Back to skill

Security audit

Android Remote Browser Debug

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Android browser debugging skill whose powerful device/browser access is clearly tied to its stated purpose.

Install only if you intentionally want an agent to help debug an Android browser over USB/ADB. Use it on devices and tabs you control, close unrelated sensitive pages, review any JavaScript before it runs, remove ADB forwards after debugging, and delete temporary scripts or captured output that may contain private page data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly enables inspection of console logs, network requests, DOM content, screenshots, and arbitrary JavaScript execution on a connected mobile browser, but provides no privacy warning, consent boundary, or data-handling caution. In practice this can expose sensitive page contents, session data, personal information, and authenticated application state during debugging, especially if used on a real user device or production session.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.