appshots-automation-pipeline

Fail

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Found in SKILL.md. The instruction curl -fsSL "https://get.maestro.mobile.dev" | bash executes code from a remote source directly in the shell. This URL is also flagged as malicious by automated scanners.
  • [EXTERNAL_DOWNLOADS]: Found in SKILL.md. The skill recommends installing a third-party Homebrew tap (brew install cameroncooke/axe/axe), which introduces unverified external dependencies into the development environment.
  • [COMMAND_EXECUTION]: Found in SKILL.md. The skill uses shell commands like xcrun simctl and adb to manipulate mobile simulator environments, modify application preferences, and interact with the local file system.
Recommendations
  • HIGH: Downloads and executes remote code from: https://get.maestro.mobile.dev - DO NOT USE without thorough review
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 23, 2026, 05:23 PM
Security Audit — agent-trust-hub — appshots-automation-pipeline