appium-mobile-testing

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to analyze "real Appium projects" and "application builds" provided by the user to plan automation. This ingestion of untrusted external content represents a surface for indirect prompt injection, where malicious instructions could be embedded in code comments, configuration files (e.g., pom.xml, package.json), or project metadata.
  • Ingestion points: External Appium project files, application builds, and device provider documentation mentioned in SKILL.md.
  • Boundary markers: The skill contains instructions to verify environment details and warns against inferring execution context from provided materials, though it lacks explicit delimiters for user content.
  • Capability inventory: The skill is scoped to planning, script suggestions, and code review; it does not request tools for arbitrary command execution or external network writing.
  • Sanitization: The instructions do not define specific sanitization or filtering logic for the data ingested from user projects.
  • [EXTERNAL_DOWNLOADS]: The reference file references/source-1.md includes a metadata field info pointing to vip.hctestedu.com. This is an external domain associated with a well-known software testing educational service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:04 PM
Security Audit — agent-trust-hub — appium-mobile-testing