Back to skill

Security audit

Andee

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Andee setup/debug guide, but it documents a powerful unauthenticated device-control WebSocket that can be reachable on the network after Accessibility is enabled.

Install only if you understand that Andee can read and act on your phone screen through Android Accessibility. Do not enable or use its debug WebSocket on public, shared, or untrusted networks; prefer adb-forwarded local debugging on an isolated device. Treat WRITE_SECURE_SETTINGS as an elevated optional grant and avoid granting it unless you need that specific workaround.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:94
Finding

Unauthenticated Network-Exposed Device Control Interface

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:94-96; supporting operational details in references/get-the-code.md:62-65, references/build-and-install.md:159-166, and references/debug-loop.md:69-102
Vulnerability Type: Unauthenticated remote access to privileged Android device-control functions
Risk Level: High

Relevant snippets:

text
- The debug WebSocket server binds `0.0.0.0:9008` and does not authenticate clients.
  That is a known limitation written down in `SECURITY.md`. Say so before telling anyone
  to run this on a network they do not control.
text
`ScreenBodyService` runs a WebSocket server **on the device**, port **9008**, exposing every tool the
brain can call.
text
| `screen.*` | `screen.ui_tree`, `screen.screenshot`, `screen.tap`, `screen.tap_id`,
`screen.type`, `screen.submit_input`, `screen.swipe`, `screen.global` |
| `device.*` | `device.battery`, `device.apps`, `device.permissions`, `device.launch`,
`device.notifications` |

Technical Analysis

The documented workflow starts a WebSocket service on all network interfaces at TCP port 9008 after the user enables Andee's Accessibility service. The Skill explicitly states that this service does not authenticate clients and exposes the tools available to the agent.

Consequently, a network peer that can reach the device can submit WebSocket JSON requests without proving authorization. The documented protocol permits the caller to select a method and supply its parameters:

json
{"type":"request","id":"1","method":"device.battery","params":{}}

The interface includes privileged operations such as reading the UI tree, taking screenshots, tapping, typing, issuing global screen actions, launching applications, and accessing notifications. These operations cross a material trust boundary: an unauthenticated network client gains access to functionality backed by the victim-approved Android Acce ...[truncated 1592 chars]

Remediation
View remediation

Remediation Suggestions

  1. Bind the debug WebSocket service to loopback by default rather than 0.0.0.0, and access it through adb forward during local development.
  2. If direct network access is required, use encrypted transport and mutually authenticated, per-device sessions.
  3. Reject unauthenticated requests before method lookup or dispatch.
  4. Add an explicit, disabled-by-default user setting for network debugging and visibly indicate when the server is active.
  5. Apply method-level authorization and separate read-only diagnostics from state-changing or sensitive operations.
  6. Rotate or revoke credentials when debugging is disabled, and rate-limit failed authentication attempts.
  7. Restrict network exposure with platform network-security controls or firewall rules and document the exact trusted-network assumptions.
  8. Add tests confirming that unauthenticated clients cannot invoke any dispatcher method.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/build-and-install.md (reported line 52)May include surrounding context.

md
# 2. command-line tools: developer.android.com/studio → "Command line tools only"
#    grab commandlinetools-mac-*.zip, then:
mkdir -p ~/Library/Android/sdk/cmdline-tools
unzip commandlinetools-mac-*.zip -d ~/Library/Android/sdk/cmdline-tools
mv ~/Library/Android/sdk/cmdline-tools/cmdline-tools ~/Library/Android/sdk/cmdline-tools/latest

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs users to grant WRITE_SECURE_SETTINGS, which is a privileged Android permission that enables modification of secure system settings and accessibility-related configuration. Although presented as optional and with some context, it lacks a clear warning that this is an elevated system-level capability and could materially expand the app's power if the app is compromised or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

With no manifest available, this file documents a broad WebSocket control surface including screen interaction, app launching, UI prompts, notebook/scene operations, and robot-dog control. Those capabilities go well beyond ordinary passive debugging guidance and are not justified by any stated skill purpose in the provided context.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/get-the-code.md (reported line 15)May include surrounding context.

md
| Missing | Fix |
|---|---|
| `git` | macOS: `xcode-select --install` · Debian/Ubuntu: `sudo apt install git` · Windows: install Git for Windows |
| a JDK 17–20 | macOS: `brew install --cask temurin@17` · Windows/Linux: [Adoptium Temurin 17](https://adoptium.net/) |
| `adb` | Comes with **Android SDK Platform-Tools** — install Android Studio, or use the command-line path in `build-and-install.md` §2.2 |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance explicitly points users to a known limitation: a debug WebSocket server bound to 0.0.0.0:9008 with no client authentication. Even though it is framed as something to read in SECURITY.md rather than an instruction to enable it directly, this is still a real security issue because it exposes a remote control/debug surface to any reachable host on the network, which is especially risky for an Android app with powerful accessibility and device-control capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The text explicitly labels one site as English and the other as Chinese, which can be read as a locale constraint without stating that users may choose their preferred language. Under the policy rule, forced or assumed language/locale behavior can be a natural-language policy concern when no opt-in or alternative is described.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.