androguard
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a reference for Androguard, a recognized library for Android static analysis. The installation instructions and Python snippets follow standard usage patterns for extracting metadata and resources from APK files.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external data (Android APKs) into the agent's context.
- Ingestion points: The agent reads external binary files using the
AnalyzeAPKfunction described inSKILL.md. - Boundary markers: The provided code snippets do not include explicit delimiters or warnings to ignore instructions embedded within the extracted strings.
- Capability inventory: The skill provides methods to extract package names, permissions, activities, and file inventories.
- Sanitization: There is no logic provided to sanitize or filter the content extracted from the APK before it is displayed to the user or agent, which is typical for triage tools but constitutes a known attack surface for indirect prompt injection.
Audit Metadata