android-device-automation

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Purpose and capabilities are internally consistent: this is genuinely an Android automation skill. Main risk comes from runtime npx execution, credential forwarding to the Midscene CLI and external model providers, and broad real-device control including adb shell passthrough. Overall this is not malware, but it is a medium-risk automation skill that should be used only with trusted model endpoints and explicit user supervision.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Apr 30, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/web-infra-dev%2Fmidscene-skills%2Fandroid-device-automation%2F@adffd7a917a7502f3b2f65f155f77fe5061646fe