skills/aeondave/malskill/dex2jar/Gen Agent Trust Hub

dex2jar

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides command-line examples for executing local shell and batch scripts (d2j-dex2jar.sh, d2j-dex2jar.bat) to process Android application files.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions involve the processing of external artifacts (DEX and APK files) which could theoretically contain malicious content designed to influence agent behavior during analysis.
  • Ingestion points: Input files classes.dex and app.apk provided as arguments to conversion commands in SKILL.md.
  • Boundary markers: None specified in the usage examples.
  • Capability inventory: Execution of local conversion utilities.
  • Sanitization: No specific sanitization or validation logic is defined within the instructional content.
  • [NO_CODE]: The skill is a documentation-only resource and does not include any bundled scripts, configuration files, or executable components.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — dex2jar