skills/aeondave/malskill/apktool/Gen Agent Trust Hub

apktool

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a workflow for decoding and inspecting Android APK files, which are external, untrusted data sources.
  • Ingestion points: AndroidManifest.xml, apktool.yml, res/, and smali/ files decoded from targeted APKs into the agent's context.
  • Boundary markers: None; the skill does not define specific delimiters or instructions to ignore embedded content in decoded files.
  • Capability inventory: The skill uses shell-based tools including apktool, apksigner, and adb for file system and device operations.
  • Sanitization: The instructions do not include steps for sanitizing or filtering the content of decoded resources before inspection or rebuilding.
  • [SAFE]: The skill is entirely instructional and does not package any scripts or binary files. All external tools mentioned (Apktool, JADX, ADB) are standard utilities in the Android development and security ecosystem. The metadata correctly identifies the author, and no obfuscation or hidden malicious patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — apktool