Back to skill

Security audit

ClawPhone Phone Control

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent phone-control skill that guides cautious screen reading and user-directed UI actions, with clipboard privacy caveats users should understand.

Install only if you intend to let the agent inspect and operate your phone UI. Avoid using it for passwords, one-time codes, or sensitive messages unless you are comfortable with clipboard-based input and visible-screen processing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs a clipboard-based fallback for text entry (set_clipboard(...) then paste) but does not warn that user-provided content will be copied into the system clipboard, where it may persist or be visible to other apps and processes. In a phone-control skill, this is more sensitive because the workflow may handle private messages, credentials, or other user data during automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly documents type_text as using the clipboard automatically, but provides no warning that user clipboard contents may be overwritten or exposed during automation. In a phone-control skill, clipboard use can affect sensitive data such as copied passwords, OTPs, or private text, making the omission a real privacy and integrity risk rather than a purely informational issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill exposes a direct set_clipboard capability without warning that it can overwrite the user's clipboard contents or place sensitive data into a globally accessible OS buffer. Given this skill is designed for active phone control, the context increases risk because clipboard manipulation may interfere with user workflows and leak or replace private content across apps.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language instructions and description force a specific language/locale without indicating that users may choose another language. Under the policy, fixed language behavior without opt-in can be a locale-policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.