android-release-validation

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is a legitimate, documentation-style release-validation workflow for Android projects. It prescribes building release APK/AAB, verifying ProGuard/R8 mapping, validating signing, analyzing APK contents, and running instrumentation tests on a connected device/emulator. I found no evidence of malicious code, remote exfiltration, or obfuscated malicious behavior. The primary security concerns are operational: protect signing keystore and credentials, run validations on dedicated test devices or CI agents (not personal/production devices), and avoid leaking secrets in logs. Overall assessment: benign but operationally sensitive — recommended to enforce keystore protection, redact or avoid printing secrets in logs, and run on isolated test environments.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:42 PM
Package URL
pkg:socket/skills-sh/hitoshura25%2Fclaude-devtools%2Fandroid-release-validation%2F@613461b8d110a97aa1a063d02e9ccbe1e8e7c0e7