android-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill focuses on analyzing and editing Android project files, which serves as an entry point for indirect prompt injection if project files contain malicious instructions.
  • Ingestion points: Uses Read, Grep, and Glob tools to ingest content from the user's local filesystem (e.g., Kotlin source files, build scripts).
  • Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between user-provided code and agent instructions.
  • Capability inventory: The skill has access to Bash, Write, and Edit tools, allowing for system-level actions and file modifications based on ingested data.
  • Sanitization: No specific sanitization or validation logic is defined for processing external code snippets.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform development tasks. This is a standard and expected capability for an Android development agent to interact with build systems (Gradle), version control (Git), and project management tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:12 AM
Security Audit — agent-trust-hub — android-expert