Back to skill

Security audit

Android Stack Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Android debugging helper that uses ADB to read device UI and activity state, with privacy caveats users should understand.

Install only if you intend to use ADB against Android devices you own or are authorized to inspect. Treat dumpsys, recents, process, getprop, and logcat output as potentially sensitive, and prefer package-scoped commands or redaction before sharing results.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · INSTALL.md (reported line 70)May include surrounding context.

Windows

  1. 下载Android SDK Platform Tools
  2. 解压到 C:\AndroidSDK\platform-tools
  3. 添加到系统PATH:
    • 右键"此电脑" → "属性" → "高级系统设置" → "环境变量"
    • 在"系统变量"中找到Path,添加 C:\AndroidSDK\platform-tools

macOS/Linux

  1. 下载Android SDK Platform Tools
  2. 解压到 ~/AndroidSDK/platform-tools
  3. 添加到PATH:
bash
echo 'export PATH=$PATH:~/AndroidSDK/platform-tools' >> ~/.bashrc
source ~/.bashrc

4. 验证ADB安装

打开终端/命令提示符,运行:

bash
adb version

应该显示ADB版本信息。

5. 连接Android设备

  1. 开启手机的开发者选项和USB调试
  2. 使用USB连接手机到电脑
  3. 在手机上授权电脑连接
  4. 验证连接:
bash
adb devices

使用方法

基本使用

  1. 重启LobsterAI
  2. 在对话中提及以下关键词激活技能:
    • "安卓页面栈分析"
    • "查看页面栈"
    • "adb命令"
    • "当前页面"

使用�

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases include very generic terms such as "adb命令" and "当前页面", which can unintentionally trigger the skill during ordinary conversation about Android debugging or page state. In an agentic environment, overly broad triggers can cause the wrong skill to activate and execute unintended actions or provide misleading operational guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description and examples are entirely written in Chinese and the activation examples are Chinese-specific, with no indication that other languages are supported or that Chinese is a justified regional requirement. This can constitute a language policy issue when a skill effectively requires a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says the skill activates when users mention broad phrases like "adb 命令" or generic Android page-stack requests. This ambiguous trigger scope can cause unintended activation in unrelated conversations, increasing the chance the agent executes device-oriented commands or exposes connected-device context when the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to run ADB dumpsys commands that reveal current focus, activity history, recent tasks, processes, and continuous page-switch monitoring, but it does not warn that this can expose sensitive on-device usage data from apps. In a debugging-oriented context this is not inherently malicious, but omission of a privacy warning increases the risk of collecting or sharing sensitive app/activity information without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script includes user-facing natural-language strings exclusively in Chinese, such as status and error messages, with no opt-in or fallback language. That can violate language/locale policy when a skill is expected to be generally usable but forces a specific language on users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple comments and all user-facing messages are written in Chinese, which imposes a specific language on users without opt-in. Under the stated policy, locale-specific behavior should either offer a choice or clearly document and justify the restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This shell script retrieves the current foreground window, activity stack, and recent tasks from a connected Android device using adb dumpsys commands. Although the script prints what it is doing, it does not warn the user that these outputs may expose sensitive app usage, screen context, or task-history information from the device.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script’s comments and all user-visible prompts are in Chinese, including startup text, error messages, and instructions. This imposes a specific language on users without opt-in or any indication that the skill is intentionally limited to a Chinese-speaking audience, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This file presents all installation and usage instructions in Chinese, which imposes a specific language on users without any visible opt-in or alternative language path. Under the stated policy, forcing a language or locale without user choice can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructions, headings, and operational guidance are presented in Chinese throughout the file, which effectively forces a specific language for users. There is no note offering alternative languages or explaining that the skill is intended only for a Chinese-speaking audience or region-specific use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The script executes an ADB shell loop on the connected device to inspect current window focus state, which accesses live device state. Although the script prints that monitoring is starting, it does not explicitly disclose that it will query data from the attached device via remote shell commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell script presents its title, status, and error messages in Chinese, which imposes a specific language on users. The file does not offer an opt-in or alternative locale, and nothing in the script indicates that the tool is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and echoed status messages are consistently written in Chinese, with no option for users to choose another language. This can violate language/locale policy when a skill forces a specific language without documented justification or user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.