Agent skill

Aosp Security

by aospbooks in aospbooks/aosp-internal-book

AOSP Part IX — Security. An agent skill from aospbooks/aosp-internal-book.

Apache-2.0Auto-check passedMobile

Install Aosp Security

skills CLI
$ npx skills add aospbooks/aosp-internal-book --skill aosp-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aospbooks/aosp-internal-book aosp-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aospbooks/aosp-internal-book.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/_content/parts/security .claude/skills/aosp-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aosp-security
GitHub stars
139
Token cost
~491 tokens
SKILL.md length
128 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

AOSP Part IX — Security. An agent skill from aospbooks/aosp-internal-book.

  • Reasoning about SELinux on Android
  • SKILL.md covers Chapters in this Part and When to load which chapter
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Keystore/Keymint

What it does

Aosp Security is an agent skill from aospbooks/aosp-internal-book. AOSP Part IX — Security. Use when reasoning about SELinux on Android, Keystore/Keymint, Trusty TEE, gatekeeper/weaver, Android Verified Boot, dm-verity, hardware-backed attestation, Credential Manager (CredentialManagerService, credential providers, passkeys/FIDO2, password and autofill integration, digital credentials), or DRM (MediaDrm framework, Widevine L1/L2/L3, OEMCrypto, license acquisition, secure decoder/display path), or the LFI in-process sandbox (Lightweight Fault Isolation for untrusted code such as…

Its SKILL.md is about 490 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile. It works with Android. The repository describes itself as: The book introduces the internal of AOSP. The licence is Apache-2.0.

When your agent uses it

  • Reasoning about SELinux on Android
  • Keystore/Keymint
  • Gatekeeper/weaver
  • Android Verified Boot

Example prompts

  • “/aosp-security”

What it can do on your machine

Read from SKILL.md and the folder at commit fc0b48b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aosp Security loads about 491 tokens when it runs. Until then it costs about 142 tokens; SKILL.md has 128 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~491

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aospbooks/aosp-internal-book at commit fc0b48b, republished under its Apache-2.0 licence (© aospbooks). 128 words, ~491 tokens.

Download SKILL.mdSave it as .claude/skills/aosp-security/SKILL.md (or your agent's skills folder).
name
aosp-security
description
AOSP Part IX — Security. Use when reasoning about SELinux on Android, Keystore/Keymint, Trusty TEE, gatekeeper/weaver, Android Verified Boot, dm-verity, hardware-backed attestation, Credential Manager (CredentialManagerService, credential providers, passkeys/FIDO2, password and autofill integration, digital credentials), or DRM (MediaDrm framework, Widevine L1/L2/L3, OEMCrypto, license acquisition, secure decoder/display path), or the LFI in-process sandbox (Lightweight Fault Isolation for untrusted code such as software codecs). Chapters 40–42, 68.
metadata.author
utzcoz
metadata.version
2026.06.24
metadata.last-updated
2026-10-05

AOSP Part IX — Security

Trust roots, key storage, credential management, and content protection.

Chapters in this Part

  • 40-security.md — SELinux on Android, Keystore/Keymint, Trusty TEE, gatekeeper/weaver, AVB, dm-verity, hardware-backed attestation
  • 41-credential-manager.md — CredentialManagerService, credential providers, passkeys/FIDO2, password and autofill integration, digital credentials
  • 42-drm.md — MediaDrm framework, Widevine L1/L2/L3, OEMCrypto, license acquisition, secure decoder/display path
  • 43-lfi-sandbox.md — Lightweight Fault Isolation: memory-safe in-process sandboxing for untrusted code (software codecs) without a separate process; the external/lfi verifier and runtime, the Soong LFI toolchain, and the libapexcodecs/codec2 integration

When to load which chapter

  • Question mentions SELinux, Keystore, Keymint, Trusty, gatekeeper, weaver, AVB, attestation → 40-security.md
  • Question mentions Credential Manager, passkeys, FIDO2, autofill, digital credentials → 41-credential-manager.md
  • Question mentions MediaDrm, Widevine, OEMCrypto, secure decoder, license server → 42-drm.md
  • Question mentions LFI, lightweight fault isolation, in-process sandboxing, sandboxed software codec → 43-lfi-sandbox.md

© aospbooks, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/_content/parts/security of aospbooks/aosp-internal-book.

Open the folder on GitHubat commit fc0b48b

Compare with similar skills

Aosp Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aosp Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aosp Security this skillaospbooks/aosp-internal-book139—~491Automated safety check: PassApache-2.0
Compose Multiplatform Patternsmonta-app/ocpp-emulator1805 repos~2kAutomated safety check: PassApache-2.0
Phone HarnessShawnPana/phone-harness3.2k—~4.3kAutomated safety check: PassMIT
Stylesarindamxd/camerax-android1324 repos~2.3kAutomated safety check: PassApache-2.0
Verified Emailarindamxd/camerax-android1324 repos~4.7kAutomated safety check: PassApache-2.0
Argent Metro Debuggerbbplayer-app/BBPlayer1.2k—~3.4kAutomated safety check: PassMIT

Similar skills

  • Compose Multiplatform Patterns

    monta-app/ocpp-emulator

    Compose Multiplatform and Jetpack Compose patterns for KMP projects — state management, navigation, theming, performance, and platform-specific UI.

