release-android

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to process external, potentially untrusted data sources such as application manifests and dependency metadata which could contain embedded instructions.
  • Ingestion points: Android manifest files, dependency metadata, and build resources (SKILL.md).
  • Boundary markers: None provided in the instructions to separate untrusted data from the agent's operational instructions.
  • Capability inventory: The agent is instructed to perform build execution, signature verification, and artifact inspection tasks (SKILL.md).
  • Sanitization: No specific sanitization or validation steps are defined for handling the external content during the inspection process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 12:11 PM
Security Audit — agent-trust-hub — release-android