mobile-android-assessment
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external Android applications, which could contain malicious instructions meant to influence the agent's behavior. 1. Ingestion points: Decompiled Java and Kotlin source code, AndroidManifest.xml, resource files like strings.xml, and files retrieved from the application's local storage (/data/data//). 2. Boundary markers: The instructions do not specify the use of delimiters or warnings to prevent the agent from obeying instructions potentially embedded within the analyzed code or metadata. 3. Capability inventory: The skill employs various tools for analysis and interaction, including grep, apktool, jadx, adb, and objection. 4. Sanitization: There are no prescribed steps for sanitizing or validating the content extracted from the target application before the agent processes it.
Audit Metadata