Inspect Network Traffic
HedvigInsurance/android
Read the HTTP and GraphQL calls a debug build of the Android app made, with request and response bodies, status codes, timings and errors, over adb.
Provides a complete workflow for implementing verified email retrieval on Android Credential Manager API.
$ npx skills add sreichholf/dreamDroid --skill verified-email -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sreichholf/dreamDroid verified-email --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sreichholf/dreamDroid.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/verified-email .claude/skills/verified-email && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verified-email" agent skill from https://github.com/sreichholf/dreamDroid/tree/main/.agents/skills/verified-email into .claude/skills/verified-email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verified-email", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sreichholf/dreamDroid/tree/main/.agents/skills/verified-emailType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sreichholf/dreamDroid --skill verified-email -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sreichholf/dreamDroid verified-email --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sreichholf/dreamDroid.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/verified-email .agents/skills/verified-email && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verified-email" agent skill from https://github.com/sreichholf/dreamDroid/tree/main/.agents/skills/verified-email into .agents/skills/verified-email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verified-email", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sreichholf/dreamDroid --skill verified-email -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sreichholf/dreamDroid verified-email --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sreichholf/dreamDroid.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/verified-email .cursor/skills/verified-email && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verified-email" agent skill from https://github.com/sreichholf/dreamDroid/tree/main/.agents/skills/verified-email into .cursor/skills/verified-email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verified-email", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sreichholf/dreamDroid.git --path .agents/skills/verified-email--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sreichholf/dreamDroid --skill verified-email -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sreichholf/dreamDroid verified-email --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sreichholf/dreamDroid.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/verified-email .gemini/skills/verified-email && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verified-email" agent skill from https://github.com/sreichholf/dreamDroid/tree/main/.agents/skills/verified-email into .gemini/skills/verified-email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verified-email", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sreichholf/dreamDroid verified-emailInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sreichholf/dreamDroid --skill verified-email -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sreichholf/dreamDroid.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/verified-email .github/skills/verified-email && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verified-email" agent skill from https://github.com/sreichholf/dreamDroid/tree/main/.agents/skills/verified-email into .github/skills/verified-email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verified-email", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sreichholf/dreamDroid --skill verified-email -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sreichholf/dreamDroid verified-email --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sreichholf/dreamDroid.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/verified-email .opencode/skills/verified-email && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verified-email" agent skill from https://github.com/sreichholf/dreamDroid/tree/main/.agents/skills/verified-email into .opencode/skills/verified-email/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verified-email", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verified-emailProvides a complete workflow for implementing verified email retrieval on Android Credential Manager API.
Verified Email is an agent skill from sreichholf/dreamDroid. Provides a complete workflow for implementing verified email retrieval on Android Credential Manager API. Use this skill to integrate a secure, OTP-less email verification flow into an Android app. This skill solves the problem of high-friction sign-up processes by leveraging cryptographically verified credentials from trusted providers like Google.
Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including reference files (for example `references/android/identity/credential-manager/index.md`, `references/android/identity/digital-credentials/credential-verifier.md` and `references/android/identity/digital-credentials/email-verification-implementation.md`).
It sits in Mobile, covering Android development. It works with Android. The repository describes itself as: DreamDroid is an open-source enigma2 client for android based devices. The licence is GPL-3.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ee2d56f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are kotlin and groovy).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
verifiablecredentials-pa.googleapis.comAlso links to:
developer.android.comopenid.netdatatracker.ietf.orgdigital-credentials.devw3.orgiso.orgdevelopers.google.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verified Email loads about 5.1k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 2,006 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sreichholf/dreamDroid at commit ee2d56f, republished under its GPL-3.0 licence (© sreichholf). 2,006 words, ~5,092 tokens.
.claude/skills/verified-email/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.dcql_query, UserInfoCredential, and GetDigitalCredentialOption.Email verification is applicable for the following use cases:
Crucial : This skill focuses exclusively on the Android client-side integration . It does not implement the app's server-side cryptographic validation logic. Server-side validation of the returned credential is required for security and must be implemented in your backend.
Get started with the following queries in project source code to find relevant screens with different use cases to implement verified email:
SignUpScreen"Email address""Recover Account""Account Recovery""Forgot password?""Delete Account"To implement this feature effectively, you must first locate the relevant flows in your codebase. To initiate, start with the following strategies to cater to different use cases using verified email:
If your app uses Navigation, search for routes or destinations related to authentication:
Look for:
signup, registration, create_account, forgot_password, recovery, verify_email.NavHost or composable destinations using these strings.Find the business logic handling user attributes and account creation, account recovery:
SignUpViewModel, AuthViewModel, RegistrationRepository.onCreateAccount, onRecoverAccount, or validateEmail.For reauthentication use cases, find areas where users perform sensitive actions:
ChangePassword, UpdatePayment, DeleteAccount, UpdateDetails, EditUserDetailsSdJwtParser to parse raw SD-JWT and return a JSONObject.VerifiedUserInfo data class to store the parsed name and email.This guide describes how to implement verified email retrieval using the Digital Credentials Verifier API through an OpenID for Verifiable Presentations (OpenID4VP) request.
In your app's build.gradle file, add the following dependencies for Credential
Manager:
dependencies {
implementation("androidx.credentials:credentials:1.7.0-alpha03")
implementation("androidx.credentials:credentials-play-services-auth:1.7.0-alpha03")
}dependencies {
implementation "androidx.credentials:credentials:1.7.0-alpha03"
implementation "androidx.credentials:credentials-play-services-auth:1.7.0-alpha03"
}Use your app or activity context to create a CredentialManager object.
// Use your app or activity context to instantiate a client instance of
// CredentialManager.
private val credentialManager = CredentialManager.create(context)To request a verified email, construct a GetCredentialRequest
containing a GetDigitalCredentialOption. This option requires a
requestJson string formatted as an OpenID for Verifiable Presentations
(OpenID4VP) request.
The OpenID4VP request JSON must follow a specific structure. The current
providers support a JSON structure with an outer "digital": {"requests": [...]} wrapper.
val nonce = generateSecureRandomNonce()
// This request follows the OpenID4VP spec
val openId4vpRequest = """
{
"requests": [
{
"protocol": "openid4vp-v1-unsigned",
"data": {
"response_type": "vp_token",
"response_mode": "dc_api",
"nonce": "$nonce",
"dcql_query": {
"credentials": [
{
"id": "user_info_query",
"format": "dc+sd-jwt",
"meta": {
"vct_values": ["UserInfoCredential"]
},
"claims": [
{"path": ["email"]},
{"path": ["name"]},
{"path": ["given_name"]},
{"path": ["family_name"]},
{"path": ["picture"]},
{"path": ["hd"]},
{"path": ["email_verified"]}
]
}
]
}
}
}
]
}
"""
val getDigitalCredentialOption = GetDigitalCredentialOption(requestJson = openId4vpRequest)
val request = GetCredentialRequest(listOf(getDigitalCredentialOption))The request contains the following key information:
DCQL query : The dcql_query specifies the credential type and the
claims being requested (email_verified). You can request other claims to
determine the level of verification. A few possible claims are as follows:
email_verified: In the response, this is a Boolean that indicates whether the email is verified.hd (hosted domain): In the response, this is empty.[!NOTE] Note: If
email_verifiedistrueandhdis empty in the response, it implies that the account is an authorized Google Account. Google does not issue verifiable credentials for Google Workspace Accounts. However, thehdfield is present in verifiable credentials issued for non-workspace accounts. You are encouraged to implement handling this field to future-proof your app. If the email is non-@gmail.com, Google verified this email when the Google Account was created, but there is no freshness claim. Therefore, for non-Google emails, you should consider an additional challenge, such as an OTP, to verify the user. To understand the schema of the credential and the specific rules for validating fields likeemail_verified, refer to the Google Identity guides.
nonce: A unique, cryptographically secure random value is generated for each request. This is critical for security, as it prevents replay attacks.
