termux-adb
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the 'adb' command-line tool to manage device pairing, connections, and configuration changes. This execution is restricted to the local device and is necessary for the skill's stated purpose of providing shell-level access for Android debugging.
- [PRIVILEGE_ESCALATION]: By establishing an ADB connection, the skill gains access to the 'shell' user, which possesses higher privileges than the default Termux environment. The skill mitigates risks by requiring the user to manually enable Developer Options and enter pairing codes, and by instructing the agent to get explicit confirmation for any system-wide changes.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data via the 'scripts/check-adb.sh' script, which parses output from the 'adb devices' command. While this represents an ingestion point for potentially untrusted data, the script employs 'sed' and 'awk' for text processing, and the available capabilities are focused on local system state checks, resulting in a low risk profile.
Audit Metadata