Android reverse engineering & automation framework (Client API) with MCP extensions for device control and automation
Lamda is an Android automation framework exposing 34 tools via HTTP. While most tools have descriptions and basic input schemas, the server exhibits multiple critical gaps: (1) No visible input schema definitions in source code, tool signatures are inferred from parameter documentation rather than explicit JSON Schema registration. (2) Descriptions are present but often vague or lack actionable guidance, e.g., 'Perform a click at arbitrary coordinates' does not explain what happens on failure or when to use this vs text-based click variants. (3) Parameters lack type constraints and validation rules, e.g., click's pointX/pointY are integers with no bounds, allowing absurd negative or out-of-screen values. (4) Output schemas are not documented, LLMs cannot know what these tools return. (5) No error recovery guidance, destructive tools like execute_shell_script_foreground and delete operations have no dry-run or confirmation flow. (6) Duplicate tool 'getprop' listed twice (tools 2 and 19), suggesting poor tool inventory management. (7) Composition issues: 34 tools with overlapping functionality (6 click variants, 3 text-input variants) create decision paralysis for LLMs; no batch variants offered. (8) All tools lack proper error categorization and recovery hints. This server is usable for domain experts but not production-ready for autonomous agent interaction.
Perform a click at arbitrary coordinates on the display.
Use full description matching to click on an element.
Use description contains matching to click on an element.
Use description regex matching to click on an element.
Use resourceId to click on an element, if the resource-id is duplicated, it cannot be used.
Use full text matching to click on an element.
Use text contains matching to click on an element.
No explicit input schema definitions visible in source code. Tool definitions inferred from parameter documentation rather than registered via JSON Schema. Cannot verify if schema format is compliant with JSON Schema spec.
Output schemas are completely undocumented. LLMs cannot know what fields to expect from responses, forcing them to guess downstream tool parameters and breaking tool chaining.
Duplicate tool 'getprop' registered twice (tools 2 and 19 in inventory). This creates confusion for LLM tool selection and suggests poor tool lifecycle management.
Six click variants (click, click_by_text, click_by_text_contains, click_by_text_matches, click_by_description, click_by_description_contains, click_by_description_matches) lack clear disambiguation. Descriptions do not explain when to use each variant. LLMs will waste reasoning cycles choosing between similar tools.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2025-06-18+ | v2 |
| 2026-03-09 | C | 65 | - | v1 |
Use text regex matching to click on an element.
Get information about the currently running foreground application.
Perform a drag between two points.
Dumps android window's layout hierarchy as JSON string.
Execute script in the device's shell foreground.
Get the device clipboard content.
Get device information such as screen width, height, brand, etc.
Read file content on the device by full path
Get the last displayed toast on the system.
Read android system property by name.
Read android system property by name.
Send a greeting to others.
Use the package name to check if the application is installed.
Check if the application is running in the foreground using the package name.
Check is the device screen locked.
Check if the device screen is lit up.
Simulates a short press using a key code.
Reads the SMS database using SQL statements in SQLite syntax; read-only, no write operations allowed. The database is standard android mmssms.db, you should always learn the tables or table structure if needed.
Set the device clipboard content.
Use className to input text into an input element.
Use resourceId to input text into an input element, if the resource-id is duplicated, it cannot be used.
Display a toast message on the screen.
Turn off the device screen.
Use the package name to launch an Android app.
Use the package name to close an Android app.
Perform a swipe between two points.
Wake up the device.
Three text-input variants (set_text_by_resource_id, set_text_by_class_name, and implied others) lack guidance on precedence and use cases. Descriptions do not clarify when resource_id vs class_name is preferred.
Destructive tool 'execute_shell_script_foreground' has risk DESTRUCTIVE but no dry-run, confirmation request, or error recovery guidance. Description (27 chars) is below actionable minimum and does not warn about irreversible consequences.
Parameter bounds not specified for coordinate/numeric inputs: click's pointX/pointY, swipe's fromX/fromY/toX/toY have no min/max constraints. LLMs can pass negative, zero, or screen-exceeding coordinates.
No error recovery guidance. Tools lack descriptions explaining what to do on failure: 'If click fails, try text-based click variants' or 'If app start fails, check if installed first.' Errors are undocumented.
Tool 'get_deviec_info' has typo in name ('deviec' instead of 'device'). This violates naming conventions and will confuse LLMs and human operators.
Descriptions are often vague or under-specified. E.g., 'Perform a click at arbitrary coordinates' (40 chars) does not explain return value, failure modes, or when to use coordinate-based click vs text-based variants. Baseline is 194 chars average for A+ tools.
No batch variants offered. Agents that need to click 5 UI elements must make 5 sequential calls. No batch_click or click_multiple tool offered.
No pagination parameters documented. Tools like 'read_sms_database_by_sql' could return thousands of results, but no limit/offset or cursor mechanisms are documented.