UserInfoCredential: This value implies a specific type of digital
credential that contains user attributes. Including this in the request is
pivotal to distinguish the email verification use case.
Next, wrap the openId4vpRequest JSON in a GetDigitalCredentialOption, create
a GetCredentialRequest, and call getCredential().
[!NOTE] Note: The
hdandemail_verifiedfields are hidden from users in Credential Manager's built-in UI. You cannot make a request with only these hidden fields- in case of such requests, the response is theGetCredentialCancellationException.
Present the user with the request, using the Credential Manager built-in UI.
coroutineScope {
try {
// Requesting Digital Credential from user...
val result = credentialManager.getCredential(activity, request)
when (val credential = result.credential) {
is DigitalCredential -> {
val responseJsonString = credential.credentialJson
// Successfully received digital credential response.
// Next, parse this response and send it to your server.
// ...
}
else -> {
// handle Unexpected State() - Up to the developer
}
}
} catch (e: Exception) {
// handle exceptions - Up to the developer
}
}[!NOTE] Note: There is no equivalent of Sign in with Google's
preferImmediatelyAvailableCredentialsfor Digital Credentials. If no verifiable credential is found (for example, no eligible account on device), the user will be shown a "No options available" or similar system screen.
[!WARNING] Warning: From August 2026, the response JSON format has been updated to strictly match the W3C standards. It contains
dataandprotocolkeys, with the OpenID4VPvp_tokennested indata, while legacy formats hold thevp_tokendirectly. Ensure your client-side parsing and server-side validation handle both formats during the transition period, while the older implementation is phased out. Apps that begin to integrate the email verification flow after August 2026 need to use the new format only.
After receiving the response, you can perform a preliminary parse on the client. This is useful for immediately updating the UI, for example, by showing the user's name.
[!IMPORTANT] Important: This step is not for validation. Full cryptographic verification must be performed on your server.
The following code extracts the raw Selective Disclosure JWT (SD-JWT) and uses a helper to decode its claims.
// 1. Parse the outer JSON wrapper to get the `vp_token`
val responseData = JSONObject(responseJsonString)
val dataObject = responseData.getJSONObject("data")
val vpToken = dataObject.getJSONObject("vp_token")
// 2. Extract the raw SD-JWT string
val credentialId = vpToken.keys().next()
val rawSdJwt = vpToken.getJSONArray(credentialId).getString(0)
// 3. Use your parser to get the verified claims
// Server-side validation/parsing is highly recommended.
// Assumes a local parser like the one in our SdJwtParser.kt sample
val claims = SdJwtParser.parse(rawSdJwt)
Log.d("TAG", "Parsed Claims: ${claims.toString(2)}")
// 4. Create your VerifiedUserInfo object with REAL data
val userInfo = VerifiedUserInfo(
email = claims.getString("email"),
displayName = claims.optString("name", claims.getString("email"))
)The Credential Manager API will return a DigitalCredential
response.
The following is an example of what the raw responseJsonString looks like, and
what the claims look like after parsing the inner SD-JWT where you get
additional metadata as well along with verified email:
/*
// Example of the raw JSON response from credential.credentialJson:
{
"protocol": "openid4vp-v1-unsigned",
"data": {
"vp_token": {
// This key matches the 'id' you set in your dcql_query
"user_info_query": [
// The SD-JWT string (Issuer JWT ~ Disclosures ~ Key Binding JWT)
"eyJhbGciOiJ...~WyI...IiwgImVtYWlsIiwgInVzZXJAZXhhbXBsZS5jb20iXQ~...~eyJhbGciOiJ..."
