AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Android Security Hardened

skill-prasad-vennam-awesome-android-ai-agent-skills-android-security-hardened · by prasad-vennam

Use when securing Android applications, implementing Biometric auth, or encrypting sensitive data locally.

No reviews yet
0 installs
8 views
0.0% view→install

Install

$ agentstack add skill-prasad-vennam-awesome-android-ai-agent-skills-android-security-hardened

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-prasad-vennam-awesome-android-ai-agent-skills-android-security-hardened)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Android Security Hardened? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Android Security Hardening 🛡️🔐

Professional security practices for protecting sensitive user data, identity, and application integrity on Android devices.

⚡ When to Use

  • Biometric Authentication: Fingerprint/Face ID for app lock.
  • Local Encryption: Securing login tokens or user profiles.
  • Keystore Management: Safe storage of cryptographic keys.
  • Root/Emulator Detection: Verifying device integrity for high-risk apps.
  • Certificate Pinning: Hardening HTTPS via network security config.

🏗️ The 5 Pillars of Security

  1. Identity: Strong authentication (OIDC, Biometrics).
  2. Confidentiality: Encrypting data at rest and in transit.
  3. Integrity: Preventing tampering (App signing, Root check).
  4. Available: Ensuring resilience (DDoS protection, Offline access control).
  5. Audit: Logging security-relevant events safely.

🔑 KeyStore & Cryptography

1. Android Keystore System

  • Rule: NEVER store encryption keys in resources or hardcoded.
  • Use KeyGenerator with purpose(PURPOSE_ENCRYPT | PURPOSE_DECRYPT) and blockMode(BLOCK_MODE_GCM).
  • Use GCM (Galois/Counter Mode) for authenticated encryption.

2. EncryptedSharedPreferences

  • Rule: Use Jetpack Security to encrypt standard SharedPreferences.

``kotlin val masterKey = MasterKey.Builder(context).setKeyScheme(AES256_GCM).build() val sharedPrefs = EncryptedSharedPreferences.create( context, "secret_prefs", masterKey, AES256_SIV, AES256_GCM ) ``

🔐 Biometric Auth (BiometricPrompt)

  • Use the androidx.biometric library for consistent UI across devices.
  • Class 3 (Strong): Highest security, requires biological match.
  • Class 2 (Weak): Fallback for older devices.

🛡️ Device Integrity & Hardening

  • [ ] Root Detection: Use libraries like RootBeer or Google Play Integrity API.
  • [ ] Emulator Detection: Verify system properties (ro.product.model, ro.hardware).
  • [ ] Certificate Pinning: Use the network-security-config.xml to limit trusted CAs.
  • [ ] ProGuard/R8: Obfuscate sensitive classes and strings. CRITICAL WARNING: Misconfigured R8 rules will crash the app if reflection relies on stripped classes. (See [CI/CD Expert Skill](../android-ci-cd-expert/SKILL.md) for R8 configuration guidelines).
  • [ ] No Backup: Use android:allowBackup="false" for sensitive data.

📐 Networking Best Practices

  • Always use HTTPS (TLS 1.2+).
  • Use android:usesCleartextTraffic="false" in the manifest.
  • Sanitize all external inputs (Intents, WebViews).

🧪 Testing and Verification

  • MobSF: Use Mobile Security Framework to scan for vulnerabilities.
  • Runtime Checks: Use ADB to verify private data is NOT accessible to other apps.
  • OWASP MSTG: Follow the Mobile Security Testing Guide.

🔗 Related Resources

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.