software-android-native

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external backend APIs (e.g., via Retrofit, Ktor, or Supabase) as described in references/compose-state-concurrency.md and references/ui-and-integration-patterns.md. Because the skill also instructs the agent to use powerful system-level tools such as ADB (Android Debug Bridge) and the Gradle CLI for command execution and file management (references/agentic-android-tooling.md), this creates a vulnerability surface for indirect prompt injection. Maliciously crafted data in an API response could potentially influence the agent's behavior during development tasks.
  • Ingestion points: Data Transfer Objects (DTOs) and API responses processed in the ViewModel and repository layers, as mentioned in references/compose-state-concurrency.md.
  • Boundary markers: The instructions do not explicitly advise the use of delimiters or specific boundary markers to isolate potentially untrusted natural language data from agent instructions.
  • Capability inventory: The skill utilizes significant system capabilities, including executing shell commands via ADB (adb shell, adb install), running build tasks via Gradle (./gradlew), and capturing screenshots/logs to the local filesystem.
  • Sanitization: There is no documented requirement or pattern for sanitizing or escaping external data before it is processed by the agent or displayed in the UI state.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:20 AM
Security Audit — agent-trust-hub — software-android-native