adaptive
Warn
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill's metadata contains deceptive information. The 'author' field in 'SKILL.md' is set to 'Google LLC', which is inconsistent with the actual author context of 'albertmartorell1975'. This impersonation of a well-known vendor is a form of deceptive instruction that may mislead users about the skill's origin and official support.
- [EXTERNAL_DOWNLOADS]: The skill documentation and its reference files contain links to official Android development resources, including 'developer.android.com' and the 'android/nav3-recipes' repository on GitHub. These references point to legitimate and well-known service providers.
- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection through its core workflow. (1) Ingestion points: The agent is instructed to read and modify the user's existing application source code. (2) Boundary markers: No specific delimiters or instructions to ignore potential commands embedded in the code are provided. (3) Capability inventory: The agent has the authority to update project files and execute build and test commands. (4) Sanitization: No processes are defined to validate or sanitize the ingested source code.
Audit Metadata