Back to skill

Security audit

Android Control

Security checks for vulnerabilities and agentic risk

Overview

This Android control skill is disclosed and purpose-aligned, but it should be reviewed because it automatically retries sensitive screen and UI-control actions with root privileges when normal commands fail.

Install only if you intentionally want an agent to control an Android device and are comfortable with it using any already-authorized root access. Prefer removing the automatic su fallbacks or requiring explicit confirmation for each elevated screenshot, UI dump, tap, swipe, app launch, or text entry, and avoid using it while sensitive apps or credentials are visible.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:38
Finding

Automatic Root Escalation for Android Device-Control Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-13, 38-41, 50-54, 62-63, 71-72, 80-81, 89-90
Vulnerability Type: Automatic privilege escalation without per-operation authorization
Risk Level: High

The skill automatically retries routine Android device-control operations through su -c whenever their non-root equivalents fail. This behavior applies to UI hierarchy extraction, screenshot capture, touch and swipe injection, application launching, and text input.

Complete vulnerable code snippets:

bash
# Try non-root
uiautomator dump /sdcard/ui_dump.xml 2>/dev/null \
  && cat /sdcard/ui_dump.xml \
  || (
    # Fallback to root
    su -c "uiautomator dump /sdcard/ui_dump.xml" && su -c "cat /sdcard/ui_dump.xml"
  )
bash
TMP="/sdcard/ai_screen.png"

# Try non-root
screencap -p "$TMP" 2>/dev/null \
  && base64 "$TMP" \
  || (
    # Root fallback
    su -c "screencap -p $TMP"
    su -c "base64 $TMP"
  )
bash
input tap 540 1600 2>/dev/null \
  || su -c "input tap 540 1600"
bash
input swipe 500 1600 500 600 300 2>/dev/null \
  || su -c "input swipe 500 1600 500 600 300"
bash
am start -n com.android.settings/.Settings 2>/dev/null \
  || su -c "am start -n com.android.settings/.Settings"
bash
input text "Hello" 2>/dev/null \
  || su -c "input text 'Hello'"

Technical Analysis

The shell || operator invokes the root command after any non-zero exit status from the ordinary command. The logic does not distinguish an authorization failure from transient errors, invalid arguments, missing files, unavailable services, or partial command failure. Consequently, an ordinary operational error becomes an implicit request for elevated execution.

No explicit per-operation approval, privilege policy, action allowlist, or validation step is required before su -c is invoked. Redirect ...[truncated 1916 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove automatic su -c fallback from all routine operations.
  2. Return the original non-root error to the caller instead of suppressing it with 2>/dev/null.
  3. If elevation is genuinely necessary, require explicit and informed approval for each elevated operation. The approval prompt should identify the exact command, arguments, reason for elevation, and expected effect.
  4. Separate non-root and root workflows so selecting ordinary device control can never silently transition into elevated execution.
  5. Apply strict allowlists for executable names, application components, file paths, coordinates, and supported argument formats.
  6. Avoid shell-string construction for elevated commands. Where possible, invoke fixed commands with structured arguments to reduce command-injection risk when examples are adapted to dynamic input.
  7. Restrict elevated screenshot and UI-dump output to securely created files, apply restrictive permissions, and delete temporary artifacts immediately after use.
  8. Add audit logging for every requested and approved elevated action, including the initiating task, command, result, and timestamp.
  9. Document which operations require elevated access and deny elevation for actions that can be completed through standard Android APIs or explicitly granted non-root permissions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Chaining Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This command chain automatically escalates from a normal uiautomator dump to su -c execution if the first attempt fails, with no validation or approval step. Because UI dumps can reveal sensitive app structure and on-screen metadata, automatic privileged retry broadens access and normalizes escalation for data collection actions.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

&& cat /sdcard/ui_dump.xml
|| ( # Fallback to root su -c "uiautomator dump /sdcard/ui_dump.xml" && su -c "cat /sdcard/ui_dump.xml" )

text

Chaining Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The tap action silently retries with root when standard input injection fails, enabling privileged interaction with the device UI. In a skill designed for direct device control, this can let an agent trigger sensitive actions—such as approving prompts, changing settings, or interacting with security dialogs—beyond normal restrictions.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Example: tap at (540, 1600)

input tap 540 1600 2>/dev/null
|| su -c "input tap 540 1600"

text

## Swipe on Screen

Chaining Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

Automatic root fallback for swipe injection expands the skill's ability to manipulate privileged or protected UI flows without additional authorization. Swipes can dismiss warnings, navigate into administrative settings, or complete multi-step actions, so chaining failure directly into root materially raises abuse potential.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

Example: swipe from (500, 1600) to (500, 600) over 300ms

input swipe 500 1600 500 600 300 2>/dev/null
|| su -c "input swipe 500 1600 500 600 300"

text

## Launch an App

Chaining Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

Launching activities with am start and then automatically retrying as root can enable access to components or flows that are restricted under normal execution. In a device-control skill, this makes it easier for an agent to open privileged settings, administrative interfaces, or other sensitive app components without a deliberate escalation decision.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

Example: launch Android Settings

am start -n com.android.settings/.Settings 2>/dev/null
|| su -c "am start -n com.android.settings/.Settings"

text

## Send Text Input

Chaining Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The text-input command retries with root automatically, allowing an agent to inject data into contexts where normal automation may be blocked. That can facilitate unauthorized responses, search terms, messages, credentials entry, or command submission in privileged interfaces, especially when combined with other UI-control primitives in this skill.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Example: send text "Hello"

input text "Hello" 2>/dev/null
|| su -c "input text 'Hello'"

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly advertises automatic fallback to root for device-control operations but provides no prominent warning, confirmation gate, or limitation on when elevated privileges may be used. In an agent setting, this increases the chance that routine UI automation escalates into privileged system manipulation, making accidental misuse or abuse substantially more dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The screenshot workflow captures and base64-exports the full screen without warning that on-screen content may include passwords, messages, tokens, financial data, or other sensitive information. In an agent context, silent collection and transformation of screenshots increases privacy and data-exfiltration risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.