mobilerun
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curlandjqto interact with the Mobilerun API atapi.mobilerun.ai. These operations are legitimate and necessary for listing devices, taking screenshots, and sending automation commands. - [EXTERNAL_DOWNLOADS]: Fetches PNG screenshots and JSON UI state data from the vendor's API. This content is used by the agent to understand the state of the connected mobile device.
- [SAFE]: Explicit instructions are provided to the agent to never reveal or log the
MOBILERUN_API_KEYin user-facing output. - [SAFE]: Although the skill ingests untrusted UI data from mobile devices (representing a potential indirect prompt injection surface), this is a primary and intended function of the mobile automation skill. The risk is managed by architectural boundaries and agent instructions that prioritize goal-based task execution over raw command interpolation.
Audit Metadata