Back to skill

Security audit

Harmonyos Moblink Integration

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed HarmonyOS MobLink integration helper that can edit project files and handle MobTech app credentials, but the behavior is aligned with its stated setup purpose and gated by user confirmation.

Install only for a HarmonyOS project you control. Review every proposed diff before accepting, verify the ohpm packages and permissions, keep MobLink_Config.xlsx out of version control, avoid pasting appSecret into chat or logs, and delete or secure the Excel file after integration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the user to place appKey and appSecret into a project-local Excel file and then have the agent read and validate that file, but it provides no warning about handling secrets or limiting their exposure. This increases the risk of accidental credential disclosure through logs, chat transcripts, generated documentation, or unintended reuse by the agent during subsequent steps.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.