Phone Controller | 手机操控者
PassAudited by VirusTotal on May 4, 2026.
Findings (1)
The skill facilitates full control of an Android device by instructing the agent to clone an external repository (zai-org/Open-AutoGLM), install Python dependencies, and sideload a third-party APK (ADBKeyboard.apk). While the documentation in SKILL.md includes safety warnings and requires user confirmation for 'write' operations, the automated setup and execution of unverified external code and binaries, combined with the exfiltration of screenshots to a third-party API (open.bigmodel.cn), poses a significant supply chain and privacy risk.
