testing-android-intents-for-vulnerabilities

Fail

Audited by Snyk on Mar 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill contains explicit, actionable instructions and code examples that enable data exfiltration and unauthorized access (e.g., content provider path traversal and download of app DB to /tmp/stolen.db, reading /etc/passwd via provider URIs, example exfil server "https://evil.com/data_sink", and broadcast sniffing), which are high-risk malicious/abuse patterns even though no obfuscated backdoor or remote-exec payloads are present.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 15, 2026, 01:52 PM
Issues
1