Agent skill

Levyra Android Intent Security

by LUC4N3X in LUC4N3X/Levyra-deepsound

Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work.

GPL-3.0Auto-check passedSecurity

Install Levyra Android Intent Security

skills CLI
$ npx skills add LUC4N3X/Levyra-deepsound --skill levyra-android-intent-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LUC4N3X/Levyra-deepsound levyra-android-intent-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LUC4N3X/Levyra-deepsound.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/levyra-android-intent-security .claude/skills/levyra-android-intent-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
levyra-android-intent-security
GitHub stars
531
Token cost
~2k tokens
SKILL.md length
900 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
GPL-3.0

At a glance

Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work.

  • Works in 5 steps: Read root AGENTS.md and app/AGENTS.md. → Read docs/ARCHITECTURE.md,… → Inspect the affected manifest entries,… → …
  • Levyra Android Intent
  • SKILL.md covers Purpose, Required context, Component exposure and Incoming and nested Intents, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Levyra Android Intent Security is an agent skill from LUC4N3X/Levyra-deepsound. Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. Pair it with levyra-security-review and the affected Android domain skill.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. It works with Android. The repository describes itself as: Open-source music player for Android and Windows with no accounts or tracking. Built for quick discovery, synced lyrics, radio, and rich artwork ♫. The licence is GPL-3.0.

When your agent uses it

  • Levyra Android Intent
  • Exported component
  • Caller-verification
  • OnNewIntent security work

Example prompts

  • “/levyra-android-intent-security”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read root AGENTS.md and app/AGENTS.md.
  2. Read docs/ARCHITECTURE.md, docs/ai/CODEX_SECURITY.md, and
  3. Inspect the affected manifest entries, intent filters, exported state,
  4. Treat all incoming Intents, nested Intents, deep-link data, extras, ClipData,
  5. Preserve the exact existing external contract unless the task explicitly

What it can do on your machine

Read from SKILL.md and the folder at commit 6bc7c93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Levyra Android Intent Security loads about 2k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 900 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LUC4N3X/Levyra-deepsound at commit 6bc7c93, republished under its GPL-3.0 licence (© LUC4N3X). 900 words, ~1,962 tokens.

Download SKILL.mdSave it as .claude/skills/levyra-android-intent-security/SKILL.md (or your agent's skills folder).
name
levyra-android-intent-security
description
Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. Pair it with levyra-security-review and the affected Android domain skill.

Levyra Android Intent security workflow

Purpose

This is Levyra's Android-specific component-boundary security layer. It adapts selected practices from Google's android/skills Android Intent security guide to Levyra's actual architecture and minSdk without vendoring the upstream skill.

Always pair it with levyra-security-review. Also load the affected domain skill such as levyra-player, levyra-compose, or levyra-release-check when the boundary belongs to that area.

Required context

  1. Read root AGENTS.md and app/AGENTS.md.
  2. Read docs/ARCHITECTURE.md, docs/ai/CODEX_SECURITY.md, and .agents/claude/rules/security.md.
  3. Inspect the affected manifest entries, intent filters, exported state, permissions, component implementation, caller path, URI/provider contract, PendingIntent creation, and tests.
  4. Treat all incoming Intents, nested Intents, deep-link data, extras, ClipData, URI grants, and caller identity as untrusted unless a stronger verified trust boundary applies.
  5. Preserve the exact existing external contract unless the task explicitly changes it. Security hardening must not silently break legitimate Android Auto, notification, share, deep-link, update, or media flows.

Component exposure

  • Internal activities, services, receivers, and providers should remain non-exported unless external access is part of the feature contract.
  • Every exported privileged component needs a concrete external caller/use case plus the narrowest suitable protection: explicit intent contract, permission, caller verification, signature trust, or validated public input.
  • Do not infer safety from android:exported=false alone when another exported component can proxy attacker-controlled data into the private component.
  • Review manifest aliases, intent filters, provider authorities, dynamic receiver flags, and alternate warm-start paths together with the primary component.

Incoming and nested Intents

For an incoming Intent:

  1. allow only actions/categories/data schemes/hosts/types/extras actually used by the feature;
  2. type-check and bound attacker-controlled extras before use;
  3. validate URI authorities and permission-grant flags before forwarding or persisting access;
  4. prefer explicit internal targets;
  5. apply the same validation in onNewIntent or any reused-activity path as in the initial launch path.

Never launch or forward an attacker-controlled nested Intent directly.

When nested Intent forwarding is truly required, prefer IntentSanitizer or an explicit equivalent allowlist that constrains target component/package, action, data, type, categories, extras, and permitted flags. Reject or strip URI grant flags that are not part of the approved contract.

Do not cargo-cult an upstream sample. Verify the actual AndroidX Core version and the exact APIs available in Levyra before choosing a sanitizer implementation.

