Back to skill

Security audit

Gemini Android

Security checks for vulnerabilities and agentic risk

Overview

This is a single informational Markdown skill about Gemini on Android, with no executable code or hidden install behavior.

Installing this skill should be low risk as documentation, but treat its automation examples as guidance only: do not let any assistant submit forms, add shopping items, use emails, or act across apps without explicit review and confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are very broad and generic, such as 'Gemini', '安卓AI', and '手机AI', which can easily overlap with normal user conversation or unrelated requests. This can cause unintended skill activation and routing, especially because the skill covers system-level and cross-application capabilities that may expose sensitive context or cause confusing automation flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This section promotes cross-app automation, screenshot interpretation, email reading, and shopping-cart actions without warning that personal content, account state, or purchasing actions may be involved. That omission is risky because users may not realize the skill can operate on sensitive data or produce side effects across apps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The browser-assistant section advertises automatic browsing and complex form filling without warning about submission of passwords, payment data, personal identifiers, or legal/medical information. In context, this is particularly concerning because browser forms often contain highly sensitive data and users may overtrust 'automatic' completion behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance '直接说"帮我..."' encourages invocation through an extremely ambiguous phrase that is common in everyday speech. In an environment with multiple skills or assistants, this increases the chance of accidental activation and unintended execution of automation-oriented behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.