android-ui-journey-testing
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied XML files to determine the sequence of actions and assertions to perform on a device.
- Ingestion points: Step 1 describes parsing XML structures (e.g.,
<journey>,<actions>,<action>) to drive the agent's behavior. - Boundary markers: Absent. The instructions do not include clear delimiters or directives for the agent to ignore natural language instructions that might be embedded within the XML tags.
- Capability inventory: The skill has the capability to execute
adb shellcommands, which can be used to interact with the OS, type text, and manipulate the UI. - Sanitization: Absent. The skill does not describe any validation or sanitization of the XML content beyond basic parsing.
- [COMMAND_EXECUTION]: The skill explicitly instructs the agent to use
adb shell inputcommands for UI interaction. - Evidence: The workflow includes
adb shell input tap,adb shell input swipe, andadb shell input text. While these are functional requirements for the skill's stated purpose, they represent a direct command execution interface on the connected Android device.
Audit Metadata