PendingIntent

  • Default to PendingIntent.FLAG_IMMUTABLE.
  • Use mutable PendingIntents only for a platform feature that genuinely requires receiver-side mutation, such as an approved remote-input flow.
  • A mutable PendingIntent must be narrowly scoped to an explicit trusted target; never combine mutability with an unconstrained implicit Intent.
  • Preserve uniqueness/request-code/update semantics relied on by notification, media controls, alarms, widgets, or other callers. Security changes must not accidentally alias unrelated PendingIntents.
  • Review both the base Intent and who receives the token; a PendingIntent grants the receiver the creator's authority for the represented operation.

Receivers and broadcasts

  • Prefer non-exported dynamic receivers for app-internal events when a broadcast is actually needed; do not reintroduce deprecated local-broadcast patterns.
  • Protect custom externally callable receivers with the narrowest permission or verified sender contract.
  • Treat ordinary broadcasts as spoofable unless the platform contract provides a trusted/system-only boundary.
  • Do not trust an action string or extra marker as caller authentication.
Show full SKILL.md (387 more words)Show less

Services and Binder callers

For exported or cross-app privileged services:

  • identify the real Binder/caller boundary before choosing where to authenticate;
  • use caller UID/package/signing checks when the feature contract depends on a trusted app identity;
  • account for UID-to-multiple-package mappings and signing-certificate rotation where applicable;
  • do not perform a one-time check at a lifecycle point that can be bypassed by a cached Binder connection if authorization is required per privileged call;
  • same-process calls may follow an internal path, but that does not make external entry points trusted.

Providers, FileProvider, and URI grants

  • Keep internal providers non-exported.
  • For exported providers, constrain read/write operations, projection, selection, paths, MIME types, and permissions to the documented contract.
  • Grant URI access only for the exact URI and duration required; avoid broad or persistent grants unless the feature explicitly needs them.
  • Preserve existing FileProvider path boundaries and never broaden roots merely to make sharing work.
  • Parameterize database/provider queries instead of concatenating untrusted selection data.
  • Treat scheme/host/path/query/fragment and every derived identifier as untrusted.
  • Separate navigation intent from privileged operations. Opening a screen is not authorization to perform account, file, update, playback, or destructive actions.
  • Validate both cold-start and onNewIntent delivery.
  • Reject unexpected schemes, authorities, encoded traversal, malformed IDs, or privilege-bearing nested payloads before state mutation.

Security review method

Follow levyra-security-review's closed loop:

text
threat model -> identify path -> safe validation -> minimal remediation
-> human review -> revalidation

For every finding state:

  • attacker-controlled entry point;
  • exported/caller trust boundary;
  • exact data or token being trusted;
  • path to the privileged/private operation;
  • concrete consequence;
  • safe reproduction or validation evidence;
  • smallest compatible fix;
  • regression/revalidation needed.

A broad exported component, mutable PendingIntent, or nested Intent is a review signal, not automatically a vulnerability. Confirm the reachable failure path.

Validation

Use the narrowest relevant checks, then the repository quality gate. Depending on the change this may include:

  • manifest/component inspection for every build/source-set variant involved;
  • focused unit tests for sanitization/allowlists;
  • instrumentation tests for exported-component behavior and URI grants;
  • cold-start and onNewIntent deep-link checks;
  • notification/media PendingIntent behavior;
  • negative tests proving rejected callers, targets, flags, extras, or URIs;
  • release/minified verification when reflection/component lookup is involved.

Device/emulator, external-caller, Android Auto, notification, provider, or permission behavior remains unverified unless it was actually exercised.

Provenance

This workflow is informed by Google's android/skills android-intent-security guide. Levyra keeps a compact native adaptation rather than copying its generic sample application assumptions or reference code. Current Android documentation, Levyra's architecture, and direct repository evidence take precedence.

© LUC4N3X, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/levyra-android-intent-security of LUC4N3X/Levyra-deepsound.

Open the folder on GitHubat commit 6bc7c93

Compare with similar skills

Levyra Android Intent Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Levyra Android Intent Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Levyra Android Intent Security this skillLUC4N3X/Levyra-deepsound531—~2kAutomated safety check: PassGPL-3.0
Performing Android App Static Analysis With Mobsfmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Code Review And Security Audithiroshiyui/GuilelessBopomofo135—~1.6kAutomated safety check: PassGPL-3.0
Android Static AnalyzerLeoYeAI/openclaw-master-skills2.2k—~2.7kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Performing Android App Static Analysis With Mobsf

    mukul975/Anthropic-Cybersecurity-Skills

    Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Code Review And Security Audit

    hiroshiyui/GuilelessBopomofo

    Review code for quality, correctness, and security vulnerabilities.

