Android Node

PassAudited by VirusTotal on May 14, 2026.

Findings (1)

The skill utilizes a high-risk 'curl | bash' pattern in SKILL.md to execute a remote setup script from an external domain (albionwakes.com). While the provided setup.sh and phone_nodes.py logic align with the stated purpose of provisioning Android phones as Ollama nodes, the script automatically installs openssh and binds the inference service to all network interfaces (0.0.0.0) without authentication, creating a significant security vulnerability on the mobile device.