android-device-automation
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Purpose and capabilities are internally consistent: this is genuinely an Android automation skill. Main risk comes from runtime npx execution, credential forwarding to the Midscene CLI and external model providers, and broad real-device control including adb shell passthrough. Overall this is not malware, but it is a medium-risk automation skill that should be used only with trusted model endpoints and explicit user supervision.
Confidence: 88%Severity: 64%
Audit Metadata