Back to skill

Security audit

Android Adb

Security checks for vulnerabilities and agentic risk

Overview

This ADB helper is mostly aligned with its purpose, but it needs review because parts of it can turn user-supplied ADB filters into host shell commands.

Review this skill before installing. Use it only if you are comfortable giving an agent broad ADB control over connected Android devices, and fix or avoid the logcat helper and terminal-launch templates until command arguments are safely passed without eval or bash-c interpolation. Prefer an already installed, trusted ADB or add checksum verification before using the bundled installer. Treat logs, screenshots, recordings, and UI dumps as potentially sensitive.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/logcat_capture.sh:51
Finding

Arbitrary Shell Command Injection Through eval-Based Command Construction

Content
View full analysis
/dev/null || echo "") if [ -z "$PID" ]; then echo "Process not running: $PKG"; exit 1; fi CMD="$CMD --pid=$PID" ;; tag) CMD="$CMD -s $TAG" ;; esac if [ -n "$OUTPUT" ]; then eval "$CMD" > "$OUTPUT" LINES=$(wc -l < "$OUTPUT" | tr -d ' ') echo "Captured $LINES lines -> $OUTPUT" else eval "$CMD" fi ``` ### Technical Analysis The script constructs a shell command as a string and executes it through `eval`. The `SERIAL` and `TAG` parameters originate from positional command-line arguments and are inserted into that command string without shell escaping or restrictive validation. Quoting a variable while passing it to `eval` does not make its contents safe. `eval` reparses the expanded string as shell syntax. Consequently, shell metacharacters, command substitutions, redirections, and command separators embedded in `TAG` or `SERIAL` are interpreted by the host shell. The PID lookup also expands the unquoted string variable `$SERIAL_FLAG`, although the primary arbitrary-code-execution sink is the subsequent use of `eval`. ### Attack Path 1. An attacker causes the Skill to invoke the logcat helper with a crafted tag or serial. 2. For example, a tag containing a command substitution can be passed as a literal argument: ```bash bash scripts/logcat_capture.sh tag '$(touch /tmp/adb-injected)' ``` 3. The script appends the value to `CMD`: ```bash CMD="$CMD -s $TAG" ``` 4. `eval "$CMD"` reparses the command substitution as active shell syntax. 5. The injected `touch` command executes on the host, independently of whet ...[truncated 935 chars]
Remediation
View remediation
/dev/null || true) if [ -z "$PID" ]; then echo "Process not running: $PKG" exit 1 fi cmd+=("--pid=$PID") ;; tag) cmd+=(-s "$TAG") ;; esac if [ -n "$OUTPUT" ]; then "${cmd[@]}" > "$OUTPUT" else "${cmd[@]}" fi ``` Additional hardening should include: - Validate device serials against an explicit expected format. - Validate package names using an Android package-name allowlist pattern. - Reject control characters in tags and output paths. - Use `--` where supported to terminate option parsing. - Add regression tests using tags and serials containing spaces, quotes, semicolons, dollar signs, and command substitutions. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:65
Finding

Unsafe Dynamic Command Interpolation in Terminal-Launch Instructions

Content
View full analysis
"' ``` ### Linux (common DEs) ```bash # GNOME gnome-terminal -- bash -c '; exec bash' # KDE konsole -e bash -c '; exec bash' # Fallback x-terminal-emulator -e bash -c '; exec bash' ``` Replace `` with the actual command, e.g.: - `adb logcat` — all logs - `adb logcat | grep -i "redirect" --line-buffered` — filter by keyword - `adb logcat -s MyTag:D` — filter by tag - `adb logcat --pid=$(adb shell pidof com.example.app)` — filter by app ### zsh compatibility zsh treats `*` as a glob wildcard. When the command contains `*` (e.g. `Tag:*`), **escape it** in the osascript string: ```bash # Wrong — zsh expands * osascript -e 'tell app "Terminal" to do script "adb logcat -s MyTag:*"' # Correct — escape the * osascript -e 'tell app "Terminal" to do script "adb logcat -s MyTag:\\*"' ``` ``` ### Technical Analysis The Skill instructs the Agent to replace `` with a dynamically generated command inside nested shell or AppleScript strings. On Linux, the resulting text is explicitly parsed by `bash -c`. On macOS, the command crosses both AppleScript string parsing and the command shell used by Terminal. The instructions only discuss e ...[truncated 1952 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install_adb.sh:10
Finding

