android-kotlin
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard architectural guidance for Android development (MVVM, Hilt, Room, Jetpack Compose) without introducing malicious patterns or dangerous command execution.
- [CREDENTIALS_SAFE]: The instructions explicitly warn against committing signing configurations, keystores, and API keys to version control. It also correctly recommends using backend-issued tokens rather than hardcoding secrets within the application binary.
- [PRIVILEGE_ESCALATION]: The skill emphasizes the principle of least privilege for Android manifest permissions and recommends checking the
android:exportedattribute for security correctness. - [DATA_EXFILTRATION]: There are no patterns suggesting unauthorized data access or exfiltration. The network security guidelines encourage intentional configuration, such as certificate pinning and managing cleartext traffic.
Audit Metadata