by appclawhq
AI-powered mobile automation agent — describe what you want in plain English, AppClaw reads the screen, reasons, and acts. LLM-agnostic, open-source, zero telemetry.
# Add to your Claude Code skills
git clone https://github.com/appclawhq/AppClawLast scanned: 8/7/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@appium/base-driver: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@appium/base-plugin: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@appium/docutils: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@appium/support: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server: Middleware bypass via repeated slashes in serveStatic",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@npmcli/arborist: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@npmcli/metavuln-calculator: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@opentelemetry/sdk-node: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@sigstore/core: @sigstore/core has DSSE payloadType type-binding failure",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@sigstore/sign: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@sigstore/verify: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "appium: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "appium-mcp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "applesign: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "axios: Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy",
"severity": "high"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement",
"severity": "low"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "diff: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch",
"severity": "low"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild allows arbitrary file read when running the development server on Windows",
"severity": "low"
},
{
"type": "npm-audit",
"message": "express-rate-limit: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-xml-builder: fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-xml-parser: fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "form-data: form-data: CRLF injection in form-data via unescaped multipart field names and filenames",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono missing validation of cookie name on write path in setCookie()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: js-yaml has prototype pollution in merge (<<)",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmdiff: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmexec: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmfund: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmpack: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "libnpmpublish: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mocha: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "morgan: morgan vulnerable to Log Forging via unneutralized control characters in :remote-user",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "nanoid: Predictable results in nanoid generation when given non-integer values",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "npm: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "pacote: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "high"
},
{
"type": "npm-audit",
"message": "protobufjs: protobufjs: Denial of Service via infinite loop in .proto option parsing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "qs: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "serialize-javascript: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "sharp: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591",
"severity": "high"
},
{
"type": "npm-audit",
"message": "shell-quote: shell-quote quote() does not escape newlines in object .op values",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "sigstore: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tar: node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-08-07T05:40:09.295Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how AppClaw compares with popular alternatives.
AppClaw is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by appclawhq. AI-powered mobile automation agent — describe what you want in plain English, AppClaw reads the screen, reasons, and acts. LLM-agnostic, open-source, zero telemetry. It has 110 GitHub stars.
AppClaw failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/appclawhq/AppClaw" and add it to your Claude Code skills directory (see the Installation section above).
AppClaw is primarily written in TypeScript. It is open-source under appclawhq on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh AppClaw against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
You: "Send a WhatsApp message to Mom
saying good morning"
AppClaw:
Step 1: Open WhatsApp
Step 2: Search for Mom
Step 3: Open chat with Mom
Step 4: Type "good morning"
Step 5: Tap Send
Step 6: Done
✅ Goal completed in 6 steps.
npm install -g @appclaw/cli
appclaw doctor # preflight: Node, .env, LLM key, appium-mcp, devices
appclaw "open the settings app and turn on airplane mode"
You'll need Node.js 22+, a connected device / emulator / simulator, and an LLM API key (Anthropic, OpenAI, Google, Groq, or local Ollama). appclaw doctor checks all of this in seconds and prints fix hints for anything missing (--full also spawns appium-mcp for a real handshake). Full setup → appclaw.in.
That last command opens Terminal Studio, the full-screen shell: bare appclaw stays resident so you can run one goal after another, and appclaw "a goal" runs it once and holds the finished screen until you press a key. appclaw --tui opens the same shell in step-recording mode instead. Add APPCLAW_TUI=off for an unattended run that prints to the console and exits on its own.
Terminal Studio can mirror the device inside the terminal — ^r starts it, ^p pauses, ^x closes (--stream starts it from the command line). It works with an Android device or emulator and with an iOS simulator, and draws the screen inside a device body so it reads as a phone rather than a rectangle. It looks best on a terminal that speaks the kitty graphics protocol — Ghostty, kitty, WezTerm — and falls back to half-block characters elsewhere.
appclaw, or appclaw --tui) — one shell, two modes: describe goals and watch the agent work, or record steps one at a time. Either way the device is mirrored beside it and /export turns what just happened into a runnable specappclaw test; scaffold with appclaw initEvery mode is documented at appclaw.in.
| Install | Package | For |
|---|---|---|
npm i -g @appclaw/cli |
@appclaw/cli |
the appclaw command — goals, flows, Terminal Studio, reports |
via appclaw init |
@appclaw/runner |
vitest-style test runner (appclaw test) |
npm i @appclaw/core |
@appclaw/core |
the SDK / headless engine |
git clone https://github.com/appclawhq/AppClaw.git
cd AppClaw
npm install
npm run build
cp .env.example .env # add your LLM key
See CLAUDE.md for the architecture overview, and appclaw.in for usage.
Licensed under the Apache License, Version 2.0. See LICENSE for the full text.