dogfood

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the agent-device and npx agent-device commands to interact with mobile devices, manage testing sessions, and capture system logs. This is the primary mechanism for its stated purpose of exploratory testing.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by capturing UI snapshots and reading application logs from external mobile apps under test. This data could potentially contain malicious instructions intended to manipulate the agent's behavior.
  • Ingestion points: agent-device snapshot captures UI hierarchies; agent-device logs path provides access to application logs.
  • Boundary markers: None identified; the skill processes the UI and log content directly to identify bugs.
  • Capability inventory: File system operations (mkdir, cp), device interaction (open, fill, press), and session management.
  • Sanitization: None identified; the agent is expected to interpret the observed behavior to find issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:06 AM
Security Audit — agent-trust-hub — dogfood