android-intent-security

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [METADATA_POISONING]: The skill's metadata identifies the author as 'Google LLC', which differs from the provided account username 'albertmartorell1975'. This is noted as a discrepancy in attribution.\n- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and modify Android manifest files and source code, creating a potential surface for indirect prompt injection from the files being audited.\n
  • Ingestion points: AndroidManifest.xml and application source files containing Intent handling logic.\n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the files it processes.\n
  • Capability inventory: The agent is authorized to read project files, generate security-hardened code, and modify the application manifest.\n
  • Sanitization: While the skill does not sanitize its own input, it provides templates for the agent to implement IntentSanitizer within the target application code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 03:18 PM
Security Audit — agent-trust-hub — android-intent-security