skills/droidrun/skills/mobilerun/Gen Agent Trust Hub

mobilerun

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl and jq to interact with the Mobilerun API at api.mobilerun.ai. These operations are legitimate and necessary for listing devices, taking screenshots, and sending automation commands.
  • [EXTERNAL_DOWNLOADS]: Fetches PNG screenshots and JSON UI state data from the vendor's API. This content is used by the agent to understand the state of the connected mobile device.
  • [SAFE]: Explicit instructions are provided to the agent to never reveal or log the MOBILERUN_API_KEY in user-facing output.
  • [SAFE]: Although the skill ingests untrusted UI data from mobile devices (representing a potential indirect prompt injection surface), this is a primary and intended function of the mobile automation skill. The risk is managed by architectural boundaries and agent instructions that prioritize goal-based task execution over raw command interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 12:25 PM
Security Audit — agent-trust-hub — mobilerun