mobile-technique
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill extensively uses shell commands and command-line utilities for security auditing, such as
jadx,apktool,frida,objection, andadb. These are standard tools for the skill's stated purpose of mobile application penetration testing. - [EXTERNAL_DOWNLOADS]: The instructions reference external resources and tools hosted on GitHub, including WithSecureLabs' Drozer fork, HttpToolkit's instrumentation scripts, and Il2CppDumper. These originate from well-known security research entities and services.
- [DYNAMIC_EXECUTION]: An inline Python script is provided to handle the decompression of Android backup files. This script is local, self-contained, and utilizes standard libraries (
zlib,pathlib) for file processing. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to analyze external mobile application packages (APK/IPA) and their decompiled contents, there is an inherent attack surface for indirect prompt injection. Maliciously crafted application strings or metadata could attempt to influence the agent's analysis. The skill focuses on technical auditing rather than automated decision-making, which reduces the impact of this surface.
Audit Metadata