android-device-automation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx -y @midscene/android@1 to download and execute the Midscene automation package from the NPM registry at runtime.
  • [COMMAND_EXECUTION]: Provides a mechanism to execute arbitrary shell commands on connected Android devices via adb shell through the runadbshell command functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on natural language prompts and visual data from device screenshots to guide its automation logic, which presents a surface for processing instructions embedded within the data.
  • Ingestion points: Untrusted data enters the agent context through user-provided prompts via the --prompt flag and visual information captured from the Android device screen.
  • Boundary markers: No explicit delimiters or boundary markers are defined in the instructions to separate user intent from potentially malicious content on the device screen.
  • Capability inventory: The skill has the capability to perform UI interactions (taps, swipes, text input), execute shell commands on the device, and write report files to the local file system.
  • Sanitization: There is no evidence of prompt sanitization or visual data filtering before the information is processed by the underlying AI model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:33 AM
Security Audit — agent-trust-hub — android-device-automation