Anyone vaguely skilled can reverse engineer an android app. Modern versions of android (ie Android 6, which I appreciate only 0.0001% of android users actually have) let you control which permissions an app can use.
If "vaguely skilled" is what it takes to audit an Android app, then "borderline incompetent" is all you need to audit a web app. Other commenters are talking about relative ease, not absolute impossibility.