agent-device

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a reference and router for device automation workflows across multiple platforms (iOS, Android, macOS).
  • [COMMAND_EXECUTION]: Provides guidance for executing local commands like agent-device, xcrun, adb, and curl for automation setup, debugging, and verification workflows, which aligns entirely with its primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines exploration rules that emphasize safety and anti-hallucination, such as starting with read-only snapshots, avoiding speculative mutations, and explicitly reporting when UI elements are missing rather than attempting to guess or execute unrequested web lookups/actions.
  • [EXTERNAL_DOWNLOADS]: Refers to configuring remote hosts and communication protocols via AGENT_DEVICE_DAEMON_BASE_URL and JSON-RPC APIs to manage device sessions remotely, treating tokens and credentials appropriately as host secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:05 AM
Security Audit — agent-trust-hub — agent-device