phone-agent

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Functionally legitimate automation skill that poses moderate-to-high operational and privacy risk if misconfigured or used on non-test devices. Principal risks: sensitive data exfiltration via PHONE_AGENT_ENDPOINT (especially if remote), credential exposure in prompts and logs, and abuse via broad Android accessibility permissions. Acceptable for controlled test environments with enforced local-only or authenticated backends, ephemeral/test credentials, and strong operational safeguards. Avoid use on production/personal devices without explicit safeguards.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:30 AM
Package URL
pkg:socket/skills-sh/gaojizhou%2Fskills%2Fphone-agent%2F@e5511d8a02f1eca2d9d8d5e5d769774b2d0a2718