clerk-android
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the agent to install official Clerk SDK dependencies through the Android Gradle build system. It specifically references
com.clerk:clerk-android-apiandcom.clerk:clerk-android-uias the required artifacts. - [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to read and analyze project files such as
build.gradle,AndroidManifest.xml, and Compose UI files to determine the project type and existing authentication state. This ingestion of untrusted local files is a standard surface for indirect prompt injection, though the skill includes specific gates and validation steps to mitigate accidental execution. - [COMMAND_EXECUTION]: While not explicitly providing shell scripts, the skill's instructions lead the agent to perform project modifications and dependency management using Android development tools (Gradle, Android Studio project structure), which involves local file system operations.
Audit Metadata