Unpinned Platform-Tools Download Is Executed Without Integrity Verification

Content
View full analysis
/dev/null || true echo "" echo "ADB installed to: $TOOLS_DIR/platform-tools/adb" "$TOOLS_DIR/platform-tools/adb" version ``` ### Technical Analysis The installer downloads a mutable `platform-tools-latest` archive, extracts it, marks binaries executable, and immediately executes the downloaded `adb` binary. It does not pin a specific platform-tools release or verify a cryptographic checksum or signature. HTTPS provides transport protection under normal conditions, and the URL belongs to Google's documented download domain. However, transport security alone does not provide build pinning or an independently verified artifact identity. A compromised upstream artifact, certificate trust path, redirect destination, or distribution infrastructure could replace the binary that the Skill executes. The use of `curl -L` permits redirects, while the command does not explicitly fail on HTTP error responses. The archive is also extracted without a prior archive-entry safety check. ### Attack Path 1. A user approves installation of ADB into the Sk ...[truncated 1281 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is described as an ADB operations helper, but it also installs software locally by invoking an installer script and downloading platform-tools. That expands behavior from device interaction into host-side software acquisition and filesystem modification, which creates additional supply-chain and host-integrity risk not clearly captured by the declared purpose.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
90% confidence
Finding

The skill instructs the agent to always open a new system terminal window for long output and interpolate an <adb_logcat_command> into shell-launch commands such as osascript, gnome-terminal, or bash -c. If any part of that command is derived from user-controlled values like package names, tags, grep patterns, or file paths without strict escaping, this creates a command-injection path on the host.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

bash <skill_dir>/scripts/logcat_capture.sh tag [output_file] [serial]

text

## Long Output Rule

When the user requests any long-running or verbose log output (logcat streaming, dropbox dump, dumpsys, large trace output, etc.), **unless the user explicitly specifies an output file**, always **open a new system terminal window** to display the output. This gives the user a scrollable, stoppable, dedicated view without blocking the conversation.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

bash
adb shell uiautomator dump /sdcard/ui_dump.xml
adb pull /sdcard/ui_dump.xml <local_path>
adb shell rm /sdcard/ui_dump.xml
  1. dumpsys activity top (fallback — some devices like Huawei may report could not get idle state):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/adb-commands.md (reported line 177)May include surrounding context.

bash
adb shell uiautomator dump /sdcard/ui_dump.xml
adb pull /sdcard/ui_dump.xml <local_path>
adb shell rm /sdcard/ui_dump.xml
  1. dumpsys activity top (fallback — some devices like Huawei may report could not get idle state):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

adb shell screenrecord --time-limit 30 /sdcard/recording.mp4 # limit to 30s

Ctrl+C to stop, then pull:

adb pull /sdcard/recording.mp4 <local_path> adb shell rm /sdcard/recording.mp4

text

### "Which app is in the foreground?"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/adb-commands.md (reported line 158)May include surrounding context.

md
# Screenshot
adb shell screencap /sdcard/screenshot.png
adb pull /sdcard/screenshot.png .
adb shell rm /sdcard/screenshot.png

# Screen recording (max 180s)
adb shell screenrecord /sdcard/video.mp4

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/adb-commands.md (reported line 168)May include surrounding context.

Pull recording

adb pull /sdcard/video.mp4 . adb shell rm /sdcard/video.mp4

text

## UI Hierarchy

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs the agent to execute shell commands (adb, bash, terminal launchers) but does not declare an explicit tool scope such as allowed shell tools or permissions. This weakens policy enforcement and reviewability because the runtime capabilities exceed what is formally declared, increasing the chance of unintended or overly broad command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger text is broad enough to activate on general Android command-line or debugging requests, not just clearly intended ADB operations. Over-triggering can route unrelated requests into a powerful shell-capable skill, increasing the likelihood of accidental command execution in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section documents commands that can extract potentially sensitive information from a connected Android device, including logs, crash data, package/activity state, and device properties, without any warning about privacy, consent, or safe handling. In an agent skill context, that omission increases the chance the agent will collect or export personal, credential-bearing, or app-sensitive data from a real user device without appropriate confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Screenshot, screen recording, and UI hierarchy dump commands can capture highly sensitive on-screen content such as messages, authentication prompts, PII, and internal app structure, yet the reference presents them as routine steps with no privacy warning. Because this is an ADB skill meant to drive real devices, the missing caution materially increases the risk of over-collection and unintended disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The script downloads and executes trust-sensitive tooling from the network without any integrity verification such as a pinned checksum or signature check. Although the URL points to Google's official platform-tools distribution over HTTPS, a compromised upstream, misissued certificate, hostile proxy, or local TLS interception could result in a malicious archive being installed and later used by the skill.

Content

Scanner excerpt · scripts/install_adb.sh (reported line 28)May include surrounding context.

sh
ZIP="$TOOLS_DIR/platform-tools.zip"

echo "Downloading Android platform-tools..."
curl -# -L -o "$ZIP" "$URL"

echo "Extracting..."
unzip -qo "$ZIP" -d "$TOOLS_DIR"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script redirects captured logcat output into a user-specified file and only reports the line count afterward. While the file write is visible in code, there is no user-facing warning that Android logs may include sensitive application, device, or crash information before saving them to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installation prompt is specified only in Chinese: 'ADB 未安装,是否需要我帮你安装到 skill 本地目录?(不影响系统配置)'. This imposes a language choice on the user without indicating locale detection, fallback, or user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.