]
}
}
}
// Example of the parsed and verified claims from the SD-JWT on your server:
{
"cnf": {
"jwk": {..}
},
"exp": 1775688222,
"iat": 1775083422,
"iss": "https://verifiablecredentials-pa.googleapis.com",
"vct": "UserInfoCredential",
"email": "jane.doe.246745@gmail.com",
"email_verified": true,
"given_name": "Jane",
"family_name": "Doe",
"name": "Jane Doe",
"picture": "http://example.com/janedoe/me.jpg",
"hd": ""
}
*/[!IMPORTANT] Important: We highly recommend that after receiving the verified email, you trigger Credential Manager's passkey creation.
Since the retrieved email is cryptographically verified, you can omit the email
OTP verification step, significantly reducing sign-up friction and potentially
increasing conversion. This process is best handled on your server. The client
sends the raw response (containing the vp_token) and the original nonce to a
new server endpoint.
For verification, your application must send the full responseJsonString to
your server for cryptographic validation before creating an account or logging
the user in.
The digital credential provides two critical levels of verification for your server:
iss) URL and the SD-JWT signature proves that a trusted authority issued this data.cnf field and the Key Binding (kb) signature confirms that the credential is being shared by the same device it was originally issued to, preventing it from being intercepted or used on another device.The validation on the server must achieve the following:
iss (issuer) field matches https://verifiablecredentials-pa.googleapis.com.[!NOTE] Note: Use a standard library (such as @sd-jwt/sd-jwt-vc for Node.js) to perform the verification steps as outlined in the OpenID for Verifiable Presentations specification.
For full security, make sure that you also validate the nonce to prevent
replay attacks.
By combining these steps, your server can validate both the authenticity of the data and the identity of the presenter, ensuring the credential wasn't intercepted or spoofed before provisioning the new account.
[!WARNING] Warning: As mentioned in Parse the response on the client, from August 2026, the response JSON format has been updated to match W3C standards. Ensure your client-side parsing and server-side validation handle both formats during the transition period, while the older implementation is phased out. Apps that begin to integrate the email verification flow after August 2026 need to use the new format only.
try {
// Send the raw credential response and the original nonce to your server.
// Your server must validate the response. createAccountWithVerifiedCredentials
// is a custom implementation per each RP for server side verification and account creation.
val serverResponse = createAccountWithVerifiedCredentials(responseJsonString, nonce)
// Server returns the new account info (e.g., email, name)
val claims = JSONObject(serverResponse.json)
val userInfo = VerifiedUserInfo(
email = claims.getString("email"),
displayName = claims.optString("name", claims.getString("email"))
)
// handle response - Up to the developer
} catch (e: Exception) {
// handle exceptions - Up to the developer
}An optional but highly recommended next step after provisioning an account is to immediately create a passkey for that account. This provides a secure, passwordless method for the user to sign in. This flow is identical to a standard passkey registration.
For the flow to work on a WebView, developers should implement a
JavaScript bridge (JS Bridge) to facilitate the handoff. This bridge
allows the WebView object to signal the native app, which can then perform the
actual call to the Credential Manager API.
To maintain the integrity of the email verification flow, the following security requirements are mandatory:
responseJsonString and the original nonce to the app's server for full verification.iss) field, the SD-JWT signature, and the presenter identity using the cnf field.© sreichholf, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (references) in .agents/skills/verified-email of sreichholf/dreamDroid.
Open the folder on GitHubat commit ee2d56f
We found 7 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in sreichholf/dreamDroid, which our catalogue first saw on October 11, 2026.
