This skill is a real Android remote-control integration, but it exposes broad phone control and sensitive data access with inconsistent safety documentation and overly broad activation triggers.
Install only if you fully trust the publisher, the TUTU cloud service, and the agent operating the phone. Use a non-primary or closely monitored device where possible, keep TUTU_API_TOKEN only in the platform secret store, revoke it if exposed, and require explicit user intent before any messaging, calling, notification reading, file access, app changes, settings changes, downloads, mock location, or GUI automation inside sensitive apps.