appfunctions
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs developers to include official Android Jetpack libraries (androidx.appfunctions) from Google's Maven repository in their project configuration.
- [COMMAND_EXECUTION]: Instructions provide ADB shell commands to list, execute, and manage AppFunctions on a connected Android device for development and debugging purposes.
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface where descriptions retrieved from app metadata at runtime are used as instructions for the AI agent. 1. Ingestion points: Metadata descriptions retrieved via the list-app-functions command in references/adb-interaction-testing.md. 2. Boundary markers: Not specified for the retrieved metadata content. 3. Capability inventory: ADB command execution and generation of Kotlin source code. 4. Sanitization: The skill does not provide instructions for sanitizing or escaping metadata before it is processed by the agent.
Audit Metadata