dogfood
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
agent-deviceandnpx agent-devicecommands to interact with mobile devices, manage testing sessions, and capture system logs. This is the primary mechanism for its stated purpose of exploratory testing. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by capturing UI snapshots and reading application logs from external mobile apps under test. This data could potentially contain malicious instructions intended to manipulate the agent's behavior.
- Ingestion points:
agent-device snapshotcaptures UI hierarchies;agent-device logs pathprovides access to application logs. - Boundary markers: None identified; the skill processes the UI and log content directly to identify bugs.
- Capability inventory: File system operations (
mkdir,cp), device interaction (open,fill,press), and session management. - Sanitization: None identified; the agent is expected to interpret the observed behavior to find issues.
Audit Metadata