Back to skill

Security audit

Gingiris ASO Growth

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only ASO and mobile growth playbook with disclosed advisory content and no hidden execution, credential access, persistence, or destructive behavior.

Install only if you want app store optimization and mobile growth guidance. Use it in mobile app/storefront contexts, verify marketing claims and platform policy details before acting, and avoid any prohibited tactics such as fake reviews, artificial installs, device farms, or enforcement evasion, which the artifact itself flags as off-limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains very broad terms such as "ASO," "app launch," "user acquisition," and "UA," which can match many ordinary product, growth, or marketing conversations outside the narrow intended scope. This can cause the skill to activate unexpectedly and steer users into specialized guidance when they did not request it, increasing the chance of irrelevant, low-signal, or policy-sensitive growth advice being injected into unrelated workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.