harmonyos-device-automation
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe skill is coherently aligned with its stated purpose of visual-driven HarmonyOS device automation via Midscene. Install and execution model relies on standard CLI tooling and environment-based credentials for model services and device connectors, which is proportionate to the task. Security risk is moderate given the use of external model endpoints and credentials, but there is no evident credential harvesting, data exfiltration, or malicious behavior. Data flows are largely confined to local capture of screenshots and legitimate interactions with the device and external Midscene services. Overall, the footprint is Benign with normal security considerations for secret handling and network access.