appllama-usage
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from the Appllama mobile app library, which includes screen metadata and flow definitions.
- Ingestion points: Data is retrieved from the Appllama MCP using tools such as
search_apps,list_app_screens, andsearch_screens. - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to separate user-provided or external tool data from its primary logic.
- Capability inventory: The agent is directed to generate app code and perform local testing using an iOS Simulator or Android Emulator.
- Sanitization: There are no explicit requirements for the agent to sanitize or validate the external content before processing it.
- [DYNAMIC_EXECUTION]: The skill describes an iterative development cycle where the agent generates code for app screens and executes them in a local simulator or emulator to verify design and motion fidelity.
- [COMMAND_EXECUTION]: The playbooks mention the potential use of external command-line tools for image generation, such as the Higgsfield CLI, to support the building process.
Audit Metadata