android-emulator-automation

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the subprocess.run method in scripts/common.py to execute Android Debug Bridge (ADB) commands. It also runs a shell script, run_examples.sh, which invokes the Gradle build tool (gradlew). These actions are core to the skill's purpose for Android automation and are implemented using list-based arguments that mitigate shell injection risks.
  • [INDIRECT_PROMPT_INJECTION]: The ScreenMapper class in scripts/screen_mapper.py dumps and parses UI hierarchy XML from the emulator. This creates a vector where an application could display malicious text to manipulate the agent's logic.
  • Ingestion points: scripts/screen_mapper.py parses XML data retrieved via uiautomator dump.
  • Boundary markers: No explicit delimiters or boundary instructions are used when passing extracted UI text to the agent.
  • Capability inventory: The skill can execute various ADB shell commands, including simulating clicks and text entry via scripts/navigator.py.
  • Sanitization: The skill performs basic character escaping for ADB input but does not sanitize the semantic content of extracted UI labels.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:30 PM
Security Audit — agent-trust-hub — android-emulator-automation