky node in the shortcut's JSON and copy its path
• History: scan reports saved automatically, up to 100 entries
• Fully offline: no network except iCloud link import
WHEN YOU NEED IT
• Scan a shortcut from the internet before installing it
• Check whether a shared shortcut reads your contacts or clipboard and uploads them
• Find keys or tokens accidentally left in your own shortcuts
PRIVACY
No accounts, no cloud storage, zero data collected. All analysis happens on your device. The only network request is fetching the shortcut file from Apple's servers when you paste an iCloud link.
Every feature is free forever, no paywall. Requires iOS 16 or later (deep analysis requires iOS 17).
Sichuan Yujiarui Software Technology Co., Ltd.
https://www.haoqibit.com/shortscan
Versions
- Version 1.0First seen · 3 Sept 2026
Countries
Worldwide
Apple lists this app in 50 or more storefronts, so it is available almost everywhere.
Turkey
Chart positions
Not seen in the charts we track yet.