software-android-runtime-debugging

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on local execution of standard Android development utilities, including the Android Debug Bridge (adb) and the Gradle wrapper (./gradlew). These commands are used for lifecycle management, log collection, and performance tracing, which are essential for the skill's stated purpose.
  • [EXTERNAL_DOWNLOADS]: The skill points to and utilizes resources from trusted organizations, including Google's Android Developer site, the official Perfetto tracing documentation, and Square's LeakCanary repository. These references are documented neutrally and serve as authoritative sources for the debugging workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect injection as it processes untrusted data from external sources such as logs and build artifacts.
  • Ingestion points: The agent is instructed to read logcat streams, aapt2 resource dumps, and system traces in SKILL.md and references/performance-triage.md.
  • Boundary markers: The workflow emphasizes the use of process-specific filters (e.g., adb logcat --pid) to restrict context to the target application.
  • Capability inventory: The skill employs shell command execution and file system access for reports and screenshots, as documented in references/runtime-proof-loop.md.
  • Sanitization: The skill recommends using specific CLI filtering and established diagnostic patterns to process and validate ingested runtime data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-android-runtime-debugging