Back to skill

Security audit

Duoplus Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill openly provides Android cloud-phone control through ADB, and the inspected files do not show hidden persistence, exfiltration, or unrelated behavior.

Install only if you intend to let the agent control an Android cloud phone you own or are authorized to operate. Avoid using it on screens containing passwords, one-time codes, private messages, financial data, or account settings unless necessary, because screenshots and UI dumps may capture that content and tap/type actions can change device state.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README advertises direct device-control actions such as connecting to a device, opening apps, and clicking UI elements without warning that these commands will actively manipulate a connected Android device. In a skill explicitly designed for remote cloud-phone control, this omission increases the risk of unintended or unauthorized actions against real devices, especially if users treat example prompts as harmless demonstrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README highlights screenshot capture capability without any privacy or sensitive-data warning. Because screenshots can expose credentials, personal messages, tokens, or other on-screen secrets from a connected cloud phone, failing to warn users materially increases privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill clearly enables execution of host-side commands and device control through ADB, yet it declares no explicit tool scope or permission boundaries. In an agent environment, missing scope declarations can cause overbroad access assumptions and make it easier for the skill to be invoked with powerful capabilities that users and reviewers were not clearly warned about.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs the operator to dump UI hierarchies and pull screenshots from the device, which can expose sensitive on-screen data such as messages, account identifiers, one-time codes, and personal content. Because no privacy warning, consent requirement, or data-handling guidance is provided, the skill normalizes collection of potentially sensitive device data without safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents arbitrary tap, typing, navigation, and task-ending commands that can directly manipulate a live Android session. Without warnings or guardrails, these actions could trigger destructive or security-relevant behavior such as sending messages, changing settings, approving prompts, deleting content, or interacting with sensitive apps unintentionally or maliciously.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The installation instructions include a Chinese comment while the rest of the README is in English, without telling users that multilingual content is expected or offering a language choice. This can conflict with language/locale consistency expectations because the file implicitly switches language without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.