Auditing Framework APIs via Inferred App-side Security Specifications