pokeclaw-android-ai-agent
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is coherent and not clearly malicious, but it enables high-impact autonomous phone control: reading screen contents, monitoring notifications, launching apps, and sending messages. Install sources are mostly plausible, yet the combination of broad Android privileges, autonomous messaging, optional cloud routing of sensitive content, and LLM-driven action loops makes the overall security risk high despite good purpose alignment.
Confidence: 88%Severity: 82%
Audit Metadata