    180 GitHub starsUsed in 5 repos~2k tokens
    MobileAuto-check passed
  • Phone Harness

    ShawnPana/phone-harness

    Control the user's phone — an iPhone through the Mac's iPhone Mirroring window, an Android over adb, or a rented cloud Android: open apps, tap, type, swipe, read the screen.

    3.2k GitHub stars~4.3k tokensUpdated today
    MobileAuto-check passed
  • Styles

    arindamxd/camerax-android

    A skill your agent uses to integrate the Jetpack Compose Styles API into an Android project.

    132 GitHub starsUsed in 4 repos~2.3k tokens
    MobileAuto-check passed
  • Verified Email

    arindamxd/camerax-android

    Provides a complete workflow for implementing verified email retrieval on Android Credential Manager API.

    132 GitHub starsUsed in 4 repos~4.7k tokens
    MobileAuto-check passed
  • Argent Metro Debugger

    bbplayer-app/BBPlayer

    Debug a JS runtime via CDP using argent debugger tools. An agent skill from bbplayer-app/BBPlayer.

    1.2k GitHub stars~3.4k tokensUpdated yesterday
    MobileAuto-check passed
  • 统一 Android XML 资源命名:layout、drawable、mipmap、color、values、id 的前缀与 snakecase 规则;把颜色/圆角/描边/状态编码进文件名(bg、border、textcolor…selector)。

    1.6k GitHub stars~1.3k tokensUpdated 1 mo ago
    MobileAuto-check passed

More from aospbooks/aosp-internal-book

All 17 skills in this repo
  • Book Writer

    aospbooks/aosp-internal-book

    Patterns for writing technical book chapters in Markdown with Mermaid diagrams, served via ProperDocs (a MkDocs fork).

    139 GitHub stars~3.1k tokensUpdated 4 days ago
    Auto-check passed
  • Aosp Version Diff

    aospbooks/aosp-internal-book

    Compare two AOSP releases (e.g. An agent skill from aospbooks/aosp-internal-book.

    139 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • Aosp Device Support

    aospbooks/aosp-internal-book

    AOSP Part XIV — Device Support. An agent skill from aospbooks/aosp-internal-book.

    139 GitHub stars~574 tokensUpdated 4 days ago
    Auto-check passed
  • Aosp Framework Core

    aospbooks/aosp-internal-book

    AOSP Part VI — Framework Core. An agent skill from aospbooks/aosp-internal-book.

    139 GitHub stars~628 tokensUpdated 4 days ago
    Auto-check passed
  • Aosp Framework Services

    aospbooks/aosp-internal-book

    AOSP Part VII — Framework Services. An agent skill from aospbooks/aosp-internal-book.

    139 GitHub stars~888 tokensUpdated 4 days ago
    Auto-check passed
  • Aosp Native Services And Media

    aospbooks/aosp-internal-book

    AOSP Part IV — Native Services & Media. An agent skill from aospbooks/aosp-internal-book.

    139 GitHub stars~606 tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about Aosp Security

What does Aosp Security do?

AOSP Part IX — Security. An agent skill from aospbooks/aosp-internal-book. Aosp Security is an agent skill from aospbooks/aosp-internal-book. AOSP Part IX — Security.

When should I use Aosp Security?

Aosp Security fits situations like: reasoning about SELinux on Android; keystore/Keymint; gatekeeper/weaver; android Verified Boot.

How do I install Aosp Security in Claude Code?

Run `npx skills add aospbooks/aosp-internal-book --skill aosp-security -a claude-code`. Or copy the skill folder (agents/_content/parts/security in aospbooks/aosp-internal-book) into .claude/skills/aosp-security in your project. Claude Code loads it when a task matches its description.

How do I install Aosp Security in Codex?

Run `npx skills add aospbooks/aosp-internal-book --skill aosp-security -a codex`. Or copy the skill folder (agents/_content/parts/security in aospbooks/aosp-internal-book) into .agents/skills/aosp-security in your project. Codex loads it when a task matches its description.

Can I use Aosp Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aospbooks/aosp-internal-book --skill aosp-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aosp-security, .gemini/skills/aosp-security, .github/skills/aosp-security and .opencode/skills/aosp-security in your project.

What does Aosp Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Aosp Security is instructions for the agent only.

Does Aosp Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Aosp Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aosp Security use?

Aosp Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aosp Security use?

About 491 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aosp Security?

Skills that share tags, products or a category with Aosp Security: Compose Multiplatform Patterns (monta-app/ocpp-emulator, 180 stars), Phone Harness (ShawnPana/phone-harness, 3.2k stars), Styles (arindamxd/camerax-android, 132 stars) and Verified Email (arindamxd/camerax-android, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aosp Security?

aospbooks (a GitHub organization) maintains it in aospbooks/aosp-internal-book, which has 139 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.

Source: aospbooks/aosp-internal-book on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.