Skip to content
Development
Skill

/android-legacy-security

Harden Intent handling, WebView configuration, and FileProvider access in Android apps. Use when securing Intent extras, configuring WebViews, or exposing files via FileProvider; defer manifest export flags and generic Bundle typing to focused Android security guidance.

From plugin
agent-skills-standard
538200 skills1 MCP
Install
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill android-legacy-security --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/android-legacy-security

Context preview

The summary Claude sees to decide when to auto-load this skill.

Harden Intent handling, WebView configuration, and FileProvider access in Android apps. Use when securing Intent extras, configuring WebViews, or exposing files via FileProvider; defer manifest export flags and generic Bundle typing to focused Android security guidance.

SKILL.md

android-legacy-security.SKILL.md
name: android-legacy-security
description: Harden Intent handling, WebView configuration, and FileProvider access in Android apps. Use when securing Intent extras, configuring WebViews, or exposing files via FileProvider; defer manifest export flags and generic Bundle typing to focused Android security guidance.
metadata:
  triggers:
    files:
    - '**/*Activity.kt'
    - '**/*WebView*.kt'
    - 'AndroidManifest.xml'
    keywords:
    - Intent
    - WebView
    - FileProvider
    - javaScriptEnabled

Android Legacy Security Standards

**Priority: P0 (CRITICAL)**

1. Secure Intents and Components

  • Set `android:exported="false"` for all internal Activities/Services unless needed for deep links.
  • Verify `resolveActivity` before starting implicit intents.
  • Treat all incoming Intent extras as untrusted — validate all schema/data types.

See [hardening examples](references/implementation.md) for manifest and component restrictions.

2. Lock Down WebViews

  • Default to `javaScriptEnabled = false`. Use `WebViewClient` and `WebChromeClient` to restrict navigation.
  • Disable `allowFileAccess` and `allowFileAccessFromFileURLs` to prevent local file theft via XSS.
  • If using `@JavascriptInterface` (API 17+), strictly limit exposed API surface.

See [hardening examples](references/implementation.md) for WebView lockdown patterns.

3. Protect Storage and Files

  • **NEVER expose `file://` URIs**. Use `FileProvider` to generate `content://` URIs with temporary permissions.
  • Use `EncryptedSharedPreferences` for auth tokens and PII. Never use legacy public-read file modes.
  • Use `NetworkSecurityConfig` to disable `cleartextTrafficPermitted` and implement certificate pinning.

Anti-Patterns

  • **No Implicit Intents Internally**: Use explicit intents with component class name.
  • **No Public Read Modes**: Never expose SharedPreferences or files with global read access.

References

  • [Hardening Examples](references/implementation.md)
Read more
Ships withagent-skills-standard

The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.

Get the whole plugin

Other skills on agent-skills-standard.