jugg-android-dev-loop

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [PERSISTENCE]: The skill's installation guide (references/guide_install_cli.md) instructs the agent or user to modify shell profile files (such as ~/.bashrc, ~/.zshrc, and ~/.bash_profile) and Windows Environment Variables to add the tool to the system PATH. While this is a standard procedure for installing CLI utilities, it constitutes a persistent modification of the user's shell environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a verification flow that involves reading and parsing Android application logs via adb logcat (references/flow_with_auto_run.md, scripts/py/cmd/cmd_wait_logs.py). This establishes an attack surface where malicious content within app logs could potentially influence agent behavior.
  • Ingestion points: Application logs are ingested through the wait-logs subcommand and the auto-run verification flow using adb logcat output.
  • Boundary markers: The skill uses specific markers ([JUGG_AR] START and [JUGG_AR] DONE) to delimit the relevant log content for processing.
  • Capability inventory: The skill can execute shell commands (adb), write Java/Kotlin code to the local project, and interact with a local IDE plugin for build/deploy operations.
  • Sanitization: Log content is matched against regex markers, but the skill does not detail explicit sanitization of the log message body before processing.
  • [DYNAMIC_EXECUTION]: The main CLI entry point (scripts/jugg.py) utilizes importlib.import_module to dynamically load subcommand implementations at runtime. The risk of arbitrary code execution is mitigated as the module names are retrieved from a hardcoded static mapping (COMMANDS dictionary).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 03:58 AM