mobile-testing

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains instructions for the agent to automatically execute a shell command (ls) when first activated. The command targets several directories, including hidden ones in the user's home folder (e.g., ~/.claude/skills/), to check for the presence of recommended companion skills. While the command itself is informational, automated execution initiated by skill instructions represents an additional risk surface.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its handling of untrusted user data. Ingestion points: User-provided prompts and code snippets related to mobile testing workflows. Boundary markers: The instructions lack explicit delimiters for external content. Capability inventory: The skill has the capability to execute shell commands and generate code/configuration files. Sanitization: No validation or sanitization is specified for processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — mobile-testing