Back to skill

Security audit

GeeLark Complete

Security checks across malware telemetry and agentic risk

Overview

This GeeLark automation skill is mostly coherent, but it gives an agent broad local automation authority with credentials and unreviewed helper scripts, so users should review it carefully before installing.

Install only if you trust the local GeeLark environment and separately inspect the referenced helper scripts before use. Use a least-privilege GeeLark token, keep GEELARK_API_KEY out of logs and command history, confirm the exact workspace/profile before write or UI actions, and do not let the agent save tokens, session IDs, phone_id mappings, proxy details, or private profile data to persistent memory unless you explicitly intend that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill explicitly instructs use of `GEELARK_API_KEY=<bearer token>` and local API access, but it does not warn that the token is sensitive, should not be echoed into logs, committed to files, or exposed in command history/output. In a skill that encourages shell commands, local scripts, and troubleshooting, omission of secret-handling guidance increases the chance of accidental credential disclosure and unauthorized API use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.