software-android-native
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external backend APIs (e.g., via Retrofit, Ktor, or Supabase) as described in
references/compose-state-concurrency.mdandreferences/ui-and-integration-patterns.md. Because the skill also instructs the agent to use powerful system-level tools such as ADB (Android Debug Bridge) and the Gradle CLI for command execution and file management (references/agentic-android-tooling.md), this creates a vulnerability surface for indirect prompt injection. Maliciously crafted data in an API response could potentially influence the agent's behavior during development tasks. - Ingestion points: Data Transfer Objects (DTOs) and API responses processed in the ViewModel and repository layers, as mentioned in
references/compose-state-concurrency.md. - Boundary markers: The instructions do not explicitly advise the use of delimiters or specific boundary markers to isolate potentially untrusted natural language data from agent instructions.
- Capability inventory: The skill utilizes significant system capabilities, including executing shell commands via ADB (
adb shell,adb install), running build tasks via Gradle (./gradlew), and capturing screenshots/logs to the local filesystem. - Sanitization: There is no documented requirement or pattern for sanitizing or escaping external data before it is processed by the agent or displayed in the UI state.
Audit Metadata