competition-android-hooking

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content for Android application security analysis, specifically for CTF environments. It includes checklists for static and dynamic analysis without including malicious code, remote execution patterns, or unauthorized data access mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external inputs such as APK resources, decompiled output, and runtime hook logs. While these are untrusted data sources, the instructions do not currently include specific boundary markers or sanitization steps to isolate this data from the agent's logic. This represents a minor architectural surface common to analysis skills.
  • Ingestion points: APK resources, decompiled code, and runtime hook logs (SKILL.md).
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: The instructions involve inspection and tracing logic (SKILL.md).
  • Sanitization: None mentioned for processing extracted APK strings or logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 09:25 AM
Security Audit — agent-trust-hub — competition-android-hooking