Verified Email next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verified Email this skillsreichholf/dreamDroid | 116 | 5 repos | ~5.1k | Automated safety check: Pass | GPL-3.0 | |
| Inspect Network TrafficHedvigInsurance/android | 154 | — | ~756 | Automated safety check: Pass | AGPL-3.0 | |
| CometChat Android v5 Headless SDKcometchat/cometchat-skills | 132 | — | ~4k | Automated safety check: Pass | MIT | |
| Android Hidden API and R8 Checkgkd-kit/gkd | 43k | — | ~1.5k | Automated safety check: Pass | GPL-3.0 | |
| Android API Diffgkd-kit/gkd | 43k | — | ~796 | Automated safety check: Pass | GPL-3.0 | |
| Android Readme Screenshot Studiopermissionlesstech/bitchat-android | 7.8k | — | ~3k | Automated safety check: Pass | GPL-3.0 |
HedvigInsurance/android
Read the HTTP and GraphQL calls a debug build of the Android app made, with request and response bodies, status codes, timings and errors, over adb.
cometchat/cometchat-skills
Builds chat on Android with your own UI against the headless CometChat Chat SDK v5, covering install, Jetifier conflicts, credentials and init-before-login ordering.
gkd-kit/gkd
Checks whether Android hidden-API implementations and system callbacks survive R8 minification, and diagnoses Release-only failures such as AbstractMethodError.
gkd-kit/gkd
Looks up Android framework Java and AIDL APIs across versions with the android-api-diff CLI: signatures, availability, source files and hidden-API access code.
permissionlesstech/bitchat-android
Create or refresh polished, high-resolution screenshots of the Bitchat Android app for README and repository showcase use.
monta-app/ocpp-emulator
Compose Multiplatform and Jetpack Compose patterns for KMP projects — state management, navigation, theming, performance, and platform-specific UI.
sreichholf/dreamDroid
A skill your agent uses to integrate the Jetpack Compose Styles API into an Android project.
sreichholf/dreamDroid
Provide technical guidance for Android camera development with CameraX.
sreichholf/dreamDroid
A skill your agent uses to migrate your Jetpack Compose app to add adaptive edge-to-edge support and troubleshoot common issues.
sreichholf/dreamDroid
Analyzes Android codebases to implement ML Kit GenAI Prompt API.
sreichholf/dreamDroid
Prove dreamDroid phone UI. An agent skill from sreichholf/dreamDroid.
sreichholf/dreamDroid
Provides instructions and architectural patterns for migrating Android TV applications from legacy Leanback UI Toolkit, Android Views, or Support Fragments to Jetpack Compose for TV (androidx.tv).
Works with
Categories
Provides a complete workflow for implementing verified email retrieval on Android Credential Manager API. Verified Email is an agent skill from sreichholf/dreamDroid. Provides a complete workflow for implementing verified email retrieval on Android Credential Manager API.
Verified Email fits situations like: integrate a secure; OTP-less email verification flow into an Android app.
Run `npx skills add sreichholf/dreamDroid --skill verified-email -a claude-code`. Or copy the skill folder (.agents/skills/verified-email in sreichholf/dreamDroid) into .claude/skills/verified-email in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sreichholf/dreamDroid --skill verified-email -a codex`. Or copy the skill folder (.agents/skills/verified-email in sreichholf/dreamDroid) into .agents/skills/verified-email in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sreichholf/dreamDroid --skill verified-email -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verified-email, .gemini/skills/verified-email, .github/skills/verified-email and .opencode/skills/verified-email in your project.
SKILL.md names no scripts, command-line tools or credentials: Verified Email is instructions for the agent only.
SKILL.md names 8 domains. In commands or code: verifiablecredentials-pa.googleapis.com; the agent is likely to contact it when it follows the instructions. As links in the text: developer.android.com, openid.net, datatracker.ietf.org, digital-credentials.dev, w3.org, iso.org and developers.google.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verified Email is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.1k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Verified Email: Inspect Network Traffic (HedvigInsurance/android, 154 stars), CometChat Android v5 Headless SDK (cometchat/cometchat-skills, 132 stars), Android Hidden API and R8 Check (gkd-kit/gkd, 43k stars) and Android API Diff (gkd-kit/gkd, 43k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sreichholf (a GitHub user) maintains it in sreichholf/dreamDroid, which has 116 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 11, 2026.
Source: sreichholf/dreamDroid on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.