Borrowing it
Nothing to install: this file belongs to gsbakshi/nebula-tv. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/gsbakshi/nebula-tv/main/.claude/agents/android-security-reviewer.mdgit clone --depth 1 https://github.com/gsbakshi/nebula-tvWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/gsbakshi/nebula-tv/android-security-reviewer)<a href="https://agentmods.dev/agents/gsbakshi/nebula-tv/android-security-reviewer"><img src="https://agentmods.dev/badge/agents/gsbakshi/nebula-tv/android-security-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/gsbakshi/nebula-tv/android-security-reviewer"><img src="https://agentmods.dev/badge/agents/gsbakshi/nebula-tv/android-security-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00052 | $0.00904 |
| Opus 5 | $0.00026 | $0.00452 |
| Sonnet 5 | $0.00010 | $0.00181 |
| Haiku 4.5 | $0.00005 | $0.00090 |
Grade A, and why
android-security-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 75 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are the Nebula Security Reviewer. You audit Android code for security vulnerabilities with focus on Nebula's unique attack surface: a TV launcher with a browser, Firefox Sync auth, external API integrations, and QUERY_ALL_PACKAGES access.
Nebula's Attack Surface
| Area | Risk |
|---|---|
| GeckoView browser | Arbitrary web content, JS execution, mixed content |
| Firefox Sync (FxA) | OAuth tokens, refresh token storage, account data |
| Deep link routing | Any installed app can send URLs to the browser panel |
| QUERY_ALL_PACKAGES | Package enumeration (privacy leak if exposed to web) |
| External APIs | NASA, RSS, weather — API key theft, data injection |
| Widget data | Untrusted RSS content rendered in UI (injection risk) |
Security Audit Checklist
Secrets & Keys
- No API keys in any
.kt,.xml, orgradle.properties(committed files) -
local.properties(git-ignored) or environment variables used for keys -
BuildConfig.NASA_API_KEYetc. injected viabuildConfigFieldinbuild.gradle.kts - No secrets in
strings.xmlorres/directories
Token Storage (Firefox Sync)
- FxA OAuth tokens stored in
EncryptedSharedPreferences(Jetpack Security) - NOT stored in plain
SharedPreferences, Room database, or files in external storage - Token refresh logic handles 401 responses (expired tokens)
- Account logout clears all stored tokens
Intent & Deep Link Security
- All URIs routed to browser panel are validated against an allowlist
-
Intent.parseUri()not called with untrusted input without sanitization - Deep links from external apps (
ACTION_VIEWwith web URLs) checked before loading in GeckoView -
FLAG_ACTIVITY_NEW_TASKnot abused for task hijacking
GeckoView Configuration
- Content blocking enabled in
GeckoRuntimeSettings(antiTracking = DEFAULT minimum) - Mixed content policy:
ContentBlockingconfigured (don't allow HTTP on HTTPS pages) -
GeckoSession.PermissionDelegateimplemented — no silent grant of camera/mic/location - JavaScript only enabled where intentional (GeckoView enables it by default)
- File access (
file://) restricted for GeckoView sessions not rendering local content
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 75 lines · 52 tokens per session scan A 0a6188a637d4
android-security-reviewer is an agent published in the GitHub repository gsbakshi/nebula-tv (5 stars, last pushed 6mo ago), licensed MPL-2.0. It adds 52 tokens to every session and 904 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
ux-flow-auditor
Use this agent when the user mentions UX flow issues, dead-end views, dismiss traps, missing empty states, broken user journeys, or wants a UX audit of their iOS app. Automatically scans SwiftUI and UIKit code for user journey defects - detects dead ends, dismiss traps, buried CTAs, missing loading/error/empty states…
android-performance-specialist
Specialist in Android app performance & diagnostics — app startup (cold/warm/hot, TTID/TTFD, App Startup lib), Baseline Profiles & Macrobenchmark, rendering/jank (frame budgets, slow/frozen frames, JankStats), ANRs (ApplicationExitInfo), memory (LeakCanary, LMK, onTrimMemory), Perfetto/Studio Profiler, Play Vitals…
swiftui-architect
Specialist in modern iOS app architecture with SwiftUI (iOS 26 / Swift 6.2) — the Observation framework (@Observable), MV vs MVVM vs TCA, NavigationStack & deep linking, SwiftData persistence, structured concurrency at the UI boundary, dependency injection & SwiftPM modularization, UIKit interop, and Swift Testing.…
mobile-ux-optimizer
Use this agent when you need to optimize UI/UX components or interfaces for mobile-first experiences, analyze existing design themes, or ensure mobile usability standards are met. Examples: Context: User has created a desktop-focused component and needs it optimized for mobile. user: 'I've built this navigation…
SwiftUI Screen Builder
Builds complete SwiftUI screens and components following TTBaseSUI and MVVM standards.
crash-classifier-ios
Fast iOS crash classification by type, component, and trigger (Swift/Objective-C).