skills/lynricsy/hyperskills/android/Gen Agent Trust Hub

android

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references technical documentation and source material from official and community sources, including Google's Android skill repository (android/skills) and JetBrains' Kotlin tooling guides. These references are used for attribution and technical alignment with platform standards and originate from trusted organizations.\n- [COMMAND_EXECUTION]: The skill provides instructions for using standard Android development utilities such as the Gradle wrapper (./gradlew) for builds and the Android Debug Bridge (adb) for device interaction. These are typical, necessary tools for the described development workflows.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines workflows for reviewing and writing Android source code, which involves processing user-provided Kotlin, Gradle, and XML files. While this creates a potential ingestion surface for instructions embedded in data, the risk is inherent to the skill's primary purpose and is mitigated by the skill's strict adherence to safe architectural patterns. Evidence: 1. Ingestion points: Android source files provided during review workflows. 2. Boundary markers: Absent. 3. Capability inventory: Execution of local build commands and code generation. 4. Sanitization: Absent.\n- [SAFE]: The skill includes explicit defensive guidance focused on preventing security issues such as Intent redirection and securing exported components. These instructions demonstrate a proactive security posture and align with official Android security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 03:14 PM
Security Audit — agent-trust-hub — android