    135 GitHub stars~1.6k tokensUpdated 11 days ago
    DevelopmentAuto-check passed
  • Android Static Analyzer

    LeoYeAI/openclaw-master-skills

    分析 Android 项目源码,用 LLM 从多维度生成 AI 自动化测试所需的先验知识文档,打包上报测试平台。核心价值:让 AI 测试 Agent 在运行前就知道「测什么、怎么断言、有哪些陷阱」。触发词:「分析我的 Android 项目」「生成测试画像」「理解这个 App 的业务」「提取测试先验知识」「帮我分析 Android 源码」

    2.2k GitHub stars~2.7k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Agentlas Security Scan

    agentlas-ai/Agentlas-OS

    A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

    1.6k GitHub starsUsed in 1 repo~822 tokens
    SecurityAuto-check passed

More from LUC4N3X/Levyra-deepsound

All 22 skills in this repo
  • Levyra Context Efficiency

    LUC4N3X/Levyra-deepsound

    A skill your agent uses for genuinely high-volume Levyra work such as builds, tests, lint, logs, broad searches, dependency output, Git/GitHub or CodeRabbit inspection, CI diagnostics, agent setup…

    531 GitHub stars~1.3k tokensUpdated today
    Auto-check: notes
  • Levyra R8 Proguard

    LUC4N3X/Levyra-deepsound

    Automatically use for Levyra R8, Proguard, minification, resource shrinking, keep rules, consumer rules, release-only crashes, reflection/serialization/JNI shrinking issues, APK size, mapping files…

    531 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Levyra Android Performance

    LUC4N3X/Levyra-deepsound

    Automatically use for Android runtime performance investigations involving Perfetto/System Trace, jank, latency, startup, CPU scheduling, blocking, memory, I/O, IPC, graphics, power, or measured…

    531 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Levyra CI Workflows

    LUC4N3X/Levyra-deepsound

    Automatically use for Levyra GitHub Actions, CI, F-Droid, Gradle/AGP/Kotlin/KSP compatibility, build performance, configuration/build cache, artifacts, release automation, workflow security, or…

    531 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Levyra Design Taste

    LUC4N3X/Levyra-deepsound

    Automatically use together with the matching Levyra UI skill for any visual redesign, UI polish, visual hierarchy, spacing, typography, color, shape, motion, screenshot/reference recreation, or…

    531 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Levyra PR Review

    LUC4N3X/Levyra-deepsound

    Review a Levyra branch, commit, patch, or pull request for correctness, regressions, concurrency, lifecycle, security, data safety, UI behavior, CI, release risk, missing tests, and merge-readiness…

    531 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Levyra Android Intent Security

What does Levyra Android Intent Security do?

Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work. Levyra Android Intent Security is an agent skill from LUC4N3X/Levyra-deepsound. Automatically use for Levyra Android Intent, deep-link, PendingIntent, exported component, receiver, service, provider, URI-grant, FileProvider, caller-verification, or onNewIntent security work.

When should I use Levyra Android Intent Security?

Levyra Android Intent Security fits situations like: levyra Android Intent; exported component; caller-verification; onNewIntent security work.

How do I install Levyra Android Intent Security in Claude Code?

Run `npx skills add LUC4N3X/Levyra-deepsound --skill levyra-android-intent-security -a claude-code`. Or copy the skill folder (.agents/skills/levyra-android-intent-security in LUC4N3X/Levyra-deepsound) into .claude/skills/levyra-android-intent-security in your project. Claude Code loads it when a task matches its description.

How do I install Levyra Android Intent Security in Codex?

Run `npx skills add LUC4N3X/Levyra-deepsound --skill levyra-android-intent-security -a codex`. Or copy the skill folder (.agents/skills/levyra-android-intent-security in LUC4N3X/Levyra-deepsound) into .agents/skills/levyra-android-intent-security in your project. Codex loads it when a task matches its description.

Can I use Levyra Android Intent Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LUC4N3X/Levyra-deepsound --skill levyra-android-intent-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/levyra-android-intent-security, .gemini/skills/levyra-android-intent-security, .github/skills/levyra-android-intent-security and .opencode/skills/levyra-android-intent-security in your project.

What does Levyra Android Intent Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Levyra Android Intent Security is instructions for the agent only.

Does Levyra Android Intent Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Levyra Android Intent Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Levyra Android Intent Security use?

Levyra Android Intent Security is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Levyra Android Intent Security use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Levyra Android Intent Security?

Skills that share tags, products or a category with Levyra Android Intent Security: Performing Android App Static Analysis With Mobsf (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Code Review And Security Audit (hiroshiyui/GuilelessBopomofo, 135 stars), Android Static Analyzer (LeoYeAI/openclaw-master-skills, 2.2k stars) and Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Levyra Android Intent Security?

LUC4N3X (a GitHub user) maintains it in LUC4N3X/Levyra-deepsound, which has 531 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.

Source: LUC4N3X/Levyra-deepsound on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.