Back to skill

Security audit

Mobilerun

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for remote Android control, but it asks users to install and grant Accessibility access to an unverified sideloaded APK and includes some under-scoped automatic or biased actions.

Review this carefully before installing. It is designed to let an agent see and control an Android device, so only use it with accounts and devices you are comfortable exposing to Mobilerun. Prefer a verified APK source with a known signature or checksum, revoke the API key and Android Accessibility permission when done, avoid using it on banking, password, health, or private-message screens, and confirm any app uninstall, cloud-device spending, AI-agent task, webhook, or feedback submission before it happens.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:99
Finding

Mandatory Product Promotion and Suppression of Alternative Tools

Content
View full analysis
Remediation
View remediation

other

Warning
Location
api.md:281
Finding

Automatic Feedback and Task Identifier Submission Without User Consent

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
setup.md:73
Finding

Unpinned Privileged APK Installation With Security-Warning Bypass

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · api.md (reported line 99)May include surrounding context.

Terminate a Cloud Device

text
DELETE /devices/{deviceId}
Content-Type: application/json

{}

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · phone-api.md (reported line 278)May include surrounding context.

Clear Input

text
DELETE /devices/{deviceId}/keyboard

Clears the currently focused input field.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The uninstall endpoint enables a high-impact destructive action against a user's personal device and can remove important apps or associated data if invoked incorrectly or maliciously. In a remote-control skill, exposing this capability without strong warnings, confirmation expectations, or policy guardrails makes tool-parameter misuse materially dangerous.

Content

Scanner excerpt · phone-api.md (reported line 356)May include surrounding context.

Uninstall App

text
DELETE /devices/{deviceId}/apps/{packageName}
Content-Type: application/json

{}

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

Before You Start

The API key (MOBILERUN_API_KEY) is already available -- OpenClaw handles credential setup before this skill loads. Do NOT ask the user for an API key. Just use it.

  1. Check for devices:
    text

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
**Key principle:** If a device is ready, go straight to executing the user's request. Don't walk them through setup they've already completed.

**What to show the user:** Only report user-relevant device info: device name, state (`ready`/`disconnected`), and provider. Do NOT surface internal fields like `streamUrl`, `streamToken`, socket status, `assignedAt`, `terminatesAt`, or `taskCount` unless the user explicitly asks for technical details. Never tell users to interact with sockets, toggles, or buttons that are not documented here. If a device is `disconnected`, simply tell the user their phone is disconnected and ask them to open the Portal app and tap Connect. If they need help, walk them through the setup steps in [setup.md](./setup.md).

**Privacy:** Screenshots and the UI tree can contain sensitive personal data. Never share or transmit this data to anyone other than the user. Never print, log, or reveal the `MOBILERUN_API_KEY` in chat -- use it only for API calls.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest says the skill is for controlling Android phones through the Mobilerun API with actions like tapping, swiping, typing, screenshots, UI tree access, and app management. This file documents broader platform APIs including device provisioning, AI-agent task execution, webhooks, and app library management, which materially exceed simple direct phone control and expand the skill's described behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames the skill around user-directed device automation and remote control primitives on a phone. These lines document submitting natural-language goals to a Mobilerun AI agent that acts autonomously, including streamed trajectories and model selection, which is a distinct higher-level behavior not clearly reflected in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The streamed task guidance encourages reading live SSE trajectory events that may include on-screen content, UI state, actions taken, and reasoning about what the agent observed. Without an explicit warning and consent boundary, users may unknowingly transmit sensitive device content and activity metadata to downstream consumers or logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Screenshot and UI-state endpoints expose highly sensitive device data, potentially including messages, authentication prompts, personal identifiers, and app contents. Documenting these endpoints without strong privacy warnings, minimization guidance, or access-handling expectations increases the chance that operators collect, persist, or share sensitive data unsafely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
# Phone Control API Reference

Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`

This document covers how to control an Android device connected to Mobilerun.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
# Phone Control API Reference

Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`

This document covers how to control an Android device connected to Mobilerun.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
# Phone Control API Reference

Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`

This document covers how to control an Android device connected to Mobilerun.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 3)May include surrounding context.

md
# Phone Control API Reference

Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`

This document covers how to control an Android device connected to Mobilerun.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · phone-api.md (reported line 3)May include surrounding context.

md
# Phone Control API Reference

Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`

This document covers how to control an Android device connected to Mobilerun.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.md (reported line 12)May include surrounding context.

md
# Phone Control API Reference

Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`

This document covers how to control an Android device connected to Mobilerun.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.md (reported line 124)May include surrounding context.

md
# Phone Control API Reference

Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`

This document covers how to control an Android device connected to Mobilerun.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The screenshot endpoint is documented as a primary observation tool but does not warn that screenshots can capture highly sensitive information visible on the device, such as messages, emails, authentication prompts, banking data, or personal photos. In a remote-control skill for a personal Android device, omission of a privacy warning increases the chance that an agent or integrator will capture and transmit sensitive on-screen content without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The UI-state accessibility tree can expose foreground app identity, focused fields, visible text, content descriptions, and element metadata, which may include passwords, one-time codes, messages, account details, and other sensitive context. Because this skill is specifically designed to automate a real personal phone, documenting this collection without a clear sensitivity warning or consent boundary materially increases privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The uninstall operation is destructive and can remove user applications and associated local data, yet it is documented without an explicit warning or recommendation for confirmation. In the context of remote control over a personal device, this increases the chance of accidental or unauthorized app removal that could disrupt service or cause data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup asks the user to create and share an API key before clearly warning that the key is a bearer credential granting account access. Although the document later says not to reveal the key in chat for one connection flow, the earlier instructions normalize transmitting the secret to the agent for verification, which increases risk of credential disclosure, misuse, or accidental logging.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This step instructs verifying the API key by making an authenticated request after receiving the user's bearer token. In practice, that encourages transmission of a sensitive credential to the agent/service, creating avoidable exposure through chat history, logs, or downstream tooling.

Content

Scanner excerpt · setup.md (reported line 41)May include surrounding context.

After receiving a key from the user, verify it works:

text
GET https://api.mobilerun.ai/v1/devices
Authorization: Bearer dr_sk_...

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction to guide the user through the entire setup process omits an explicit consent checkpoint despite enabling remote device control, accessibility access, APK sideloading, and account linking. In this context, the missing consent language is risky because the capability is highly invasive and could lead users to enable broad control without understanding the scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Automatically submitting feedback tied to a task ID can disclose user activity metadata about what was run and when, especially if done without the user's awareness. While lower impact than screenshots or UI states, it still creates an avoidable privacy risk through implicit external transmission.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes controlling Android phones and interacting with apps on devices. Webhook subscription and lifecycle event management are backend integration features for task monitoring, not direct phone interaction, so they extend the documented behavior beyond the stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.