Back to skill

Security audit

phone-agent

Security checks across malware telemetry and agentic risk

Overview

The skill clearly discloses that it controls a real phone, but that access is broad enough to affect private data and real accounts without documented guardrails.

Review this carefully before installing. Use it only with a phone and accounts you are comfortable letting an agent operate, keep the relay local, and require your own explicit confirmation before messages, purchases, settings changes, account actions, app installs, or anything that exposes private data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill explicitly enables remote control of a real phone, including tapping, typing, screenshots, and multi-step autonomous actions, yet the documentation does not warn about high-risk operations such as sending messages, changing settings, initiating payments, exposing private data, or destructive actions on the device. In this context, the omission is dangerous because the skill is designed for a high-impact environment where natural-language requests can directly cause real-world side effects on a user device.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.