Security audit
Acodepowerfultextcodeeditorforandroid
Security checks for vulnerabilities and agentic risk
Overview
The bundled code is mostly a disclosed self-improvement memory skill, but its registry identity is inconsistent and it can persistently change agent memory/instruction context.
Proceed only if you intended to install a self-improvement/memory skill, not an Android code editor. Before enabling hooks or using promotion workflows, require the agent to ask before writing persistent instruction files or sharing session context, and keep secrets and raw transcripts out of learning logs.
Static analysis
No suspicious patterns detected.
