Skip to content
Back to skills

Android Legacy Security

ASecurity

Standards for Intents, WebViews, and FileProvider

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
developmentjavascriptrustjavasecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill android-legacy-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Android Legacy Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Android Legacy Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-android-legacy-security/badge)](https://www.skillsdirectory.com/skills/david-li0406-android-legacy-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Android Legacy Security
description: Standards for Intents, WebViews, and FileProvider
metadata:
  labels: [android, security, legacy, intents]
  triggers:
    files: ['**/*Activity.kt', '**/*WebView*.kt', 'AndroidManifest.xml']
    keywords: ['Intent', 'WebView', 'FileProvider', 'javaScriptEnabled']
---

# Android Legacy Security Standards

## **Priority: P0**

## Implementation Guidelines

### Intents

- **Implicit**: Always verify `resolveActivity` before starting.
- **Exported**: Verify `android:exported` logic (as per `security` skill).
- **Data**: Treat all incoming Intent extras as untrusted input.

### WebView

- **JS**: Default to `javaScriptEnabled = false`. Only enable for trusted domains.
- **File Access**: Disable `allowFileAccess` to prevent local file theft via XSS.

### File Exposure

- **FileProvider**: NEVER expose `file://` URIs. Use `FileProvider`.

## Anti-Patterns

- **Implicit Internal**: `**No Implicit for Internal**: Use Explicit Intents (class name).`
- **World Readable**: `**No MODE_WORLD_READABLE**: SharedPreferences/Files.`

## References

- [Hardening Examples](references/implementation.md)

Files in this skill

  • SKILL.md1.1 KB
  • references/implementation.md1.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…