android-device-automation
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npx -y @midscene/android@1to download and execute the Midscene automation package from the NPM registry at runtime. - [COMMAND_EXECUTION]: Provides a mechanism to execute arbitrary shell commands on connected Android devices via
adb shellthrough therunadbshellcommand functionality. - [INDIRECT_PROMPT_INJECTION]: The skill relies on natural language prompts and visual data from device screenshots to guide its automation logic, which presents a surface for processing instructions embedded within the data.
- Ingestion points: Untrusted data enters the agent context through user-provided prompts via the
--promptflag and visual information captured from the Android device screen. - Boundary markers: No explicit delimiters or boundary markers are defined in the instructions to separate user intent from potentially malicious content on the device screen.
- Capability inventory: The skill has the capability to perform UI interactions (taps, swipes, text input), execute shell commands on the device, and write report files to the local file system.
- Sanitization: There is no evidence of prompt sanitization or visual data filtering before the information is processed by the underlying AI model.
Audit Metadata