phonebase

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core phone-control capability matches the stated purpose, and the `pb` installer appears to be the vendor's official path, so this is not fundamentally deceptive. Risk comes from broad remote device control, arbitrary app/URL/APK actions, and especially transitive installation of additional skills that inherit agent trust.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 16, 2026, 03:03 PM
Package URL
pkg:socket/skills-sh/phonebase-cloud%2Fphonebase-skills%2Fphonebase%2F@30beffeae5d8440b988a0ab53d7799943ef78ce4