adb-claw

Fail

Audited by Snyk on Jul 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). These URLs point to a third‑party GitHub repository and its Releases page which the plugin auto-downloads prebuilt binaries from — hosting executables on an unvetted/third‑party account is a common malware distribution vector, so treat as suspicious until verified or built from source.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). SKILL.md describes runtime commands like monitor/audio capture that read UI text from the connected Android device via the accessibility framework (outsider-authored content from the user’s device/app UI), which can be ingested into the agent’s LLM context as returned JSON/text.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 17, 2026, 10:01 AM
Issues
2
Security Audit — snyk — adb-claw