Back to skill

Security audit

Gemini Android

Security checks across malware telemetry and agentic risk

Overview

This is a static informational guide about Gemini on Android, with no executable code or hidden install behavior.

Safe to install as an informational guide. Before using the described Gemini features, review phone confirmations carefully, especially for email, shopping, web forms, or sensitive content, and do not assume every Gemini action is local-only or private by default.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad, generic terms like "Gemini" and "手机AI" that are likely to appear in ordinary conversation or unrelated requests. In an agent-routing context, this can cause unintended skill activation, increasing the chance that users are funneled into this skill when they did not explicitly intend to invoke it.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The quick-command example "帮我..." is extremely vague and effectively matches a huge range of normal user requests. If the platform treats this as a routing hint, it may over-trigger the skill for unrelated tasks, leading to unintended execution paths or confusing users about what agent is acting on their behalf.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This section describes cross-app automation that reads emails, extracts content from screenshots, and adds items to shopping carts, all of which can affect private data or initiate actions in other apps. Without warnings, consent expectations, or limits on what data may be accessed and what actions may be taken, users may not understand the privacy and transaction risks involved.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
Automated browsing, summarization, comparison, and especially complex form filling can expose sensitive personal or financial information and may submit incorrect data if not reviewed. The skill presents these capabilities as seamless actions but omits any caution about data handling, user confirmation, or the risks of acting on web content automatically.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.