Install
$ agentstack add skill-adrigm06-android-engineering-skill-android-security ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Purpose
Provide threat-aware Android security recommendations that reduce exploitability risk while remaining operationally feasible.
Scope and authority
This skill has global critical override authority for:
- exploitable security risk
- sensitive data exposure pathways
- secrets and trust-boundary handling
If security risk is critical, this skill can override convenience, performance, or UX preferences.
When to use
- credentials/tokens/PII handling
- secure storage and network hardening decisions
- integrity/tamper-risk mitigation planning
- security assessment of architecture/build/release changes
Decision engine workflow
- Identify assets, trust boundaries, and attacker capabilities.
- Rank threats by exploitability and business impact.
- Choose mitigations by risk reduction vs operational cost.
- Define rollout controls and residual risk.
- Align with release constraints and incident readiness.
Branching decision tree
Branch A: risk class
Critical exploitability:- block release-impacting exposure
- enforce immediate mitigation path
High but non-blocking:- prioritize near-term remediation with guardrails
Medium/Low:- schedule hardening with explicit risk acceptance notes
Branch B: mitigation feasibility
- if ideal control is operationally heavy:
- recommend staged mitigation plan with interim control
- if threat model is weak/unknown:
- choose conservative baseline controls and request missing threat inputs
Quantitative gates
Use measurable risk gates and label each pass | at-risk | fail:
- unresolved critical exploitability gate (must pass for release)
- sensitive data exposure gate (must pass for release)
- control coverage gate (critical assets mapped to active controls)
- observability gate (security-relevant detection/alert paths in place)
If threat evidence is incomplete, return a measurement and threat-model completion plan first.
Tradeoff realism
Allow constrained compromises only when explicit:
- interim controls are acceptable if expiry criteria is defined
- partial hardening is acceptable when release windows are tight and residual risk is transparent
Do not frame risk acceptance as risk elimination.
Uncertainty protocol
Always report confidence:
High(>= 0.80)Medium(0.60-0.79)Low(< 0.60)
If confidence is medium/low:
- list assumptions and missing threat intel
- provide least-risk interim control
- escalate to
android-release-engineeringwhen residual risk may block release - escalate to
android-architecturewhen control requires structural change
Cross-skill handoff payload
Use the standard payload defined in ../../AGENTS.md (section: Cross-skill handoff contract). Set requesting_skill to android-security.
Output contract
Follow global order from ../../AGENTS.md:
Context and constraintsDecision and rationaleAlternatives consideredTradeoffsRisks and mitigationsConfidence and unknownsCross-skill impactsNext implementation steps
Also include:
Risk summaryThreat surfacesMitigation planStorage/network/integrity controlsResidual risksImplementation priorities
Anti-pattern detection
- secrets in source, resources, or build scripts
- plaintext sensitive data persistence
- custom crypto without strong justification
- UI-only security checks lacking backend enforcement
- security controls that are impractical to operate and therefore bypassed
Related resources
references/mobile-threat-model.md
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: adrigm06
- Source: adrigm06/Android-Engineering-Skill
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.