Back to skills
SKILL.md
Android Security
ASecurityStandards for Data Encryption, Network Security, and Permissions
- 2 stars
- 0 votes
- 0 copies
- 1 view
- Added September 27, 2026
Works with
Security analysis
100/100Pro scans all 2 files and shows the line behind each finding
npx -y skills add David-Li0406/meta-skill-evloving --skill android-security --agent claude-codeAre you the author of Android Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/david-li0406-android-security)---
name: Android Security
description: Standards for Data Encryption, Network Security, and Permissions
metadata:
labels: [android, security, encryption]
triggers:
files: ['network_security_config.xml', 'AndroidManifest.xml']
keywords:
[
'EncryptedSharedPreferences',
'cleartextTrafficPermitted',
'intent-filter',
]
---
# Android Security Standards
## **Priority: P0 (CRITICAL)**
## Implementation Guidelines
### Data Storage
- **Secrets**: NEVER store API keys in code. Use `EncryptedSharedPreferences` for sensitive local data (Tokens).
- **Keystore**: Use Android Keystore System for cryptographic keys.
### Network
- **HTTPS**: Enforce HTTPS via `network_security_config.xml` (`cleartextTrafficPermitted="false"`).
- **Pinning**: Consider Certificate Pinning for high-security apps.
### Component Export
- **Exported**: Explicitly set `android:exported="false"` for Activities/Receivers unless intended for external use.
## Anti-Patterns
- **No Sensitive Logs**: Strip logs in Release builds.
- **No Homebrew Root Detection**: Use Play Integrity API instead.
- **No Raw URL String Concatenation**: Use `Uri.Builder` or `HttpUrl` (OkHttp) to prevent parameter injection.
## References
- [Setup Examples](references/implementation.md)
## Related Topics
common/security-standards | architecture
Files in this skill
- SKILL.md
- references/implementation.md
Attribution
Comments
Loading comments…