limrun-maestro-testing
Fail
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to install the Maestro CLI by downloading a script from
https://get.maestro.mobile.devand piping it directly tobash. This is the official installation method for the well-known Maestro testing framework. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the vendor's
limCLI tool vianpm install --global lim. This is a standard installation of a tool provided by the skill's author. - [COMMAND_EXECUTION]: The skill facilitates the execution of various
limandmaestrocommands to manage iOS simulators, install assets, and run UI tests. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied Maestro flow files (YAML) and application identifiers to drive simulator interactions.
- Ingestion points: User-provided
hello-flow.yaml,flow.yaml, and directory paths containing multiple flow files. - Boundary markers: The instructions do not define specific delimiters or security warnings to prevent the interpretation of malicious instructions within the flow files.
- Capability inventory: The skill has the capability to execute shell commands using the
limandmaestroCLIs and interact with remote simulator instances. - Sanitization: The skill does not mention specific validation or sanitization steps for the content of the flow files before they are passed to the Maestro execution engine.
Recommendations
- HIGH: Downloads and executes remote code from: https://get.maestro.mobile.dev - DO NOT USE without thorough review
Audit Metadata