mobile-tester

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill automatically executes a local shell script scripts/mobile-test-setup.sh to configure the testing environment. It also invokes adb (Android Debug Bridge) commands for device interaction, such as unlocking the screen and checking for connected devices.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting data from external sources (BRD, PRD, and app source code) and using it to drive AI-powered testing actions.
  • Ingestion points: Reads business requirements (BRD), product requirements (PRD), and application source code (Android, React Native, or Flutter structures) to understand testing logic.
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore malicious commands embedded within the documents it processes.
  • Capability inventory: The agent can execute shell scripts, run ADB commands, write files to the local filesystem (tests/e2e/mobile/), and perform network operations via testing frameworks.
  • Sanitization: There is no evidence of sanitization or filtering applied to the content extracted from requirement documents before it is interpolated into aiAction or aiAssert calls.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — mobile-tester