mobile-automation
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from mobile application interfaces which could contain adversarial instructions targeting the agent's logic.
- Ingestion points:
mobile_list_elements_on_screenandmobile_take_screenshotinSKILL.mdingest UI text and visual data from external apps. - Boundary markers: Absent. The instructions do not specify delimiters or warnings to ignore embedded content within the mobile UI.
- Capability inventory: High-impact capabilities include
mobile_click_on_screen_at_coordinates,mobile_type_keys,mobile_open_url, andmobile_login_to_cloud_providerinSKILL.md. - Sanitization: Absent. There is no evidence of sanitization or filtering of screen content before the agent interprets it.
- [COMMAND_EXECUTION]: The skill metadata specifies a requirement for
npx, indicating it relies on shell-level command execution to manage its operational environment. - [EXTERNAL_DOWNLOADS]: The skill instructions reference documentation hosted at
mobilenext.ai, which is the official domain for the skill's author,mobile-next.
Audit Metadata