smali-dex-patching
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform various local system operations to manipulate Android application packages. This includes decompilation using apktool, editing AndroidManifest.xml files via sed, and managing device installations through adb.\n- [EXTERNAL_DOWNLOADS]: Instructions are provided for fetching and installing third-party security tools from well-known sources. This includes installing apk-mitm via NPM and referencing specialized utilities like apk.sh and uber-apk-signer from public GitHub repositories to assist in patching and signing workflows.\n- [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest and process external Android application data (APK files, Smali bytecode, and XML resources), it is inherently susceptible to indirect prompt injection. Adversarial content embedded within these untrusted files could attempt to manipulate the agent's reasoning or actions during the analysis process.\n
- Ingestion points: Android APK files and decompiled Smali sources processed via apktool as described in SKILL.md.\n
- Boundary markers: No explicit delimiter or instruction-guarding mechanisms are present to isolate the external application code from the agent's internal logic.\n
- Capability inventory: The skill utilizes shell commands (apktool, apksigner, adb), file system modification (sed), and external tool execution.\n
- Sanitization: There is no evidence of content sanitization or validation performed on the Smali bytecode or manifest XML before the agent processes them.
Audit Metadata