software-android-design
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and downloads documentation and system images from official Google and Material Design domains (developer.android.com, m3.material.io, fonts.google.com). These resources are fetched using standard platform tools like
sdkmanagerin thescripts/bootstrap-emulator.shfile. - [COMMAND_EXECUTION]: The skill uses shell scripts to execute standard Android Development Bridge (ADB) commands, emulator management tools, and Gradle tasks for building and deploying applications. Key scripts include
scripts/run-android.shfor installation/launch andscripts/layout-inspector.shfor UI hierarchy extraction. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and analyzing untrusted data from an external emulator environment.
- Ingestion points: UI hierarchy XML files captured via
uiautomator dumpand application screenshots captured viascreencap. - Boundary markers: None identified in the skill's instructions.
- Capability inventory: Command execution (adb, gradle) and file system operations within the local environment.
- Sanitization: The skill processes raw UI metadata and visual data to perform its design audits, which is an inherent part of its functionality as an auditing tool.
Audit Metadata