deveco-studio-verify

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell, batch, and PowerShell scripts to interact with the HarmonyOS device bridge (hdc) and emulator management tools. These operations include starting/stopping processes, installing application packages (HAP files), and executing UI automation commands (uitest) to facilitate application testing.
  • [DATA_EXPOSURE]: The skill facilitates the collection of system and application logs, as well as UI hierarchy trees and screenshots, for debugging and verification purposes. These operations are standard for development environments and are performed through local file system operations without unauthorized network exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests untrusted data from device logs and UI trees (e.g., via hdc shell hilog). However, its capabilities are confined to developer-triggered testing workflows, and it lacks the autonomous network-outbound functionality required for exfiltration, rendering the risk negligible in its intended context.
  • [SAFE]: Static and manual analysis of all 18 files, including scripts (hdc.sh, hdc.ps1, create_and_start_emulator.bat) and documentation, confirms no presence of obfuscation, hardcoded credentials, malicious remote code execution patterns, or prompt injection attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:16 AM
Security Audit — agent-trust-hub — deveco-studio-verify