Atlas / MCP servers / iamr0s / Ruto Phone

Ruto PhoneSAFE

mcp/iamr0s/ruto-phone

It can run on the phone itself, or on any other machine that can reach the phone through `adb`. With a vision-capable model, it can observe screenshots, operate the device, and complete multi-step tasks. It can also expose the same capabilities as an MCP server, so tools such as OpenClaw and PicoCla

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
3 2r · 1w · 0d
Transport
stdio · streamable-http
License
—
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 简体中文 | 繁體中文

Ruto Phone MCP is a phone automation toolkit for Android devices.

It can run on the phone itself, or on any other machine that can reach the phone through adb. With a vision-capable model, it can observe screenshots, operate the device, and complete multi-step tasks. It can also expose the same capabilities as an MCP server, so tools such as OpenClaw and PicoClaw can control the phone indirectly.

QQ Group: Join the group. You can also share your own app operating manuals and SKILL.md instructions there.

Discussions: GitHub Discussions

What It Can Do

  • Control an Android device through touch, swipe, back, home, launch-app, and app inspection tools.
  • Run an interactive agent from the command line with screenshots and tool callbacks.
  • Expose the phone controller and the task-running agent through MCP.
  • Load local SKILL.md files so the model can follow product-specific operating instructions.

TODO

  • Add a web UI for phone control, task execution, and session inspection.
  • Make configuration easier to edit and validate.
  • Add built-in skill management for install, update, enable, disable, and uninstall flows.
  • Support more notification channels for task progress and completion events.

Contributing

My time is limited and work is busy, so progress on the project will not always be fast. If you find this project useful, you are welcome to join development, improve documentation, contribute skills, and help make the whole system more complete.

Deployment Model

You can use this project in either of these setups:

  1. Install and run it directly on an Android environment.
  2. Install and run it on another device, as long as that device can access the phone through adb.

Typical examples:

  • Run on a PC and co
Read from source at commit 4f62b702cfbbOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add ruto-phone-mcp -- uvx ruto-phone-mcp
claude-desktop
{
  "mcpServers": {
    "ruto-phone-mcp": {
      "command": "uvx",
      "args": [
        "ruto-phone-mcp"
      ]
    }
  }
}
03

Exposed tools (3)

2 read · 1 write · 0 destructive.

ToolRiskDescription
helloreadReturn a simple greeting.
taskwriteRun the phone agent to completion for a single task request.
testreadStream 4 random characters through progress/log notifications and return the final text.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMInventory / provenance · inv.binary · CWE-1104
src/ruto_phone_mcp/rutophone.dex
rutophone.dex
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:167
"url": "http://127.0.0.1:8000/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_zh-CN.md:167
"url": "http://127.0.0.1:8000/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_zh-TW.md:167
"url": "http://127.0.0.1:8000/mcp"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
langchain, langchain-core, langchain-openai, mcp, Pillow, uvicorn
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f62b702cfbbfull audit observations/trust-audit/mcp-server/iamr0s__ruto-phone.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084f62b702cfbbSAFEB89first audit
06

Questions

What is the Ruto Phone MCP server?

It can run on the phone itself, or on any other machine that can reach the phone through `adb`. With a vision-capable model, it can observe screenshots, operate the device, and complete multi-step tasks. It can also expose the same capabilities as an MCP server, so tools such as OpenClaw and PicoCla

What tools does Ruto Phone expose?

3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Ruto Phone safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Ruto Phone need?

No credential environment variables were found in its source, so it appears to need none.

How does Ruto Phone run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as ruto-phone-mcp.

How current is this page?

The grade is for one exact copy of the source (4f62b702cfbb), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement