Ruto PhoneSAFE
It can run on the phone itself, or on any other machine that can reach the phone through `adb`. With a vision-capable model, it can observe screenshots, operate the device, and complete multi-step tasks. It can also expose the same capabilities as an MCP server, so tools such as OpenClaw and PicoCla
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 简体中文 | 繁體中文
Ruto Phone MCP is a phone automation toolkit for Android devices.
It can run on the phone itself, or on any other machine that can reach the phone through adb. With a vision-capable model, it can observe screenshots, operate the device, and complete multi-step tasks. It can also expose the same capabilities as an MCP server, so tools such as OpenClaw and PicoClaw can control the phone indirectly.
QQ Group: Join the group. You can also share your own app operating manuals and SKILL.md instructions there.
Discussions: GitHub Discussions
What It Can Do
- Control an Android device through touch, swipe, back, home, launch-app, and app inspection tools.
- Run an interactive agent from the command line with screenshots and tool callbacks.
- Expose the phone controller and the task-running agent through MCP.
- Load local
SKILL.mdfiles so the model can follow product-specific operating instructions.
TODO
- Add a web UI for phone control, task execution, and session inspection.
- Make configuration easier to edit and validate.
- Add built-in skill management for install, update, enable, disable, and uninstall flows.
- Support more notification channels for task progress and completion events.
Contributing
My time is limited and work is busy, so progress on the project will not always be fast. If you find this project useful, you are welcome to join development, improve documentation, contribute skills, and help make the whole system more complete.
Deployment Model
You can use this project in either of these setups:
- Install and run it directly on an Android environment.
- Install and run it on another device, as long as that device can access the phone through
adb.
Typical examples:
- Run on a PC and co
4f62b702cfbbOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ruto-phone-mcp -- uvx ruto-phone-mcp
{
"mcpServers": {
"ruto-phone-mcp": {
"command": "uvx",
"args": [
"ruto-phone-mcp"
]
}
}
}Exposed tools (3)
2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
hello | read | Return a simple greeting. |
task | write | Run the phone agent to completion for a single task request. |
test | read | Stream 4 random characters through progress/log notifications and return the final text. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
rutophone.dex
"url": "http://127.0.0.1:8000/mcp"
"url": "http://127.0.0.1:8000/mcp"
"url": "http://127.0.0.1:8000/mcp"
langchain, langchain-core, langchain-openai, mcp, Pillow, uvicorn
Gates applied: no_behavioural_pass, no_license.
4f62b702cfbbfull audit observations/trust-audit/mcp-server/iamr0s__ruto-phone.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f62b702cfbb | SAFE | B | 89 | first audit |
Questions
What is the Ruto Phone MCP server?
It can run on the phone itself, or on any other machine that can reach the phone through `adb`. With a vision-capable model, it can observe screenshots, operate the device, and complete multi-step tasks. It can also expose the same capabilities as an MCP server, so tools such as OpenClaw and PicoCla
What tools does Ruto Phone expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ruto Phone safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Ruto Phone need?
No credential environment variables were found in its source, so it appears to need none.
How does Ruto Phone run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as ruto-phone-mcp.
How current is this page?
The grade is for one exact copy of the source (4f62b702cfbb), read on 2026-10-08. The repository is watched and re-audited when it changes.