Back to skills
SKILL.md
Android Legacy Security
ASecurityStandards for Intents, WebViews, and FileProvider
- 2 stars
- 0 votes
- 0 copies
- 0 views
- Added September 27, 2026
Security analysis
100/100Pro scans all 2 files and shows the line behind each finding
npx -y skills add David-Li0406/meta-skill-evloving --skill android-legacy-security --agent claude-codeAre you the author of Android Legacy Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/david-li0406-android-legacy-security)---
name: Android Legacy Security
description: Standards for Intents, WebViews, and FileProvider
metadata:
labels: [android, security, legacy, intents]
triggers:
files: ['**/*Activity.kt', '**/*WebView*.kt', 'AndroidManifest.xml']
keywords: ['Intent', 'WebView', 'FileProvider', 'javaScriptEnabled']
---
# Android Legacy Security Standards
## **Priority: P0**
## Implementation Guidelines
### Intents
- **Implicit**: Always verify `resolveActivity` before starting.
- **Exported**: Verify `android:exported` logic (as per `security` skill).
- **Data**: Treat all incoming Intent extras as untrusted input.
### WebView
- **JS**: Default to `javaScriptEnabled = false`. Only enable for trusted domains.
- **File Access**: Disable `allowFileAccess` to prevent local file theft via XSS.
### File Exposure
- **FileProvider**: NEVER expose `file://` URIs. Use `FileProvider`.
## Anti-Patterns
- **Implicit Internal**: `**No Implicit for Internal**: Use Explicit Intents (class name).`
- **World Readable**: `**No MODE_WORLD_READABLE**: SharedPreferences/Files.`
## References
- [Hardening Examples](references/implementation.md)
Files in this skill
- SKILL.md
- references/implementation.md
Attribution
Comments
Loading comments…