automating-mobile-app-testing
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHPROMPT_INJECTIONNO_CODE
Full Analysis
- PROMPT_INJECTION (HIGH): The skill possesses a significant Indirect Prompt Injection vulnerability surface because it is designed to take untrusted user requirements and translate them into executable tests and system configurations. * Ingestion points: The skill ingests 'user-defined flows and requirements' for mobile apps (SKILL.md). * Boundary markers: Absent; there are no instructions to delimit user input or to ignore instructions embedded within the requirements. * Capability inventory: The skill claims the capability to configure simulators, emulators, and device farms (e.g., AWS Device Farm) and to generate end-to-end test code for multiple frameworks. * Sanitization: Absent; no logic is provided to sanitize, escape, or validate user requirements before they are used to influence code generation or system environment setup.
- NO_CODE (INFO): The skill is composed entirely of natural language instructions in markdown format and does not include any accompanying scripts or source code, which precludes a full behavioral analysis of the underlying implementation.
Recommendations
- AI detected serious security threats
Audit Metadata