Back to skill

Security audit

Adb Claw

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Android-control skill, but it automatically installs an unpinned executable and exposes broad phone-control powers that merit careful review.

Install only if you are comfortable trusting the adb-claw GitHub release binary or can verify/build it yourself. Use it only with devices you control, disable USB debugging when finished, and require explicit approval before audio capture, file transfer, app deletion/data clearing, or raw shell commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:15
Finding

Automatic Retrieval and Execution of Mutable, Unverified Binaries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–46; automatic execution behavior is documented at lines 93 and 136
Vulnerability Type: Remote payload retrieval and execution without enforced integrity verification
Risk Level: Medium

Vulnerable Code

yaml
"install":
  [
    {
      "id": "adb-claw-darwin-arm64",
      "kind": "download",
      "url": "https://github.com/llm-net/adb-claw/releases/latest/download/adb-claw-darwin-arm64",
      "bins": ["adb-claw"],
      "os": "darwin",
      "label": "Download adb-claw (macOS Apple Silicon)",
    },
    {
      "id": "adb-claw-darwin-amd64",
      "kind": "download",
      "url": "https://github.com/llm-net/adb-claw/releases/latest/download/adb-claw-darwin-amd64",
      "bins": ["adb-claw"],
      "os": "darwin",
      "label": "Download adb-claw (macOS Intel)",
    },
    {
      "id": "adb-claw-linux-amd64",
      "kind": "download",
      "url": "https://github.com/llm-net/adb-claw/releases/latest/download/adb-claw-linux-amd64",
      "bins": ["adb-claw"],
      "os": "linux",
      "label": "Download adb-claw (Linux x86_64)",
    },
    {
      "id": "adb-claw-linux-arm64",
      "kind": "download",
      "url": "https://github.com/llm-net/adb-claw/releases/latest/download/adb-claw-linux-arm64",
      "bins": ["adb-claw"],
      "os": "linux",
      "label": "Download adb-claw (Linux ARM64)",
    },

Related automatic retrieval and execution statements:

markdown
The plugin auto-downloads the adb-claw binary on first session.
markdown
The binary is installed automatically via the SessionStart hook.

Technical Analysis

The installation configuration retrieves platform-specific executable files through mutable GitHub releases/latest URLs. The downloaded artifact is therefore not cryptographically bound to the skill version that was audited. A future release can change the effective executable payload without requiring any modification to this package.

T ...[truncated 2259 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace every releases/latest URL with an immutable, version-specific release URL that matches the declared skill version.
  2. Store an expected SHA-256 digest for each operating-system and architecture combination in the audited installation metadata.
  3. Verify the downloaded binary against that digest before installation or execution, and fail closed on any mismatch.
  4. Prefer a cryptographically signed release manifest and verify its signature against a public key pinned in the skill package.
  5. Bind the skill version, executable version, source commit, checksums, and signatures together in the release process.
  6. Avoid automatically executing a newly downloaded binary during SessionStart until integrity and authenticity checks succeed.
  7. Prefer reproducible builds from a pinned source commit so users can independently compare locally built artifacts with published binaries.
  8. Protect the upstream release workflow with least-privilege tokens, mandatory review, protected tags, hardware-backed multifactor authentication, and artifact attestations.
  9. Document the verified binary version and digest in logs so users can audit which payload was executed.
  10. Treat the connected Android device as sensitive: restrict ADB authorization to trusted hosts and disable USB debugging when it is not required.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list is very broad and includes generic Android-related requests such as screenshots, app management, shell commands, and mobile UI testing. In an agentic environment, this can cause the skill to auto-activate for ordinary Android discussions or loosely related requests, unexpectedly granting a high-risk device-control capability that can read screens, capture audio, transfer files, and run shell commands.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

brew install android-platform-tools

Linux (Debian/Ubuntu)

sudo apt install android-tools-adb

text

### Connect device

Static analysis

No suspicious patterns detected.