Back to skill

Security audit

Expo App Store Screenshots

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed app-store screenshot workflow, but its optional upload helpers can replace existing App Store or Google Play screenshots.

Install only if you want an agent to operate local simulators/emulators and help manage App Store or Google Play screenshots. Before running upload commands, verify the app/package ID, locale, device slot, and screenshot directory; review images for secrets, private test data, or unreleased content; use least-privilege store credentials; and pass --keep-existing unless you intentionally want to replace the existing screenshot slot.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger text includes broad adjacent phrasing and low-specificity indicators like mentions of generic screenshot terms or tooling names, which can cause the skill to activate outside the user's intended context. Unintended invocation is risky here because the skill can drive devices, read app configuration, generate files, and potentially proceed toward upload workflows involving external services.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The upload section tells users how to send screenshots to App Store Connect and Google Play using API credentials, but it does not prominently warn that this transmits local assets and associated metadata to third-party services. In this context, screenshots may expose unreleased features, test data, internal branding, or regulated content, so omission of an explicit transmission warning increases the chance of accidental disclosure.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The script's default behavior is to delete all existing screenshots in the selected App Store Connect slot before uploading new ones, and this occurs without an interactive confirmation or a safer opt-in flag. In a CI/automation or misconfigured invocation, this can cause unintended destructive changes to production metadata and loss of previously curated screenshots.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.