android-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill focuses on analyzing and editing Android project files, which serves as an entry point for indirect prompt injection if project files contain malicious instructions.
- Ingestion points: Uses
Read,Grep, andGlobtools to ingest content from the user's local filesystem (e.g., Kotlin source files, build scripts). - Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between user-provided code and agent instructions.
- Capability inventory: The skill has access to
Bash,Write, andEdittools, allowing for system-level actions and file modifications based on ingested data. - Sanitization: No specific sanitization or validation logic is defined for processing external code snippets.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform development tasks. This is a standard and expected capability for an Android development agent to interact with build systems (Gradle), version control (Git), and project management tools.
Audit Metadata