by appclawhq
AI-powered mobile automation agent — describe what you want in plain English, AppClaw reads the screen, reasons, and acts. LLM-agnostic, open-source, zero telemetry.
# Add to your Claude Code skills
git clone https://github.com/appclawhq/AppClawLast scanned: 8/7/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@appium/base-driver: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@appium/base-plugin: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@appium/docutils: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@appium/support: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server: Middleware bypass via repeated slashes in serveStatic",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@npmcli/arborist: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@npmcli/metavuln-calculator: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@opentelemetry/sdk-node: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@sigstore/core: @sigstore/core has DSSE payloadType type-binding failure",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@sigstore/sign: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@sigstore/verify: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "appium: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "appium-mcp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "applesign: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "axios: Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy",
"severity": "high"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement",
"severity": "low"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "diff: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch",
"severity": "low"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild allows arbitrary file read when running the development server on Windows",
"severity": "low"
},
{
"type": "npm-audit",
"message": "express-rate-limit: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-xml-builder: fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-xml-parser: fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "form-data: form-data: CRLF injection in form-data via unescaped multipart field names and filenames",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono missing validation of cookie name on write path in setCookie()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: js-yaml has prototype pollution in merge (<<)",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmdiff: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmexec: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmfund: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmpack: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmpublish: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mocha: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "morgan: morgan vulnerable to Log Forging via unneutralized control characters in :remote-user",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "nanoid: Predictable results in nanoid generation when given non-integer values",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "npm: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "pacote: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "high"
},
{
"type": "npm-audit",
"message": "protobufjs: protobufjs: Denial of Service via infinite loop in .proto option parsing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "qs: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "serialize-javascript: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "sharp: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591",
"severity": "high"
},
{
"type": "npm-audit",
"message": "shell-quote: shell-quote quote() does not escape newlines in object .op values",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "sigstore: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tar: node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-08-07T05:40:09.295Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}AppClaw is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by appclawhq. AI-powered mobile automation agent — describe what you want in plain English, AppClaw reads the screen, reasons, and acts. LLM-agnostic, open-source, zero telemetry. It has 100 GitHub stars.
AppClaw failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/appclawhq/AppClaw" and add it to your Claude Code skills directory (see the Installation section above).
AppClaw is primarily written in TypeScript. It is open-source under appclawhq on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh AppClaw against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
You: "Send a WhatsApp message to Mom
saying good morning"
AppClaw:
Step 1: Open WhatsApp
Step 2: Search for Mom
Step 3: Open chat with Mom
Step 4: Type "good morning"
Step 5: Tap Send
Step 6: Done
✅ Goal completed in 6 steps.
npm install -g @appclaw/cli
appclaw "open the settings app and turn on airplane mode"
You'll need Node.js 22+, a connected device / emulator / simulator, and an LLM API key (Anthropic, OpenAI, Google, Groq, or local Ollama). Full setup → appclaw.in.
appclaw initEvery mode is documented at appclaw.in.
| Install | Package | For |
|---|---|---|
npm i -g @appclaw/cli |
@appclaw/cli |
the appclaw command — goals, flows, playground, reports |
via appclaw init |
@appclaw/runner |
vitest-style test runner (appclaw-runner) |
npm i @appclaw/core |
@appclaw/core |
the SDK / headless engine |
git clone https://github.com/appclawhq/AppClaw.git
cd AppClaw
npm install
npm run build
cp .env.example .env # add your LLM key
See CLAUDE.md for the architecture overview, and appclaw.in for usage.
Licensed under the Apache License, Version 2.0. See LICENSE for the full text.