android-jni-ndk

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Downloads a verification script (check_elf_alignment.sh) from the official Android Open Source Project (AOSP) source host at cs.android.com.- [COMMAND_EXECUTION]: Instructions provide numerous commands for Android binary analysis and debugging using standard NDK and SDK tools such as llvm-readelf, zipalign, and ndk-stack. It also includes a Gradle task snippet that executes llvm-readelf via ProcessBuilder.- [REMOTE_CODE_EXECUTION]: Describes native library loading mechanisms (System.load, System.loadLibrary) and highlights the security risks associated with loading shared objects from user-writable paths.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data sources such as native crash tombstones and APK metadata.
  • Ingestion points: Tombstone crash reports and APK symbols referenced in SKILL.md and references/native-crashes-and-debugging.md.
  • Boundary markers: None present.
  • Capability inventory: Subprocess execution (NDK tools), file system access (Gradle tasks), and network operations (utility downloads).
  • Sanitization: None performed on ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — android-jni-ndk