Back to skill

Security audit

Ghost in the Droid

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes a mobile-device automation MCP server, including sensitive screen, clipboard, app install, and app-data actions, but those capabilities match its stated purpose.

Install only if you intend to let an agent operate the selected mobile device. Before use, connect only test devices or emulators when possible, avoid sensitive screens and clipboard contents, and require explicit confirmation before installs, app-data clearing, login flows, or replayed/batched actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill enables powerful interaction with real Android and iOS devices, including screenshots, clipboard access, app launch/closure, APK installation, app data clearing, and replayed interaction flows, but it does not prominently warn users about the privacy and integrity risks of those actions. In practice, an agent using this skill could access sensitive device content or modify device state in ways the user may not anticipate, increasing the chance of accidental data exposure or destructive actions.

Static analysis

No suspicious patterns detected.