Standards for Intents, WebViews, and FileProvider. Use when securing Intent handling, WebViews, or FileProvider access in Android. (triggers: **/*Activity.kt, **/*WebView*.kt, AndroidManifest.xml, Intent, WebView, FileProvider, javaScriptEnabled)
Scanned 5/30/2026
Install via CLI
openskills install ComeOnOliver/skillshub---
name: android-legacy-security
description: 'Standards for Intents, WebViews, and FileProvider. Use when securing Intent handling, WebViews, or FileProvider access in Android. (triggers: **/*Activity.kt, **/*WebView*.kt, AndroidManifest.xml, Intent, WebView, FileProvider, javaScriptEnabled)'
---
# Android Legacy Security Standards
## **Priority: P0**
## Implementation Guidelines
### Intents & Components
- **Visibility**: Set **`android:exported="false"`** in the Manifest for all internal Activities/Services unless explicitly needed for deep links or external integration.
- **Intents**: Verify **`resolveActivity`** before starting implicit intents. Use **`LocalBroadcastManager`** (legacy) or **`SharedFlow/StateFlow`** for internal communication.
- **Data**: Treat all incoming **Intent extras as untrusted**. Validate all schema/data types before consumption.
### WebView
- **JS**: Default to **`javaScriptEnabled = false`**. Use **`WebViewClient`** and **`WebChromeClient`** to restrict navigation and origin access.
- **File Access**: Disable **`allowFileAccess`** and **`allowFileAccessFromFileURLs`** to prevent local file theft via XSS.
- **Bridge**: If creating a **`JavascriptInterface`**, use **`@JavascriptInterface`** (API 17+) and strictly limit the exposed API surface.
### Storage & Files
- **File Exposure**: **NEVER expose `file://` URIs**. Use **`FileProvider`** (androidx) to generate **`content://`** URIs with temporary permissions.
- **SharedPreferences**: Use **`EncryptedSharedPreferences`** (Security library) for auth tokens and PII. Never use **`MODE_WORLD_READABLE`** (deprecated/insecure).
- **Network**: Use **`NetworkSecurityConfig`** to disable **`cleartextTrafficPermitted`** (mandatory for API 28+) and implement **SSL Pinning/Certificate Pinning**.
## Anti-Patterns
- **No Implicit Intents Internally**: Use explicit intents with the component class name.
- **No MODE_WORLD_READABLE**: Never use for SharedPreferences or files.
## References
- [Hardening Examples](references/implementation.md)
No comments yet. Be the first to comment!
Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.
SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.
Python backend development expertise for FastAPI, security patterns, database operations, Upstash integrations, and code quality. Use when: (1) Building REST APIs with FastAPI, (2) Implementing JWT/OAuth2 authentication, (3) Setting up SQLAlchemy/async databases, (4) Integrating Redis/Upstash caching, (5) Refactoring AI-generated Python code (deslopification), (6) Designing API patterns, or (7) Optimizing backend performance.
Drive the full internationalization journey for a project — detect the stack, recommend a library, set up the chosen library, wrap existing strings, and optionally connect a translation platform. Use when the user asks to add or configure i18n, internationalization, localization, multi-language support, or translations — including when they explicitly mention LinguiJS, Lingui, next-intl, "wrap strings", "find hardcoded text", "make my app translatable", or "set up translations". Triggers on g...
PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.