appshots-automation-pipeline
Fail
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Found in
SKILL.md. The instructioncurl -fsSL "https://get.maestro.mobile.dev" | bashexecutes code from a remote source directly in the shell. This URL is also flagged as malicious by automated scanners. - [EXTERNAL_DOWNLOADS]: Found in
SKILL.md. The skill recommends installing a third-party Homebrew tap (brew install cameroncooke/axe/axe), which introduces unverified external dependencies into the development environment. - [COMMAND_EXECUTION]: Found in
SKILL.md. The skill uses shell commands likexcrun simctlandadbto manipulate mobile simulator environments, modify application preferences, and interact with the local file system.
Recommendations
- HIGH: Downloads and executes remote code from: https://get.maestro.mobile.dev - DO NOT USE without thorough review
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata