apk-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates several analysis tools including
jadx,dex2jar, andaapt. These executions are performed inside a containerized environment to isolate the analysis from the host system. - [EXTERNAL_DOWNLOADS]: The
Dockerfilefetchesjadxanddex2jarfrom GitHub. These downloads are version-pinned and verified with SHA-256 checksums to ensure integrity and prevent the use of altered assets. - [DATA_EXFILTRATION]: The skill implements significant protections against data leakage by running the analysis container with
--network none. Furthermore, scripts likeextract-strings.shandfind-api-calls.shinclude explicit redaction logic to mask tokens and API keys found in the source code before they are exposed to the agent context. - [SAFE]: The skill includes comprehensive security documentation and explicitly requires user confirmation of authorization and scope before starting any analysis tasks.
Audit Metadata