Apps are Turing-complete, right? In theory, that means it's possible to make an arbitarily complex and obfuscated route to a private API, making it impossible to detect via simple static analysis.
You're going to have to elaborate if you know any more, it seems incredibly easy to check programmatically.