Skip to content
Development
Skill

/android-security

Secure Android data at rest and authentication secrets. Use for auth tokens, encrypted storage, and app-data isolation; defer WebView/Intent/FileProvider to android-legacy-security and TLS/certificate pinning to android-networking.

From plugin
agent-skills-standard
538200 skills1 MCP
Install
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill android-security --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/android-security

Context preview

The summary Claude sees to decide when to auto-load this skill.

Secure Android data at rest and authentication secrets. Use for auth tokens, encrypted storage, and app-data isolation; defer WebView/Intent/FileProvider to android-legacy-security and TLS/certificate pinning to android-networking.

SKILL.md

android-security.SKILL.md
name: android-security
description: Secure Android data at rest and authentication secrets. Use for auth tokens, encrypted storage, and app-data isolation; defer WebView/Intent/FileProvider to android-legacy-security and TLS/certificate pinning to android-networking.
metadata:
  triggers:
    files:
    - 'network_security_config.xml'
    - 'AndroidManifest.xml'
    keywords:
    - EncryptedSharedPreferences
    - cleartextTrafficPermitted
    - intent-filter
    - api key
    - token storage
    - certificate pinning
    - root detection
    - secure storage

Android Security Standards

**Priority: P0 (CRITICAL)**

Implementation Guidelines

Data Storage

  • **Secrets**: NEVER store API keys in code. Use `EncryptedSharedPreferences` for sensitive local data (Tokens).
  • **Keystore**: Use Android Keystore System for cryptographic keys.

Network

  • **HTTPS**: Enforce HTTPS via `network_security_config.xml` (`cleartextTrafficPermitted="false"`).
  • **Pinning**: Consider Certificate Pinning for high-security apps.

Component Export

  • **Exported**: Explicitly set `android:exported="false"` for Activities/Receivers unless intended for external use.

Anti-Patterns

  • **No Sensitive Logs**: Strip logs in Release builds.
  • **No Homebrew Root Detection**: Use Play Integrity API instead.
  • **No Raw URL String Concatenation**: Use `Uri.Builder` or `HttpUrl` (OkHttp) to prevent parameter injection.

References

  • [Setup Examples](references/implementation.md)
  • [common/common-security-standards] — shared OWASP baselines
  • [android/android-legacy-security] — Intent, WebView, and FileProvider hardening
Read more
Ships withagent-skills-standard

The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.

Get the whole plugin

Other skills on agent-skills-standard.