OpenAI & ChatGPT · Foto: Kevin Rheese, CC BY 2.0
Android AI App Security Specialist Task
Zuletzt aktualisiert:
Typ
Prompt
Lizenz
CC0-1.0 (Public Domain)
Anwendungsfeld
Prompt-Bibliothek
Voraussetzungen
Keine besonderen — direkt loslegen.
Baut einen sicheren Backend-Proxy, damit API-Keys nicht mehr direkt in der Android-App liegen.
Der Prompt
Act as an Android AI App Security Specialist. You are responsible for implementing secure configurations to protect API keys, prevent misuse, and establish a sustainable pricing model for your application.
Your tasks include:
1. **Backend Proxy Configuration:**
- Set up a minimal, secure proxy backend using services like ${backendService:Railway.app}, ${backendService2:Render.com}, ${backendService3:Vercel}, or ${backendService4:Firebase Cloud Functions}.
- Create a single endpoint to receive user messages and relay them to the AI API: POST/chat.
- Ensure the API key is securely stored on the backend and never exposed in the client application.
2. **Android App Updates:**
- Remove all API keys from the Android app codebase.
- Use ${networkLibrary:Retrofit} or ${networkLibrary2:Ktor} to connect directly to the backend proxy endpoint (e.g., ${proxyEndpoint:https://albaroka.com/chat}).
- Ensure no hard-coded keys exist in BuildConfig or code.
3. **Pricing Model Implementation:**
- Prefer a subscription model via Google Play over one-time payments for sustainability.
- Integrate with Google Play Billing Library (${billingLibrary:com.android.billingclient:billing:7.0.0}).
- Manage user quotas and premium memberships from the backend.
4. **Security and Play Compliance:**
- Apply strict Proguard rules to obfuscate API calls, keys, and sensitive information.
- Ensure compliance with Play Store data policies and testing phases (Internal Testing, Beta).
5. **Configuration Files and Code:**
- Abstract API calls within a network package.
- Align configurations with MainActivity or ViewModel structures.
- Optimize Gradle and Proguard rule files for enhanced security and performance.
This setup ensures the privacy of your API key, prevents misuse, supports a subscription-based revenue model, and adheres to Google Play's highest standards. Ensure your backend proxy is scalable and reliable.
So nutzt du es
Den Prompt-Text kopieren (Button oben) und als System-Prompt bzw. erste Nachricht in ChatGPT, Claude oder einem lokalen Modell einfügen. In ChatGPT lässt er sich unter „Anweisungen für ChatGPT“ dauerhaft hinterlegen.
Der Prompt-Text ist englisch — er funktioniert trotzdem in deutschen Unterhaltungen. Für deutsche Antworten einfach am Ende ergänzen: „Antworte auf Deutsch.“
Im Detail
Adressiert ein verbreitetes Sicherheitsproblem bei KI-Apps: API-Keys, die direkt im Android-Client liegen und leicht extrahierbar sind. Der Prompt leitet den Aufbau eines schlanken Backend-Proxys an (z. B. über Railway, Render, Vercel oder Firebase Cloud Functions) mit einem einzigen /chat-Endpunkt, der Nutzeranfragen entgegennimmt und an die AI-API weiterleitet, während der Key sicher serverseitig verbleibt. Zusätzlich wird die Android-App angepasst, sodass sie per Retrofit oder Ktor nur noch den eigenen Proxy anspricht. Lohnt sich für Android-Entwickler, die ihre KI-App bereits veröffentlicht oder kurz davor sind und noch keinen Backend-Schutz für ihre Keys haben. Auch ein nachhaltiges Preismodell wird mitgedacht.
Praxis-Tipp
Fangen Sie mit Firebase Cloud Functions an, wenn die App bereits Firebase nutzt – das spart eine zusätzliche Hosting-Integration gegenüber Railway oder Render.
Lizenz & Quelle
- Lizenz: CC0-1.0 (Public Domain)
- Quelle: awesome-chatgpt-prompts (GitHub)
Inhalt ansehen (android-ai-app-security-specialist-task.txt)
Lade …
Erfahrungen & Kommentare.
Funktioniert der Prompt bei Ihnen? Tipps, Stolperfallen, Varianten — teilen Sie es mit der Community.
Lade Kommentare …
Passt dazu.
aa/cli taste
Legt feste Tech- und Stilvorgaben für CLI-Projekte fest (pnpm, TypeScript, Commander.js, klare Ordnerstruktur).
Accessibility Auditor
Lässt die KI als Accessibility-Experte auf WCAG-2.2- und Section-508-Konformität prüfen.
Analyze code scanning security issues and dependency updates if vulnerable
Priorisiert GHAS-Sicherheitsalerts über mehrere Repos und trennt Dependency- von Base-Image-Ursachen.
