code-signing-android
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documentation provides legitimate workflows for Android app signing, including keystore generation and SHA fingerprint extraction for Firebase integration.
- [SAFE]: Explicit security warnings are present, advising users to keep keystores and passwords private and to avoid exposing them in repositories, prompts, or logs.
- [SAFE]: The instructions rely on well-known developer tools such as
eas-cli(Expo Application Services) and the standard Javakeytoolutility.
Audit Metadata