pokeclaw-android-ai-agent

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent and not clearly malicious, but it enables high-impact autonomous phone control: reading screen contents, monitoring notifications, launching apps, and sending messages. Install sources are mostly plausible, yet the combination of broad Android privileges, autonomous messaging, optional cloud routing of sensitive content, and LLM-driven action loops makes the overall security risk high despite good purpose alignment.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Apr 11, 2026, 05:12 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fpokeclaw-android-ai-agent%2F@0c7103663b4b19d26f1936b89683d718f3512176