Android Police has an article on Android Marshmallow, and how the UI now can show you the security patch level.
Unrelated to the above Marshmallow news, but there is also this security tool for Android:
https://firmwaresecurity.com/2015/09/15/android-vulnerability-test-suite/
And if you have an Intel-based Android device, you may also be able to boot a Linux live-boot distros, like LUV-live, and run CHIPSEC, for Intel-specific firmware security tests. (I don’t have an Intel Android-IA-based device to verify if this works, speak up if you can confirm it does or does not work.)