software-android-design

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and downloads documentation and system images from official Google and Material Design domains (developer.android.com, m3.material.io, fonts.google.com). These resources are fetched using standard platform tools like sdkmanager in the scripts/bootstrap-emulator.sh file.
  • [COMMAND_EXECUTION]: The skill uses shell scripts to execute standard Android Development Bridge (ADB) commands, emulator management tools, and Gradle tasks for building and deploying applications. Key scripts include scripts/run-android.sh for installation/launch and scripts/layout-inspector.sh for UI hierarchy extraction.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and analyzing untrusted data from an external emulator environment.
  • Ingestion points: UI hierarchy XML files captured via uiautomator dump and application screenshots captured via screencap.
  • Boundary markers: None identified in the skill's instructions.
  • Capability inventory: Command execution (adb, gradle) and file system operations within the local environment.
  • Sanitization: The skill processes raw UI metadata and visual data to perform its design audits, which is an inherent part of its functionality as an auditing tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-android-design