agent-device-mobile-automation

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructions for using agent-device, a utility for mobile app automation and testing.
  • [COMMAND_EXECUTION]: The skill uses shell commands to interact with the agent-device CLI tool to control devices and simulators, which is standard for automation tasks.
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading the agent-device package from the NPM registry during setup.
  • [DATA_EXFILTRATION]: The skill includes commands to capture screenshots, videos, and network logs, which are stored in a local ./artifacts/ directory for testing verification.
  • [PROMPT_INJECTION]: The skill allows the agent to process mobile app UI snapshots. 1. Ingestion points: UI accessibility snapshots processed via the agent-device snapshot command in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Execution of agent-device CLI commands for taps, typing, and navigation in SKILL.md. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 03:09 AM
Security Audit — agent-trust-hub — agent-device-mobile-automation