android-emulator-automation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
subprocess.runmethod inscripts/common.pyto execute Android Debug Bridge (ADB) commands. It also runs a shell script,run_examples.sh, which invokes the Gradle build tool (gradlew). These actions are core to the skill's purpose for Android automation and are implemented using list-based arguments that mitigate shell injection risks. - [INDIRECT_PROMPT_INJECTION]: The
ScreenMapperclass inscripts/screen_mapper.pydumps and parses UI hierarchy XML from the emulator. This creates a vector where an application could display malicious text to manipulate the agent's logic. - Ingestion points:
scripts/screen_mapper.pyparses XML data retrieved viauiautomator dump. - Boundary markers: No explicit delimiters or boundary instructions are used when passing extracted UI text to the agent.
- Capability inventory: The skill can execute various ADB shell commands, including simulating clicks and text entry via
scripts/navigator.py. - Sanitization: The skill performs basic character escaping for ADB input but does not sanitize the semantic content of extracted UI labels.
Audit Metadata