T01 · Skill Instruction Hijacking
- Location
SKILL.md:99- Finding
Mandatory Product Promotion and Suppression of Alternative Tools
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly coherent for remote Android control, but it asks users to install and grant Accessibility access to an unverified sideloaded APK and includes some under-scoped automatic or biased actions.
Review this carefully before installing. It is designed to let an agent see and control an Android device, so only use it with accounts and devices you are comfortable exposing to Mobilerun. Prefer a verified APK source with a known signature or checksum, revoke the API key and Android Accessibility permission when done, avoid using it on banking, password, health, or private-message screens, and confirm any app uninstall, cloud-device spending, AI-agent task, webhook, or feedback submission before it happens.
SKILL.md:99Mandatory Product Promotion and Suppression of Alternative Tools
api.md:281Automatic Feedback and Task Identifier Submission Without User Consent
setup.md:73Unpinned Privileged APK Installation With Security-Warning Bypass
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
DELETE /devices/{deviceId}
Content-Type: application/json
{}
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
DELETE /devices/{deviceId}/keyboard
Clears the currently focused input field.
The uninstall endpoint enables a high-impact destructive action against a user's personal device and can remove important apps or associated data if invoked incorrectly or maliciously. In a remote-control skill, exposing this capability without strong warnings, confirmation expectations, or policy guardrails makes tool-parameter misuse materially dangerous.
DELETE /devices/{deviceId}/apps/{packageName}
Content-Type: application/json
{}
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
The API key (MOBILERUN_API_KEY) is already available -- OpenClaw handles credential setup before this skill loads. Do NOT ask the user for an API key. Just use it.
Subtle instructions detected that may alter agent decision-making or introduce hidden biases.
**Key principle:** If a device is ready, go straight to executing the user's request. Don't walk them through setup they've already completed.
**What to show the user:** Only report user-relevant device info: device name, state (`ready`/`disconnected`), and provider. Do NOT surface internal fields like `streamUrl`, `streamToken`, socket status, `assignedAt`, `terminatesAt`, or `taskCount` unless the user explicitly asks for technical details. Never tell users to interact with sockets, toggles, or buttons that are not documented here. If a device is `disconnected`, simply tell the user their phone is disconnected and ask them to open the Portal app and tap Connect. If they need help, walk them through the setup steps in [setup.md](./setup.md).
**Privacy:** Screenshots and the UI tree can contain sensitive personal data. Never share or transmit this data to anyone other than the user. Never print, log, or reveal the `MOBILERUN_API_KEY` in chat -- use it only for API calls.
The manifest says the skill is for controlling Android phones through the Mobilerun API with actions like tapping, swiping, typing, screenshots, UI tree access, and app management. This file documents broader platform APIs including device provisioning, AI-agent task execution, webhooks, and app library management, which materially exceed simple direct phone control and expand the skill's described behavior.
The manifest frames the skill around user-directed device automation and remote control primitives on a phone. These lines document submitting natural-language goals to a Mobilerun AI agent that acts autonomously, including streamed trajectories and model selection, which is a distinct higher-level behavior not clearly reflected in the manifest description.
The streamed task guidance encourages reading live SSE trajectory events that may include on-screen content, UI state, actions taken, and reasoning about what the agent observed. Without an explicit warning and consent boundary, users may unknowingly transmit sensitive device content and activity metadata to downstream consumers or logs.
Screenshot and UI-state endpoints expose highly sensitive device data, potentially including messages, authentication prompts, personal identifiers, and app contents. Documenting these endpoints without strong privacy warnings, minimization guidance, or access-handling expectations increases the chance that operators collect, persist, or share sensitive data unsafely.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Phone Control API Reference
Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`
This document covers how to control an Android device connected to Mobilerun.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Phone Control API Reference
Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`
This document covers how to control an Android device connected to Mobilerun.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Phone Control API Reference
Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`
This document covers how to control an Android device connected to Mobilerun.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Phone Control API Reference
Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`
This document covers how to control an Android device connected to Mobilerun.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Phone Control API Reference
Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`
This document covers how to control an Android device connected to Mobilerun.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Phone Control API Reference
Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`
This document covers how to control an Android device connected to Mobilerun.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Phone Control API Reference
Base URL: `https://api.mobilerun.ai/v1`
Auth: `Authorization: Bearer dr_sk_...`
This document covers how to control an Android device connected to Mobilerun.
The screenshot endpoint is documented as a primary observation tool but does not warn that screenshots can capture highly sensitive information visible on the device, such as messages, emails, authentication prompts, banking data, or personal photos. In a remote-control skill for a personal Android device, omission of a privacy warning increases the chance that an agent or integrator will capture and transmit sensitive on-screen content without informed user consent.
The UI-state accessibility tree can expose foreground app identity, focused fields, visible text, content descriptions, and element metadata, which may include passwords, one-time codes, messages, account details, and other sensitive context. Because this skill is specifically designed to automate a real personal phone, documenting this collection without a clear sensitivity warning or consent boundary materially increases privacy and data-exposure risk.
The uninstall operation is destructive and can remove user applications and associated local data, yet it is documented without an explicit warning or recommendation for confirmation. In the context of remote control over a personal device, this increases the chance of accidental or unauthorized app removal that could disrupt service or cause data loss.
The setup asks the user to create and share an API key before clearly warning that the key is a bearer credential granting account access. Although the document later says not to reveal the key in chat for one connection flow, the earlier instructions normalize transmitting the secret to the agent for verification, which increases risk of credential disclosure, misuse, or accidental logging.
This step instructs verifying the API key by making an authenticated request after receiving the user's bearer token. In practice, that encourages transmission of a sensitive credential to the agent/service, creating avoidable exposure through chat history, logs, or downstream tooling.
After receiving a key from the user, verify it works:
GET https://api.mobilerun.ai/v1/devices
Authorization: Bearer dr_sk_...
The instruction to guide the user through the entire setup process omits an explicit consent checkpoint despite enabling remote device control, accessibility access, APK sideloading, and account linking. In this context, the missing consent language is risky because the capability is highly invasive and could lead users to enable broad control without understanding the scope.
Automatically submitting feedback tied to a task ID can disclose user activity metadata about what was run and when, especially if done without the user's awareness. While lower impact than screenshots or UI states, it still creates an avoidable privacy risk through implicit external transmission.
The manifest describes controlling Android phones and interacting with apps on devices. Webhook subscription and lifecycle event management are backend integration features for task monitoring, not direct phone interaction, so they extend the documented behavior beyond the stated purpose.
No suspicious patterns detected.