jugg-android-dev-loop
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [PERSISTENCE]: The skill's installation guide (
references/guide_install_cli.md) instructs the agent or user to modify shell profile files (such as~/.bashrc,~/.zshrc, and~/.bash_profile) and Windows Environment Variables to add the tool to the system PATH. While this is a standard procedure for installing CLI utilities, it constitutes a persistent modification of the user's shell environment. - [INDIRECT_PROMPT_INJECTION]: The skill implements a verification flow that involves reading and parsing Android application logs via
adb logcat(references/flow_with_auto_run.md,scripts/py/cmd/cmd_wait_logs.py). This establishes an attack surface where malicious content within app logs could potentially influence agent behavior. - Ingestion points: Application logs are ingested through the
wait-logssubcommand and the auto-run verification flow usingadb logcatoutput. - Boundary markers: The skill uses specific markers (
[JUGG_AR] STARTand[JUGG_AR] DONE) to delimit the relevant log content for processing. - Capability inventory: The skill can execute shell commands (
adb), write Java/Kotlin code to the local project, and interact with a local IDE plugin for build/deploy operations. - Sanitization: Log content is matched against regex markers, but the skill does not detail explicit sanitization of the log message body before processing.
- [DYNAMIC_EXECUTION]: The main CLI entry point (
scripts/jugg.py) utilizesimportlib.import_moduleto dynamically load subcommand implementations at runtime. The risk of arbitrary code execution is mitigated as the module names are retrieved from a hardcoded static mapping (COMMANDSdictionary).
Audit Metadata