Back to skill

Security audit

Android Control

Security checks across malware telemetry and agentic risk

Overview

This is a powerful but coherent Android-control skill that clearly describes ADB, Termux, intents, UI automation, and safety checks without hidden install code or unrelated behavior.

Install only if you intend to let OpenClaw control an Android device through ADB or Termux. Keep wireless debugging and ADB access limited to trusted devices, and review any task involving real messages, app install/uninstall, file deletion, account data, screenshots, logs, or security settings before allowing execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation phrase "Jalankan tugas Android ini." is excessively broad for a high-privilege Android control skill. Because this skill can drive ADB, intents, UI automation, and messaging-related actions, an overly generic trigger increases the chance of accidental activation on unrelated user prompts, leading to unintended device control actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.