AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Android Security

skill-adrigm06-android-engineering-skill-android-security · by adrigm06

Android security engineering skill for threat-aware recommendations on secrets handling, secure storage, network hardening, Play Integrity, and release safeguards. Use this whenever security posture or sensitive data handling is in scope.

No reviews yet
0 installs
34 views
0.0% view→install

Install

$ agentstack add skill-adrigm06-android-engineering-skill-android-security

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-adrigm06-android-engineering-skill-android-security)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Android Security? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Purpose

Provide threat-aware Android security recommendations that reduce exploitability risk while remaining operationally feasible.

Scope and authority

This skill has global critical override authority for:

  • exploitable security risk
  • sensitive data exposure pathways
  • secrets and trust-boundary handling

If security risk is critical, this skill can override convenience, performance, or UX preferences.

When to use

  • credentials/tokens/PII handling
  • secure storage and network hardening decisions
  • integrity/tamper-risk mitigation planning
  • security assessment of architecture/build/release changes

Decision engine workflow

  1. Identify assets, trust boundaries, and attacker capabilities.
  2. Rank threats by exploitability and business impact.
  3. Choose mitigations by risk reduction vs operational cost.
  4. Define rollout controls and residual risk.
  5. Align with release constraints and incident readiness.

Branching decision tree

Branch A: risk class

  • Critical exploitability:
  • block release-impacting exposure
  • enforce immediate mitigation path
  • High but non-blocking:
  • prioritize near-term remediation with guardrails
  • Medium/Low:
  • schedule hardening with explicit risk acceptance notes

Branch B: mitigation feasibility

  • if ideal control is operationally heavy:
  • recommend staged mitigation plan with interim control
  • if threat model is weak/unknown:
  • choose conservative baseline controls and request missing threat inputs

Quantitative gates

Use measurable risk gates and label each pass | at-risk | fail:

  • unresolved critical exploitability gate (must pass for release)
  • sensitive data exposure gate (must pass for release)
  • control coverage gate (critical assets mapped to active controls)
  • observability gate (security-relevant detection/alert paths in place)

If threat evidence is incomplete, return a measurement and threat-model completion plan first.

Tradeoff realism

Allow constrained compromises only when explicit:

  • interim controls are acceptable if expiry criteria is defined
  • partial hardening is acceptable when release windows are tight and residual risk is transparent

Do not frame risk acceptance as risk elimination.

Uncertainty protocol

Always report confidence:

  • High (>= 0.80)
  • Medium (0.60-0.79)
  • Low (< 0.60)

If confidence is medium/low:

  • list assumptions and missing threat intel
  • provide least-risk interim control
  • escalate to android-release-engineering when residual risk may block release
  • escalate to android-architecture when control requires structural change

Cross-skill handoff payload

Use the standard payload defined in ../../AGENTS.md (section: Cross-skill handoff contract). Set requesting_skill to android-security.

Output contract

Follow global order from ../../AGENTS.md:

  1. Context and constraints
  2. Decision and rationale
  3. Alternatives considered
  4. Tradeoffs
  5. Risks and mitigations
  6. Confidence and unknowns
  7. Cross-skill impacts
  8. Next implementation steps

Also include:

  • Risk summary
  • Threat surfaces
  • Mitigation plan
  • Storage/network/integrity controls
  • Residual risks
  • Implementation priorities

Anti-pattern detection

  • secrets in source, resources, or build scripts
  • plaintext sensitive data persistence
  • custom crypto without strong justification
  • UI-only security checks lacking backend enforcement
  • security controls that are impractical to operate and therefore bypassed

Related resources

  • references/mobile-threat-model.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.