mobile-android-assessment

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external Android applications, which could contain malicious instructions meant to influence the agent's behavior. 1. Ingestion points: Decompiled Java and Kotlin source code, AndroidManifest.xml, resource files like strings.xml, and files retrieved from the application's local storage (/data/data//). 2. Boundary markers: The instructions do not specify the use of delimiters or warnings to prevent the agent from obeying instructions potentially embedded within the analyzed code or metadata. 3. Capability inventory: The skill employs various tools for analysis and interaction, including grep, apktool, jadx, adb, and objection. 4. Sanitization: There are no prescribed steps for sanitizing or validating the content extracted from the target application before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — mobile-android-assessment