dogfood

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx agent-device:* to download and execute the testing utility from the npm registry.
  • [COMMAND_EXECUTION]: Executes shell commands for environment setup (mkdir, cp) and various CLI operations via agent-device to interact with mobile apps, including launching apps, taking snapshots, and recording videos.
  • [CREDENTIALS_UNSAFE]: The authentication workflow passes user-provided {EMAIL} and {PASSWORD} as plaintext arguments to the agent-device fill command, which can expose secrets in process lists or shell history logs.
  • [DATA_EXFILTRATION]: Reads mobile application logs via agent-device logs path to assist in bug diagnosis. All captured data is stored in the local output directory specified by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 05:31 AM