jadx
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill documentation describes standard usage of the JADX decompiler for Android application analysis. The provided commands for decompiling and exploring APK files are standard and do not involve suspicious network activity, credential theft, or privilege escalation.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of untrusted Android application files (APK/DEX/AAB/JAR) via the JADX tool. 1. Ingestion points: APK, DEX, AAB, and JAR files processed through CLI and GUI workflows. 2. Boundary markers: Absent; instructions provide direct tool invocation. 3. Capability inventory: Local command execution of jadx and jadx-gui, and file system writes via the output directory flag. 4. Sanitization: None; the skill is designed for raw reverse engineering of provided binary assets.
Audit Metadata