clerk-android

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides the agent to install official Clerk SDK dependencies through the Android Gradle build system. It specifically references com.clerk:clerk-android-api and com.clerk:clerk-android-ui as the required artifacts.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to read and analyze project files such as build.gradle, AndroidManifest.xml, and Compose UI files to determine the project type and existing authentication state. This ingestion of untrusted local files is a standard surface for indirect prompt injection, though the skill includes specific gates and validation steps to mitigate accidental execution.
  • [COMMAND_EXECUTION]: While not explicitly providing shell scripts, the skill's instructions lead the agent to perform project modifications and dependency management using Android development tools (Gradle, Android Studio project structure), which involves local file system operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — clerk-android